Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.2.0
Report Generated On : Fri, 29 May 2026 08:45:39 +0200
Dependencies Scanned : 777 (761 unique)
Vulnerable Dependencies : 48
Vulnerabilities Found : 112
Vulnerabilities Suppressed : 554
(show )
...
NVD API Last Checked : 2026-05-29T08:38:18+02
NVD API Last Modified : 2026-05-29T05:16:19Z
Summary
Summary of Vulnerable Dependencies (click to show all)
FastInfoset-1.2.16.jar
Description:
Open Source implementation of the Fast Infoset Standard for Binary XML (http://www.itu.int/ITU-T/asn1/).
License:
http://www.opensource.org/licenses/apache2.0.php, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.fastinfoset/FastInfoset/1.2.16/4eb6a0adad553bf759ffe86927df6f3b848c8bea/FastInfoset-1.2.16.jar
MD5: f7f4be4695e2501a6d585beca305c74c
SHA1: 4eb6a0adad553bf759ffe86927df6f3b848c8bea
SHA256: 056f3a1e144409f21ed16afc26805f58e9a21f3fce1543c42d400719d250c511
Referenced In Project/Scope: server-start:compileClasspath
FastInfoset-1.2.16.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name FastInfoset High
Vendor gradle artifactid FastInfoset Highest
Vendor gradle groupid com.sun.xml.fastinfoset Highest
Vendor jar package name fastinfoset Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium
Vendor Manifest extension-name com.sun.xml.fastinfoset Medium
Vendor Manifest implementation-build-id 1.2.16-df8b153, 2018-12-27T14:31:11+0000 Low
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest Implementation-Vendor-Id com.sun.xml.fastinfoset Medium
Vendor pom artifactid FastInfoset Low
Vendor pom groupid com.sun.xml.fastinfoset Highest
Vendor pom name fastinfoset High
Vendor pom parent-artifactid fastinfoset-project Low
Product file name FastInfoset High
Product gradle artifactid FastInfoset Highest
Product jar package name fastinfoset Highest
Product jar package name org Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name fastinfoset Medium
Product Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium
Product Manifest extension-name com.sun.xml.fastinfoset Medium
Product Manifest implementation-build-id 1.2.16-df8b153, 2018-12-27T14:31:11+0000 Low
Product Manifest Implementation-Title Fast Infoset Implementation High
Product Manifest specification-title ITU-T Rec. X.891 | ISO/IEC 24824-1 (Fast Infoset) Medium
Product pom artifactid FastInfoset Highest
Product pom groupid com.sun.xml.fastinfoset Highest
Product pom name fastinfoset High
Product pom parent-artifactid fastinfoset-project Medium
Version file version 1.2.16 High
Version gradle version 1.2.16 Highest
Version Manifest Bundle-Version 1.2.16 High
Version Manifest Implementation-Version 1.2.16 High
Version pom version 1.2.16 Highest
pkg:maven/com.sun.xml.fastinfoset/FastInfoset@1.2.16
(Confidence :High)
FastInfoset-2.1.0.jar
Description:
Open Source implementation of the Fast Infoset Standard for Binary XML (http://www.itu.int/ITU-T/asn1/).
License:
http://www.opensource.org/licenses/apache2.0.php, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.fastinfoset/FastInfoset/2.1.0/cd92e93ef4ee608bffe4ba41b1247846a3d42227/FastInfoset-2.1.0.jar
MD5: e3b96affb511af41c5ba5bc6827b93db
SHA1: cd92e93ef4ee608bffe4ba41b1247846a3d42227
SHA256: b968161aab6beb1ea1a4a62a3d84b5d762d62681f7ce23cf03049915d9748d21
Referenced In Project/Scope: server-start:runtimeClasspath
FastInfoset-2.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name FastInfoset High
Vendor gradle artifactid FastInfoset Highest
Vendor gradle groupid com.sun.xml.fastinfoset Highest
Vendor jar package name fastinfoset Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium
Vendor Manifest extension-name com.sun.xml.fastinfoset Medium
Vendor Manifest implementation-build-id 2.1.0 - 8de254a Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id com.sun.xml.fastinfoset Medium
Vendor pom artifactid FastInfoset Low
Vendor pom groupid com.sun.xml.fastinfoset Highest
Vendor pom name fastinfoset High
Vendor pom parent-artifactid fastinfoset-project Low
Product file name FastInfoset High
Product gradle artifactid FastInfoset Highest
Product jar package name fastinfoset Highest
Product jar package name org Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name fastinfoset Medium
Product Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium
Product Manifest extension-name com.sun.xml.fastinfoset Medium
Product Manifest implementation-build-id 2.1.0 - 8de254a Low
Product Manifest Implementation-Title Fast Infoset Implementation High
Product Manifest specification-title ITU-T Rec. X.891 | ISO/IEC 24824-1 (Fast Infoset) Medium
Product pom artifactid FastInfoset Highest
Product pom groupid com.sun.xml.fastinfoset Highest
Product pom name fastinfoset High
Product pom parent-artifactid fastinfoset-project Medium
Version file version 2.1.0 High
Version gradle version 2.1.0 Highest
Version Manifest Bundle-Version 2.1.0 High
Version Manifest implementation-build-id 2.1.0 Low
Version Manifest Implementation-Version 2.1.0 High
Version pom version 2.1.0 Highest
pkg:maven/com.sun.xml.fastinfoset/FastInfoset@2.1.0
(Confidence :High)
Saxon-HE-9.9.1-6.jar
Description:
The XSLT and XQuery Processor
License:
Mozilla Public License Version 2.0: http://www.mozilla.org/MPL/2.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.sf.saxon/Saxon-HE/9.9.1-6/1905b27b0e4df1ee3a0857f403f64558ef780e6f/Saxon-HE-9.9.1-6.jar
MD5: 173398f1e38f077a0583900d99b4f5f9
SHA1: 1905b27b0e4df1ee3a0857f403f64558ef780e6f
SHA256: 00d1d0428752a245f1725293c0c0d102f735455b14028777baef42a90f3d93ec
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Saxon-HE-9.9.1-6.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name Saxon-HE High
Vendor gradle artifactid Saxon-HE Highest
Vendor gradle groupid net.sf.saxon Highest
Vendor jar package name net Low
Vendor jar package name saxon Highest
Vendor jar package name saxon Low
Vendor jar package name sf Low
Vendor Manifest project-name Saxon-HE Medium
Vendor pom artifactid Saxon-HE Low
Vendor pom developer email debbie@saxonica.com Low
Vendor pom developer email john@saxonica.com Low
Vendor pom developer email mike@saxonica.com Low
Vendor pom developer email oneil@saxonica.com Low
Vendor pom developer id debbie Medium
Vendor pom developer id John Medium
Vendor pom developer id mike Medium
Vendor pom developer id ond1 Medium
Vendor pom developer name Debbie Lockett Medium
Vendor pom developer name John Lumley Medium
Vendor pom developer name Michael Kay Medium
Vendor pom developer name O'Neil Delpratt Medium
Vendor pom groupid net.sf.saxon Highest
Vendor pom name Saxon-HE High
Vendor pom organization name Saxonica High
Vendor pom organization url http://www.saxonica.com Medium
Vendor pom url http://www.saxonica.com/ Highest
Product file name Saxon-HE High
Product gradle artifactid Saxon-HE Highest
Product jar package name saxon Highest
Product jar package name saxon Low
Product jar package name sf Low
Product Manifest project-name Saxon-HE Medium
Product pom artifactid Saxon-HE Highest
Product pom developer email debbie@saxonica.com Low
Product pom developer email john@saxonica.com Low
Product pom developer email mike@saxonica.com Low
Product pom developer email oneil@saxonica.com Low
Product pom developer id debbie Low
Product pom developer id John Low
Product pom developer id mike Low
Product pom developer id ond1 Low
Product pom developer name Debbie Lockett Low
Product pom developer name John Lumley Low
Product pom developer name Michael Kay Low
Product pom developer name O'Neil Delpratt Low
Product pom groupid net.sf.saxon Highest
Product pom name Saxon-HE High
Product pom organization name Saxonica Low
Product pom organization url http://www.saxonica.com Low
Product pom url http://www.saxonica.com/ Medium
Version gradle version 9.9.1-6 Highest
Version pom version 9.9.1-6 Highest
pkg:maven/net.sf.saxon/Saxon-HE@9.9.1-6
(Confidence :High)
SparseBitSet-1.2.jar
Description:
An efficient sparse bitset implementation for Java
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.zaxxer/SparseBitSet/1.2/8467c813d442837fcaeddbc42cf5c5359fab4933/SparseBitSet-1.2.jar
MD5: 1c6032441aec11b523e1a7bfa96d60cf
SHA1: 8467c813d442837fcaeddbc42cf5c5359fab4933
SHA256: 91e6b318c901a0f2dd1f6ce781d62474435ae627d22fbac9b21bbc39ffd804b6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
SparseBitSet-1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name SparseBitSet High
Vendor gradle artifactid SparseBitSet Highest
Vendor gradle groupid com.zaxxer Highest
Vendor jar package name sparsebits Low
Vendor jar package name sparsebitset Highest
Vendor jar package name zaxxer Highest
Vendor jar package name zaxxer Low
Vendor pom artifactid SparseBitSet Low
Vendor pom developer email brett.wooldridge@gmail.com Low
Vendor pom developer name Brett Wooldridge Medium
Vendor pom groupid com.zaxxer Highest
Vendor pom name SparseBitSet High
Vendor pom organization name Zaxxer.com High
Vendor pom organization url brettwooldridge/SparseBitSet Medium
Vendor pom url brettwooldridge/SparseBitSet Highest
Product file name SparseBitSet High
Product gradle artifactid SparseBitSet Highest
Product jar package name sparsebits Low
Product jar package name sparsebitset Highest
Product jar package name zaxxer Highest
Product pom artifactid SparseBitSet Highest
Product pom developer email brett.wooldridge@gmail.com Low
Product pom developer name Brett Wooldridge Low
Product pom groupid com.zaxxer Highest
Product pom name SparseBitSet High
Product pom organization name Zaxxer.com Low
Product pom url brettwooldridge/SparseBitSet High
Version file version 1.2 High
Version gradle version 1.2 Highest
Version pom version 1.2 Highest
pkg:maven/com.zaxxer/SparseBitSet@1.2
(Confidence :High)
cpe:2.3:a:bit_project:bit:1.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-activation/2.0.2/41f1e0ddd157c856926ed149ab837d110955a9fc/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
angus-activation-2.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor gradle artifactid angus-activation Highest
Vendor gradle groupid org.eclipse.angus Highest
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product gradle artifactid angus-activation Highest
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version gradle version 2.0.2 Highest
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.angus/angus-mail/2.0.4/80a49d6e187788d17a23b05e375bad75f56a4a92/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
angus-mail-2.0.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor gradle artifactid angus-mail Highest
Vendor gradle groupid org.eclipse.angus Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product gradle artifactid angus-mail Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version gradle version 2.0.4 Highest
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
annotations-13.0.jar
Description:
A set of annotations used for code inspection support and code documentation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains/annotations/13.0/919f0dfe192fb4e063e7dacadee7f8bb9a2672a9/annotations-13.0.jar
MD5: f4fb462172517b46b6cd90003508515a
SHA1: 919f0dfe192fb4e063e7dacadee7f8bb9a2672a9
SHA256: ace2a10dc8e2d5fd34925ecac03e4988b2c0f851650c94b8cef49ba1bd111478
Referenced In Project/Scope: server-start:compileClasspath
annotations-13.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name annotations High
Vendor gradle artifactid annotations Highest
Vendor gradle groupid org.jetbrains Highest
Vendor jar package name annotations Highest
Vendor jar package name annotations Low
Vendor jar package name intellij Highest
Vendor jar package name intellij Low
Vendor jar package name jetbrains Highest
Vendor jar package name lang Low
Vendor pom artifactid annotations Low
Vendor pom developer id JetBrains Medium
Vendor pom developer name JetBrains Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL http://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains Highest
Vendor pom name IntelliJ IDEA Annotations High
Vendor pom url http://www.jetbrains.org Highest
Product file name annotations High
Product gradle artifactid annotations Highest
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name intellij Highest
Product jar package name jetbrains Highest
Product jar package name lang Low
Product pom artifactid annotations Highest
Product pom developer id JetBrains Low
Product pom developer name JetBrains Team Low
Product pom developer org JetBrains Low
Product pom developer org URL http://www.jetbrains.com Low
Product pom groupid org.jetbrains Highest
Product pom name IntelliJ IDEA Annotations High
Product pom url http://www.jetbrains.org Medium
Version file version 13.0 High
Version gradle version 13.0 Highest
Version pom version 13.0 Highest
pkg:maven/org.jetbrains/annotations@13.0
(Confidence :High)
annotations-16.0.3.jar
Description:
A set of annotations used for code inspection support and code documentation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/license/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains/annotations/16.0.3/62c7299ced2a089cc541726c6d763da9417604a0/annotations-16.0.3.jar
MD5: a60b96e694740dc7dc0272d637efe978
SHA1: 62c7299ced2a089cc541726c6d763da9417604a0
SHA256: 04b16e8d2309bf7771fbee16187b76f63af6ccd023cf664ec846e4e8e65c5b3f
Referenced In Project/Scope: server-start:runtimeClasspath
annotations-16.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name annotations High
Vendor gradle artifactid annotations Highest
Vendor gradle groupid org.jetbrains Highest
Vendor jar package name annotations Highest
Vendor jar package name annotations Low
Vendor jar package name intellij Low
Vendor jar package name jetbrains Highest
Vendor jar package name lang Low
Vendor Manifest automatic-module-name org.jetbrains.annotations Medium
Vendor pom artifactid annotations Low
Vendor pom developer id JetBrains Medium
Vendor pom developer name JetBrains Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains Highest
Vendor pom name JetBrains Java Annotations High
Vendor pom url JetBrains/java-annotations Highest
Product file name annotations High
Product gradle artifactid annotations Highest
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name jetbrains Highest
Product jar package name lang Low
Product Manifest automatic-module-name org.jetbrains.annotations Medium
Product pom artifactid annotations Highest
Product pom developer id JetBrains Low
Product pom developer name JetBrains Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains Highest
Product pom name JetBrains Java Annotations High
Product pom url JetBrains/java-annotations High
Version file version 16.0.3 High
Version gradle version 16.0.3 Highest
Version pom version 16.0.3 Highest
pkg:maven/org.jetbrains/annotations@16.0.3
(Confidence :High)
annotations-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/annotations/2.26.30/fc6a40f655c0371f5ccca4e879f89210eff05859/annotations-2.26.30.jar
MD5: 2e49fb2261df1fc73d25961d17a455ff
SHA1: fc6a40f655c0371f5ccca4e879f89210eff05859
SHA256: 587893dfeaa070172c0187c22617f0864c473eccb7b6e724614e2b17a66f69de
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
annotations-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name annotations High
Vendor gradle artifactid annotations Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name annotations Highest
Vendor jar package name awssdk Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.annotations Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid annotations Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Annotations High
Vendor pom parent-artifactid core Low
Product file name annotations High
Product gradle artifactid annotations Highest
Product jar package name amazon Highest
Product jar package name annotations Highest
Product jar package name awssdk Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.annotations Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid annotations Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Annotations High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
antlr-2.7.7.jar
Description:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/antlr/antlr/2.7.7/83cd2cd674a217ade95a4bb83a8a14f351f48bd0/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
SHA256: 88fbda4b912596b9f56e8e12e580cc954bacfb51776ecfddd3e18fc1cf56dc4c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
antlr-2.7.7.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name antlr High
Vendor gradle artifactid antlr Highest
Vendor gradle groupid antlr Highest
Vendor jar package name antlr Low
Vendor pom artifactid antlr Low
Vendor pom groupid antlr Highest
Vendor pom name AntLR Parser Generator High
Vendor pom url http://www.antlr.org/ Highest
Product file name antlr High
Product gradle artifactid antlr Highest
Product pom artifactid antlr Highest
Product pom groupid antlr Highest
Product pom name AntLR Parser Generator High
Product pom url http://www.antlr.org/ Medium
Version file version 2.7.7 High
Version gradle version 2.7.7 Highest
Version pom version 2.7.7 Highest
pkg:maven/antlr/antlr@2.7.7
(Confidence :High)
aopalliance-repackaged-3.0.6.jar
Description:
Dependency Injection Kernel
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.hk2.external/aopalliance-repackaged/3.0.6/e3c3f17b649c97155640616026bd32b1043b3c1d/aopalliance-repackaged-3.0.6.jar
MD5: e07024ce0f95aa4a8797257c97fa5774
SHA1: e3c3f17b649c97155640616026bd32b1043b3c1d
SHA256: a82b6d1a348324ef88dc807c7cd7aaf633985cbff7b30036fb61a1b86981d840
Referenced In Project/Scope: server-start:webapps
aopalliance-repackaged-3.0.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name aopalliance-repackaged High
Vendor gradle artifactid aopalliance-repackaged Highest
Vendor gradle groupid org.glassfish.hk2.external Highest
Vendor jar package name aopalliance Highest
Vendor Manifest automatic-module-name org.aopalliance Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname org.glassfish.hk2.external.aopalliance-repackaged Medium
Vendor pom artifactid aopalliance-repackaged Low
Vendor pom groupid org.glassfish.hk2.external Highest
Vendor pom name aopalliance version repackaged as a module High
Vendor pom name aopalliance version ${aopalliance.version} repackaged as a module High
Vendor pom parent-artifactid external Low
Vendor pom parent-groupid org.glassfish.hk2 Medium
Product file name aopalliance-repackaged High
Product gradle artifactid aopalliance-repackaged Highest
Product jar package name aopalliance Highest
Product Manifest automatic-module-name org.aopalliance Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name aopalliance version 1.0 repackaged as a module Medium
Product Manifest bundle-symbolicname org.glassfish.hk2.external.aopalliance-repackaged Medium
Product pom artifactid aopalliance-repackaged Highest
Product pom groupid org.glassfish.hk2.external Highest
Product pom name aopalliance version repackaged as a module High
Product pom name aopalliance version ${aopalliance.version} repackaged as a module High
Product pom parent-artifactid external Medium
Product pom parent-groupid org.glassfish.hk2 Medium
Version file version 3.0.6 High
Version gradle version 3.0.6 Highest
Version Manifest Bundle-Version 3.0.6 High
Version pom version 3.0.6 Highest
pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@3.0.6
(Confidence :High)
apache-client-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/apache-client/2.26.30/4bc6cd588501005d1bd222eba6b934b4918542ad/apache-client-2.26.30.jar
MD5: 60da56a9cbc4aa2bc862de8a7b090aa2
SHA1: 4bc6cd588501005d1bd222eba6b934b4918542ad
SHA256: 971284e89d83ee7815b445c8b0eb921011b26d439d789bfea68c8de4db8713bf
Referenced In Project/Scope: server-start:runtimeClasspath
apache-client-2.26.30.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name apache-client High
Vendor gradle artifactid apache-client Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.apache Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid apache-client Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Clients :: Apache High
Vendor pom parent-artifactid http-clients Low
Product file name apache-client High
Product gradle artifactid apache-client Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.apache Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid apache-client Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Clients :: Apache High
Product pom parent-artifactid http-clients Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
apache-mime4j-core-0.8.6.jar
Description:
Java stream based MIME message parser
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.james/apache-mime4j-core/0.8.6/16b8375bb4d83cbe666271bad4c22da4a10b7998/apache-mime4j-core-0.8.6.jar
MD5: 995ce31d0508bde7694fd68dcabc247e
SHA1: 16b8375bb4d83cbe666271bad4c22da4a10b7998
SHA256: 54b1eb9af58cd66126c1c95d5b8aa50eedd919b5e2f8b59b202f183a4eac4d5d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
apache-mime4j-core-0.8.6.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name apache-mime4j-core High
Vendor gradle artifactid apache-mime4j-core Highest
Vendor gradle groupid org.apache.james Highest
Vendor jar package name apache Highest
Vendor jar package name james Highest
Vendor jar package name mime4j Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid apache-mime4j-core Low
Vendor pom groupid org.apache.james Highest
Vendor pom name Apache James :: Mime4j :: Core High
Vendor pom parent-artifactid apache-mime4j-project Low
Product file name apache-mime4j-core High
Product gradle artifactid apache-mime4j-core Highest
Product jar package name apache Highest
Product jar package name james Highest
Product jar package name mime4j Highest
Product jar package name parser Highest
Product jar package name stream Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache James :: Mime4j :: Core Medium
Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Product Manifest Implementation-Title Apache James :: Mime4j :: Core High
Product Manifest specification-title Apache James :: Mime4j :: Core Medium
Product pom artifactid apache-mime4j-core Highest
Product pom groupid org.apache.james Highest
Product pom name Apache James :: Mime4j :: Core High
Product pom parent-artifactid apache-mime4j-project Medium
Version file version 0.8.6 High
Version gradle version 0.8.6 Highest
Version Manifest Bundle-Version 0.8.6 High
Version Manifest Implementation-Version 0.8.6 High
Version pom version 0.8.6 Highest
CVE-2024-21742 suppress
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message.
This can be exploited by an attacker to add unintended headers to MIME messages.
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
api-1.0.0.jar
Description:
Core API for building connectors for the TRANSCONNECT platform
License:
MIT License: https://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/api/1.0.0/de704a8f0d316c2d29eb8bc69b54f8748877d7d0/api-1.0.0.jar
MD5: dccde4a80b081461b1201ea44eff271c
SHA1: de704a8f0d316c2d29eb8bc69b54f8748877d7d0
SHA256: 74ef0b6b508b7a28ee6725fc0119c2e544e208d73ef3b7c98a805d4e4170f3f8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
api-1.0.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name api High
Vendor gradle artifactid api Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Vendor pom artifactid api Low
Vendor pom developer email development@transconnect.io Low
Vendor pom developer id TCDEV Medium
Vendor pom developer name TRANSCONNECT Development Team Medium
Vendor pom groupid io.transconnect.connector Highest
Vendor pom name api High
Vendor pom url https://www.transconnect.io/ Highest
Product file name api High
Product gradle artifactid api Highest
Product jar package name api Low
Product jar package name connector Low
Product jar package name transconnect Low
Product pom artifactid api Highest
Product pom developer email development@transconnect.io Low
Product pom developer id TCDEV Low
Product pom developer name TRANSCONNECT Development Team Low
Product pom groupid io.transconnect.connector Highest
Product pom name api High
Product pom url https://www.transconnect.io/ Medium
Version file version 1.0.0 High
Version gradle version 1.0.0 Highest
Version pom version 1.0.0 Highest
pkg:maven/io.transconnect.connector/api@1.0.0
(Confidence :High)
arns-2.26.30.jar
Description:
The AWS SDK for Java - Arns module holds the classes that are related to AWS ARN
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/arns/2.26.30/b55ec56c1b0e5caab5265bf1e80f8c98f53b7db0/arns-2.26.30.jar
MD5: 76f8539bbccde6cd802c3b95f53fd73a
SHA1: b55ec56c1b0e5caab5265bf1e80f8c98f53b7db0
SHA256: 60ad49543ddf3d73f178a7946057381fd3179b32de02a5a19bf0b13b0c81f027
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
arns-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name arns High
Vendor gradle artifactid arns Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name arns Highest
Vendor jar package name awssdk Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.arns Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid arns Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Arns High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name arns High
Product gradle artifactid arns Highest
Product jar package name amazon Highest
Product jar package name arns Highest
Product jar package name awssdk Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.arns Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid arns Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Arns High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
asm-9.7.jar
Description:
ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm/9.7/73d7b3086e14beb604ced229c302feff6449723/asm-9.7.jar
MD5: 3957b18bf02a62edcb6726d074b90b08
SHA1: 073d7b3086e14beb604ced229c302feff6449723
SHA256: adf46d5e34940bdf148ecdd26a9ee8eea94496a72034ff7141066b3eea5c4e9d
Referenced In Project/Scope: server-start:jacocoAnt
asm-9.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor gradle artifactid asm Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Vendor pom artifactid asm Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm High
Product gradle artifactid asm Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Product pom artifactid asm Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.7 High
Version gradle version 9.7 Highest
Version Manifest Bundle-Version 9.7 High
Version Manifest Implementation-Version 9.7 High
Version pom parent-version 9.7 Low
Version pom version 9.7 Highest
pkg:maven/org.ow2.asm/asm@9.7
(Confidence :High)
asm-9.8.jar
Description:
ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm/9.8/dc19ecb3f7889b7860697215cae99c0f9b6f6b4b/asm-9.8.jar
MD5: f5adf3bfc54fb3d2cd8e3a1f275084bc
SHA1: dc19ecb3f7889b7860697215cae99c0f9b6f6b4b
SHA256: 876eab6a83daecad5ca67eb9fcabb063c97b5aeb8cf1fca7a989ecde17522051
Referenced In Project/Scope: server-start:webapps
asm-9.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor gradle artifactid asm Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Vendor pom artifactid asm Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm High
Product gradle artifactid asm Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Product pom artifactid asm Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.8 High
Version gradle version 9.8 Highest
Version Manifest Bundle-Version 9.8 High
Version Manifest Implementation-Version 9.8 High
Version pom parent-version 9.8 Low
Version pom version 9.8 Highest
pkg:maven/org.ow2.asm/asm@9.8
(Confidence :High)
asm-9.9.1.jar
Description:
ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm/9.9.1/2ceea6ab43bcae1979b2a6d85fc0ca429877e5ab/asm-9.9.1.jar
MD5: 1888ad1f49038441bb2d12aa6dffe396
SHA1: 2ceea6ab43bcae1979b2a6d85fc0ca429877e5ab
SHA256: 6f3828a215c920059a5efa2fb55c233d6c54ec5cadca99ce1b1bdd10077c7ddd
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
asm-9.9.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor gradle artifactid asm Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Vendor pom artifactid asm Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm High
Product gradle artifactid asm Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Product pom artifactid asm Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version gradle version 9.9.1 Highest
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm@9.9.1
(Confidence :High)
asm-commons-9.7.jar
Description:
Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm-commons/9.7/e86dda4696d3c185fcc95d8d311904e7ce38a53f/asm-commons-9.7.jar
MD5: 53a46610df6a8dbc4ff85b8fd4cdea66
SHA1: e86dda4696d3c185fcc95d8d311904e7ce38a53f
SHA256: 389bc247958e049fc9a0408d398c92c6d370c18035120395d4cba1d9d9304b7a
Referenced In Project/Scope: server-start:jacocoAnt
asm-commons-9.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
Evidence
Type Source Name Value Confidence
Vendor file name asm-commons High
Vendor gradle artifactid asm-commons Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name commons Highest
Vendor jar package name commons Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Vendor pom artifactid asm-commons Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-commons High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-commons High
Product gradle artifactid asm-commons Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name commons Highest
Product jar package name commons Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.commons Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Product Manifest Implementation-Title Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Product pom artifactid asm-commons Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-commons High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.7 High
Version gradle version 9.7 Highest
Version Manifest Bundle-Version 9.7 High
Version Manifest Implementation-Version 9.7 High
Version pom parent-version 9.7 Low
Version pom version 9.7 Highest
pkg:maven/org.ow2.asm/asm-commons@9.7
(Confidence :High)
asm-commons-9.9.1.jar
Description:
Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm-commons/9.9.1/ab35de4c537184a09339069f1a3b3aacf2289149/asm-commons-9.9.1.jar
MD5: 7e0ef716c43d92d29e666f820df24e2c
SHA1: ab35de4c537184a09339069f1a3b3aacf2289149
SHA256: c2319e014ce7199f2b7f7d56d6bb991863168c3f4b6cd6c9f542a4937ef7ef88
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
asm-commons-9.9.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name asm-commons High
Vendor gradle artifactid asm-commons Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name commons Highest
Vendor jar package name commons Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Vendor pom artifactid asm-commons Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-commons High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-commons High
Product gradle artifactid asm-commons Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name commons Highest
Product jar package name commons Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.commons Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.commons Medium
Product Manifest Implementation-Title Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low
Product pom artifactid asm-commons Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-commons High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version gradle version 9.9.1 Highest
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm-commons@9.9.1
(Confidence :High)
asm-tree-9.7.jar
Description:
Tree API of ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm-tree/9.7/e446a17b175bfb733b87c5c2560ccb4e57d69f1a/asm-tree-9.7.jar
MD5: ea5cad3e0cbd2520688e4b0b5c4218e7
SHA1: e446a17b175bfb733b87c5c2560ccb4e57d69f1a
SHA256: 62f4b3bc436045c1acb5c3ba2d8ec556ec3369093d7f5d06c747eb04b56d52b1
Referenced In Project/Scope: server-start:jacocoAnt
asm-tree-9.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
Evidence
Type Source Name Value Confidence
Vendor file name asm-tree High
Vendor gradle artifactid asm-tree Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor jar package name tree Highest
Vendor jar package name tree Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true Low
Vendor pom artifactid asm-tree Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-tree High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-tree High
Product gradle artifactid asm-tree Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product jar package name tree Highest
Product jar package name tree Low
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.tree Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Product Manifest Implementation-Title Tree API of ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true Low
Product pom artifactid asm-tree Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-tree High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.7 High
Version gradle version 9.7 Highest
Version Manifest Bundle-Version 9.7 High
Version Manifest Implementation-Version 9.7 High
Version pom parent-version 9.7 Low
Version pom version 9.7 Highest
pkg:maven/org.ow2.asm/asm-tree@9.7
(Confidence :High)
asm-tree-9.9.1.jar
Description:
Tree API of ASM, a very small and fast Java bytecode manipulation framework
License:
BSD-3-Clause: https://asm.ow2.io/license.html
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.asm/asm-tree/9.9.1/b6b1b3366296163b4b1f540731aad0a2baa484d8/asm-tree-9.9.1.jar
MD5: 7eb17cd0d09b03fbe473e51edfc6e4d2
SHA1: b6b1b3366296163b4b1f540731aad0a2baa484d8
SHA256: 0f3555096b720b820bbacab0b515589bee0200bee099bda14c561738ae837ba1
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
asm-tree-9.9.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name asm-tree High
Vendor gradle artifactid asm-tree Highest
Vendor gradle groupid org.ow2.asm Highest
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor jar package name tree Highest
Vendor jar package name tree Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Vendor Manifest module-requires org.objectweb.asm;transitive=true Low
Vendor pom artifactid asm-tree Low
Vendor pom developer email ebruneton@free.fr Low
Vendor pom developer email eu@javatx.org Low
Vendor pom developer email forax@univ-mlv.fr Low
Vendor pom developer id ebruneton Medium
Vendor pom developer id eu Medium
Vendor pom developer id forax Medium
Vendor pom developer name Eric Bruneton Medium
Vendor pom developer name Eugene Kuleshov Medium
Vendor pom developer name Remi Forax Medium
Vendor pom groupid org.ow2.asm Highest
Vendor pom name asm-tree High
Vendor pom organization name OW2 High
Vendor pom organization url http://www.ow2.org/ Medium
Vendor pom parent-artifactid ow2 Low
Vendor pom parent-groupid org.ow2 Medium
Vendor pom url http://asm.ow2.io/ Highest
Product file name asm-tree High
Product gradle artifactid asm-tree Highest
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product jar package name tree Highest
Product jar package name tree Low
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm.tree Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm.tree Medium
Product Manifest Implementation-Title Tree API of ASM, a very small and fast Java bytecode manipulation framework High
Product Manifest module-requires org.objectweb.asm;transitive=true Low
Product pom artifactid asm-tree Highest
Product pom developer email ebruneton@free.fr Low
Product pom developer email eu@javatx.org Low
Product pom developer email forax@univ-mlv.fr Low
Product pom developer id ebruneton Low
Product pom developer id eu Low
Product pom developer id forax Low
Product pom developer name Eric Bruneton Low
Product pom developer name Eugene Kuleshov Low
Product pom developer name Remi Forax Low
Product pom groupid org.ow2.asm Highest
Product pom name asm-tree High
Product pom organization name OW2 Low
Product pom organization url http://www.ow2.org/ Low
Product pom parent-artifactid ow2 Medium
Product pom parent-groupid org.ow2 Medium
Product pom url http://asm.ow2.io/ Medium
Version file version 9.9.1 High
Version gradle version 9.9.1 Highest
Version Manifest Bundle-Version 9.9.1 High
Version Manifest Implementation-Version 9.9.1 High
Version pom parent-version 9.9.1 Low
Version pom version 9.9.1 Highest
pkg:maven/org.ow2.asm/asm-tree@9.9.1
(Confidence :High)
auth-2.26.30.jar
Description:
The AWS SDK for Java - Auth module holds the classes that are used for authentication with services
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/auth/2.26.30/f081c8a49463e7716d9efe62daf415e9b31fb755/auth-2.26.30.jar
MD5: de5d9200b5ca9a5128103d49f976e0fe
SHA1: f081c8a49463e7716d9efe62daf415e9b31fb755
SHA256: 9624595c69b59c28ff3b2a7bee900ef137784bf2284b03b8be5353e364d58036
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
auth-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name auth High
Vendor gradle artifactid auth Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name auth Highest
Vendor jar package name awssdk Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.auth Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid auth Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Auth High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name auth High
Product gradle artifactid auth Highest
Product jar package name amazon Highest
Product jar package name auth Highest
Product jar package name awssdk Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.auth Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid auth Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Auth High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
aws-core-2.26.30.jar
Description:
The AWS SDK for Java - Core runtime module holds the classes that are used by the individual service
clients to interact with
Amazon Web Services. Users need to depend on aws-java-sdk artifact for accessing individual client classes.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/aws-core/2.26.30/1cf658353d15cd9d754b2821949670bbefa05917/aws-core-2.26.30.jar
MD5: ca41ab80443651616b4fd4cfb10c2bc1
SHA1: 1cf658353d15cd9d754b2821949670bbefa05917
SHA256: a3266c362cd67668b32c1991cf3748776d1e3bfbf31bd4fcb81aa4b989687da0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
aws-core-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name aws-core High
Vendor gradle artifactid aws-core Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awscore Highest
Vendor jar package name awssdk Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.awscore Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid aws-core Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: AWS Core High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name aws-core High
Product gradle artifactid aws-core Highest
Product jar package name amazon Highest
Product jar package name awscore Highest
Product jar package name awssdk Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.awscore Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid aws-core Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: AWS Core High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
aws-query-protocol-2.26.30.jar
Description:
The AWS SDK for Java - module holds the classes for AWS Query protocol
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/aws-query-protocol/2.26.30/9682ec15a6ddff748649c4e7ccde8d1f36343455/aws-query-protocol-2.26.30.jar
MD5: 97aa81a1c50c6c21c213a64a8237d27a
SHA1: 9682ec15a6ddff748649c4e7ccde8d1f36343455
SHA256: 8e6e41ac07cfef3ca5c8eb3803ce2840fb7ea1bc622f78db5a9f8466da560bb6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
aws-query-protocol-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name aws-query-protocol High
Vendor gradle artifactid aws-query-protocol Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name protocols Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.protocols.query Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid aws-query-protocol Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Core :: Protocols :: AWS Query Protocol High
Vendor pom parent-artifactid protocols Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name aws-query-protocol High
Product gradle artifactid aws-query-protocol Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name protocols Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.protocols.query Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid aws-query-protocol Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Core :: Protocols :: AWS Query Protocol High
Product pom parent-artifactid protocols Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
aws-xml-protocol-2.26.30.jar
Description:
The AWS SDK for Java - module holds the classes for AWS Xml protocol
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/aws-xml-protocol/2.26.30/d4e6b7bd10e5332fc315cd288eb3fb905a1d1f11/aws-xml-protocol-2.26.30.jar
MD5: 28bbd9c7d60d13ca5d052a8010b5f889
SHA1: d4e6b7bd10e5332fc315cd288eb3fb905a1d1f11
SHA256: 1c3e7e9bcf4169329f19a3b5732ba7a42123d56e197f3e7d156e2dc8e31377e7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
aws-xml-protocol-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name aws-xml-protocol High
Vendor gradle artifactid aws-xml-protocol Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name protocols Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.protocols.xml Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid aws-xml-protocol Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Core :: Protocols :: AWS Xml Protocol High
Vendor pom parent-artifactid protocols Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name aws-xml-protocol High
Product gradle artifactid aws-xml-protocol Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name protocols Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.protocols.xml Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid aws-xml-protocol Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Core :: Protocols :: AWS Xml Protocol High
Product pom parent-artifactid protocols Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
axiom-api-1.4.0.jar
Description:
The Axiom API
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.commons.axiom/axiom-api/1.4.0/29232349f732f0555f2cda4457e6e1dafec48859/axiom-api-1.4.0.jar
MD5: 38d3b8711eb524adb3ee67b0462da875
SHA1: 29232349f732f0555f2cda4457e6e1dafec48859
SHA256: 3bc96fa1e977be387f01ec983c60c8a9dd7ead7fbbb5b37297e6a5c72462d795
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
axiom-api-1.4.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axiom-api High
Vendor gradle artifactid axiom-api Highest
Vendor gradle groupid org.apache.ws.commons.axiom Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name axiom Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-api Medium
Vendor pom artifactid axiom-api Low
Vendor pom groupid org.apache.ws.commons.axiom Highest
Vendor pom name Axiom API High
Vendor pom parent-artifactid axiom Low
Vendor pom url http://ws.apache.org/axiom/ Highest
Product file name axiom-api High
Product gradle artifactid axiom-api Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name axiom Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Axiom API Medium
Product Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-api Medium
Product pom artifactid axiom-api Highest
Product pom groupid org.apache.ws.commons.axiom Highest
Product pom name Axiom API High
Product pom parent-artifactid axiom Medium
Product pom url http://ws.apache.org/axiom/ Medium
Version file version 1.4.0 High
Version gradle version 1.4.0 Highest
Version Manifest Bundle-Version 1.4.0 High
Version pom version 1.4.0 Highest
pkg:maven/org.apache.ws.commons.axiom/axiom-api@1.4.0
(Confidence :High)
axiom-compat-1.4.0.jar
Description:
Contains deprecated classes that will disappear in the next major release.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.commons.axiom/axiom-compat/1.4.0/a69be40ff5a8b6b69a46745fef6d9524d19f40d6/axiom-compat-1.4.0.jar
MD5: 9c438ea8c661025f79503b71ef46c3e1
SHA1: a69be40ff5a8b6b69a46745fef6d9524d19f40d6
SHA256: 8e0e94055c40cac38f7773bde5ee6b1c8d91684c317e34def27e17642b7c2bf5
Referenced In Project/Scope: server-start:runtimeClasspath
axiom-compat-1.4.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axiom-compat High
Vendor gradle artifactid axiom-compat Highest
Vendor gradle groupid org.apache.ws.commons.axiom Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name axiom Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axiom-compat Low
Vendor pom groupid org.apache.ws.commons.axiom Highest
Vendor pom name Axiom Compatibility Classes High
Vendor pom parent-artifactid axiom Low
Product file name axiom-compat High
Product gradle artifactid axiom-compat Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name axiom Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Axiom Compatibility Classes High
Product Manifest specification-title Axiom Compatibility Classes Medium
Product pom artifactid axiom-compat Highest
Product pom groupid org.apache.ws.commons.axiom Highest
Product pom name Axiom Compatibility Classes High
Product pom parent-artifactid axiom Medium
Version file version 1.4.0 High
Version gradle version 1.4.0 Highest
Version Manifest Implementation-Version 1.4.0 High
Version pom version 1.4.0 Highest
pkg:maven/org.apache.ws.commons.axiom/axiom-compat@1.4.0
(Confidence :High)
axiom-dom-1.4.0.jar
Description:
An implementation of the Axiom API that also implements DOM.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.commons.axiom/axiom-dom/1.4.0/ce6d6347785e4d29234f10502af0f468fe8f3cd5/axiom-dom-1.4.0.jar
MD5: ebd5980bf365d24311a1282738e663ac
SHA1: ce6d6347785e4d29234f10502af0f468fe8f3cd5
SHA256: 07da590bac8c900680e871ade45ecc2bacfc578c368fdb849c028802009864ad
Referenced In Project/Scope: server-start:runtimeClasspath
axiom-dom-1.4.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axiom-dom High
Vendor gradle artifactid axiom-dom Highest
Vendor gradle groupid org.apache.ws.commons.axiom Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name axiom Highest
Vendor jar package name dom Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-dom Medium
Vendor pom artifactid axiom-dom Low
Vendor pom groupid org.apache.ws.commons.axiom Highest
Vendor pom name DOOM High
Vendor pom parent-artifactid implementations Low
Product file name axiom-dom High
Product gradle artifactid axiom-dom Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name axiom Highest
Product jar package name dom Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name DOOM Medium
Product Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-dom Medium
Product pom artifactid axiom-dom Highest
Product pom groupid org.apache.ws.commons.axiom Highest
Product pom name DOOM High
Product pom parent-artifactid implementations Medium
Version file version 1.4.0 High
Version gradle version 1.4.0 Highest
Version Manifest Bundle-Version 1.4.0 High
Version pom version 1.4.0 Highest
pkg:maven/org.apache.ws.commons.axiom/axiom-dom@1.4.0
(Confidence :High)
axiom-impl-1.4.0.jar
Description:
The default implementation of the Axiom API.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.commons.axiom/axiom-impl/1.4.0/328594317d79ce5c071af6625657982662867a04/axiom-impl-1.4.0.jar
MD5: 0d7624f016a8ab4cd6f9b34b3f9ad88f
SHA1: 328594317d79ce5c071af6625657982662867a04
SHA256: cba1998d5cb436fd979b3ad1ea82e5301006ee8f70e39ff65abe0725c642cfd8
Referenced In Project/Scope: server-start:runtimeClasspath
axiom-impl-1.4.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axiom-impl High
Vendor gradle artifactid axiom-impl Highest
Vendor gradle groupid org.apache.ws.commons.axiom Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name axiom Highest
Vendor jar package name impl Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-impl Medium
Vendor pom artifactid axiom-impl Low
Vendor pom groupid org.apache.ws.commons.axiom Highest
Vendor pom name LLOM High
Vendor pom parent-artifactid implementations Low
Product file name axiom-impl High
Product gradle artifactid axiom-impl Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name axiom Highest
Product jar package name impl Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name LLOM Medium
Product Manifest bundle-symbolicname org.apache.ws.commons.axiom.axiom-impl Medium
Product pom artifactid axiom-impl Highest
Product pom groupid org.apache.ws.commons.axiom Highest
Product pom name LLOM High
Product pom parent-artifactid implementations Medium
Version file version 1.4.0 High
Version gradle version 1.4.0 Highest
Version Manifest Bundle-Version 1.4.0 High
Version pom version 1.4.0 Highest
pkg:maven/org.apache.ws.commons.axiom/axiom-impl@1.4.0
(Confidence :High)
axis2-adb-1.8.2.jar
Description:
Axis2 Data Binding module
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-adb/1.8.2/b5524059212283592bf31a5da19a170ca87c23f/axis2-adb-1.8.2.jar
MD5: fdd109781c4ee541fecc9833dd337809
SHA1: 0b5524059212283592bf31a5da19a170ca87c23f
SHA256: ed298ba22672768b31bf07f12c7744062faf7355982e4dbe3079ee1064b0b824
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-adb-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-adb High
Vendor gradle artifactid axis2-adb Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-adb Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Data Binding High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-adb High
Product gradle artifactid axis2-adb Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Data Binding High
Product Manifest specification-title Apache Axis2 - Data Binding Medium
Product pom artifactid axis2-adb Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Data Binding High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-adb-codegen-1.8.2.jar
Description:
ADB code generation support for Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-adb-codegen/1.8.2/4cb7ca75a1bf607c10c8a82f9ae94327e6eafc8/axis2-adb-codegen-1.8.2.jar
MD5: 234a8737f304555ed8136f45c57dd9fc
SHA1: 04cb7ca75a1bf607c10c8a82f9ae94327e6eafc8
SHA256: dd9457b6d510cb96a312b6a2d43baeaa88e759b85a40447c2987f25e064527aa
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-adb-codegen-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-adb-codegen High
Vendor gradle artifactid axis2-adb-codegen Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-adb-codegen Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - ADB Codegen High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-adb-codegen High
Product gradle artifactid axis2-adb-codegen Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - ADB Codegen High
Product Manifest specification-title Apache Axis2 - ADB Codegen Medium
Product pom artifactid axis2-adb-codegen Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - ADB Codegen High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-codegen-1.8.2.jar
Description:
Axis2 Code Generation module
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-codegen/1.8.2/43e17c3ae89048ed4923bd913f2267f4443866/axis2-codegen-1.8.2.jar
MD5: a2cc1b3e3839dd75f90fdd5ec7a7db40
SHA1: 0043e17c3ae89048ed4923bd913f2267f4443866
SHA256: e41353debf123e82e37d47ae0e1bee3f3dc7abc201c5adc88dc37050e06d9136
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-codegen-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-codegen High
Vendor gradle artifactid axis2-codegen Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name codegen Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-codegen Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Code Generation High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-codegen High
Product gradle artifactid axis2-codegen Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name codegen Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Code Generation High
Product Manifest specification-title Apache Axis2 - Code Generation Medium
Product pom artifactid axis2-codegen Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Code Generation High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-corba-1.8.2.jar
Description:
Axis2 CORBA module
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-corba/1.8.2/56ccbd9954703f525452ea37c8c83a3c2227fbe5/axis2-corba-1.8.2.jar
MD5: 60c0b5b99ade8fbb6a396a6bc4d141f2
SHA1: 56ccbd9954703f525452ea37c8c83a3c2227fbe5
SHA256: 8e74d42b07499c9b68fb088f54ddcf282a33aa5b67540b80e1a310eb7c86078b
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-corba-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-corba High
Vendor gradle artifactid axis2-corba Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name corba Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-corba Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - CORBA High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-corba High
Product gradle artifactid axis2-corba Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name corba Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - CORBA High
Product Manifest specification-title Apache Axis2 - CORBA Medium
Product pom artifactid axis2-corba Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - CORBA High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-fastinfoset-1.8.2.jar
Description:
Axis2 Fast Infoset module
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-fastinfoset/1.8.2/de14899147264d7c8040f1f2a5ddc4598ab53ed0/axis2-fastinfoset-1.8.2.jar
MD5: 939d14b9e89fd3a3b78aa91cfe1c3799
SHA1: de14899147264d7c8040f1f2a5ddc4598ab53ed0
SHA256: f877355bc8b24477c2cb490ae7d39d52fe85d362443984bb241c59cc3e2ac6cb
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-fastinfoset-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-fastinfoset High
Vendor gradle artifactid axis2-fastinfoset Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name fastinfoset Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-fastinfoset Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Fast Infoset High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-fastinfoset High
Product gradle artifactid axis2-fastinfoset Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name fastinfoset Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Fast Infoset High
Product Manifest specification-title Apache Axis2 - Fast Infoset Medium
Product pom artifactid axis2-fastinfoset Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Fast Infoset High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-java2wsdl-1.8.2.jar
Description:
To generate WSDL file for a given Java class
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-java2wsdl/1.8.2/38b8881f89bde6e3508e613c715dab8b816f7446/axis2-java2wsdl-1.8.2.jar
MD5: e62fc1438a2e2bdcbd0f1fad95e8b1aa
SHA1: 38b8881f89bde6e3508e613c715dab8b816f7446
SHA256: 3cd3bb186cb7f74b12ad1eacb380d7c8de31766004c20a5aa2499b6d68712e03
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-java2wsdl-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-java2wsdl High
Vendor gradle artifactid axis2-java2wsdl Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name java2wsdl Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-java2wsdl Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Java2WSDL High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-java2wsdl High
Product gradle artifactid axis2-java2wsdl Highest
Product jar package name apache Highest
Product jar package name java2wsdl Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Java2WSDL High
Product Manifest specification-title Apache Axis2 - Java2WSDL Medium
Product pom artifactid axis2-java2wsdl Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Java2WSDL High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-jaxbri-codegen-1.8.2.jar
Description:
JAXB-RI data binding support for Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-jaxbri-codegen/1.8.2/84661a7972ef9395cb9c42926a5f3eb13aac3bdd/axis2-jaxbri-codegen-1.8.2.jar
MD5: 26f3a65c127c0d87e7863cabd9739ceb
SHA1: 84661a7972ef9395cb9c42926a5f3eb13aac3bdd
SHA256: 3ce6b4f65b2d33ad35dfec78741ae342f7724a391591b5b5ea05618ce82dea69
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-jaxbri-codegen-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-jaxbri-codegen High
Vendor gradle artifactid axis2-jaxbri-codegen Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name jaxbri Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-jaxbri-codegen Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - JAXB-RI Data Binding High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-jaxbri-codegen High
Product gradle artifactid axis2-jaxbri-codegen Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name jaxbri Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - JAXB-RI Data Binding High
Product Manifest specification-title Apache Axis2 - JAXB-RI Data Binding Medium
Product pom artifactid axis2-jaxbri-codegen Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - JAXB-RI Data Binding High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-jaxws-1.8.2.jar
Description:
Axis2 JAXWS Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-jaxws/1.8.2/232ba53b69cad5c83e2fd9e0e628298fb453cf3d/axis2-jaxws-1.8.2.jar
MD5: 63df9299b4c2dcda4d231d75b6c489c6
SHA1: 232ba53b69cad5c83e2fd9e0e628298fb453cf3d
SHA256: cbdaae912142a0a43fce2c3bd2a19dd46552bc753c9a500b180c7b0fd127c1a6
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-jaxws-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-jaxws High
Vendor gradle artifactid axis2-jaxws Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name jaxws Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-jaxws Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - JAXWS High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-jaxws High
Product gradle artifactid axis2-jaxws Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name jaxws Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - JAXWS High
Product Manifest specification-title Apache Axis2 - JAXWS Medium
Product pom artifactid axis2-jaxws Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - JAXWS High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-jibx-1.8.2.jar
Description:
JiBX data binding support for Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-jibx/1.8.2/4ee416dfcda8d9dbd7f831eff633b4a7b0430586/axis2-jibx-1.8.2.jar
MD5: 4cb5ab7fb08251ff6eb3b53b499c334b
SHA1: 4ee416dfcda8d9dbd7f831eff633b4a7b0430586
SHA256: 592971b1c1d87613482ad245d9d5063a68c89593b41cec80525c4331dd70ab9b
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-jibx-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-jibx High
Vendor gradle artifactid axis2-jibx Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name jibx Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-jibx Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - JiBX Data Binding High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-jibx High
Product gradle artifactid axis2-jibx Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name jibx Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - JiBX Data Binding High
Product Manifest specification-title Apache Axis2 - JiBX Data Binding Medium
Product pom artifactid axis2-jibx Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - JiBX Data Binding High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-kernel-1.8.2.jar
Description:
Core Parts of Axis2. This includes Axis2 engine, Client API, Addressing support, etc.,
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-kernel/1.8.2/d4e09961e043adaba3853acf079fdd8a5caaf27a/axis2-kernel-1.8.2.jar
MD5: 87912df5a9e1699181ffaf9f07260522
SHA1: d4e09961e043adaba3853acf079fdd8a5caaf27a
SHA256: 4850157df9985e3b588659650916abac800ace5630435b357a6d1230f24ad32b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
axis2-kernel-1.8.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-kernel High
Vendor gradle artifactid axis2-kernel Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name addressing Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name client Highest
Vendor jar package name engine Highest
Vendor jar package name kernel Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-kernel Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Kernel High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-kernel High
Product gradle artifactid axis2-kernel Highest
Product jar package name addressing Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name client Highest
Product jar package name engine Highest
Product jar package name kernel Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Kernel High
Product Manifest specification-title Apache Axis2 - Kernel Medium
Product pom artifactid axis2-kernel Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Kernel High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-metadata-1.8.2.jar
Description:
JSR-181 and JSR-224 Annotations Processing
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-metadata/1.8.2/4de456dc1858db5c343e2bbedbb108da5c320558/axis2-metadata-1.8.2.jar
MD5: 160b9c5e619d033475e98ec521f73df2
SHA1: 4de456dc1858db5c343e2bbedbb108da5c320558
SHA256: 5fabf9c9b4b5768206bc95b7a34848e7ee152be9de68949f5b2af24eeb676ad9
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-metadata-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-metadata High
Vendor gradle artifactid axis2-metadata Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name metadata Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-metadata Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Metadata High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-metadata High
Product gradle artifactid axis2-metadata Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name metadata Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Metadata High
Product Manifest specification-title Apache Axis2 - Metadata Medium
Product pom artifactid axis2-metadata Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Metadata High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-mtompolicy-1.8.2.jar
Description:
Axis2 : MTOM Policy
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-mtompolicy/1.8.2/3d96b08dac4b088dc49a54bea23c9967d631492c/axis2-mtompolicy-1.8.2.jar
MD5: 970a17b514f839fd7bdfddff749b947d
SHA1: 3d96b08dac4b088dc49a54bea23c9967d631492c
SHA256: 84bac62164872009fb1c0f6bd75364aa017e2ad0352e95b9817978b42b482881
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
axis2-mtompolicy-1.8.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-mtompolicy High
Vendor gradle artifactid axis2-mtompolicy Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name policy Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-mtompolicy Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - MTOM Policy High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-mtompolicy High
Product gradle artifactid axis2-mtompolicy Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name policy Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - MTOM Policy High
Product Manifest specification-title Apache Axis2 - MTOM Policy Medium
Product pom artifactid axis2-mtompolicy Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - MTOM Policy High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-saaj-1.8.2.jar
Description:
Axis2 SAAJ implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-saaj/1.8.2/5ffe4fa423d9cddff83cb72a9e823f61555144be/axis2-saaj-1.8.2.jar
MD5: 3db2089d52ec1f9b8334ef7a5f411ad9
SHA1: 5ffe4fa423d9cddff83cb72a9e823f61555144be
SHA256: 641070cc8c600e3872092f5af76988835e55909c513b8388d35e292a31d386fb
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-saaj-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-saaj High
Vendor gradle artifactid axis2-saaj Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name saaj Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-saaj Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - SAAJ High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-saaj High
Product gradle artifactid axis2-saaj Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name saaj Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - SAAJ High
Product Manifest specification-title Apache Axis2 - SAAJ Medium
Product pom artifactid axis2-saaj Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - SAAJ High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-soapmonitor-servlet-1.8.2.jar
Description:
soapmonitor servlet for Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-soapmonitor-servlet/1.8.2/3b05be662ffee017962e2af2eb4f6f679d370c05/axis2-soapmonitor-servlet-1.8.2.jar
MD5: ca5a9ed9b8f039abeac16bc1ec9964b5
SHA1: 3b05be662ffee017962e2af2eb4f6f679d370c05
SHA256: 599c28b80609205743286cd50fa5112bf6f33d96b2194764c118af2e0d71433f
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-soapmonitor-servlet-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-soapmonitor-servlet High
Vendor gradle artifactid axis2-soapmonitor-servlet Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name servlet Highest
Vendor jar package name soapmonitor Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-soapmonitor-servlet Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - SOAP Monitor Servlet High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-soapmonitor-servlet High
Product gradle artifactid axis2-soapmonitor-servlet Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name servlet Highest
Product jar package name soapmonitor Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - SOAP Monitor Servlet High
Product Manifest specification-title Apache Axis2 - SOAP Monitor Servlet Medium
Product pom artifactid axis2-soapmonitor-servlet Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - SOAP Monitor Servlet High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-base-1.8.2.jar
Description:
Apache Axis2 - Base Transport
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-base/1.8.2/d44d4f765f8c5a49ba35fa5ffe53c2b50302d3de/axis2-transport-base-1.8.2.jar
MD5: ac71fb412d0569b6bcf18cef672ae153
SHA1: d44d4f765f8c5a49ba35fa5ffe53c2b50302d3de
SHA256: b897a865489a374a4d45a4dbbb5a79e9348b8b95e2a64386e7d4271388c13b4d
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-base-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-base High
Vendor gradle artifactid axis2-transport-base Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name base Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-base Medium
Vendor pom artifactid axis2-transport-base Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - Base High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-base High
Product gradle artifactid axis2-transport-base Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name base Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-base Medium
Product Manifest bundle-symbolicname axis2-transport-base Medium
Product pom artifactid axis2-transport-base Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - Base High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-http-1.8.2.jar
Description:
This inclues all the available transports in Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-http/1.8.2/5ea5f42cb9033ab6cdb10d364c4e84a25fba710f/axis2-transport-http-1.8.2.jar
MD5: 3b95e775ed7d9cdec81a741d56c14350
SHA1: 5ea5f42cb9033ab6cdb10d364c4e84a25fba710f
SHA256: da727bcaef9d01205bb530c4ea7bdcd344b800defdeb65cc0c0882db391d5599
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
axis2-transport-http-1.8.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-http High
Vendor gradle artifactid axis2-transport-http Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name http Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-transport-http Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - HTTP High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-http High
Product gradle artifactid axis2-transport-http Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name http Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - Transport - HTTP High
Product Manifest specification-title Apache Axis2 - Transport - HTTP Medium
Product pom artifactid axis2-transport-http Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - HTTP High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-jms-1.8.2.jar
Description:
Apache Axis2 - JMS Transport
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-jms/1.8.2/ad1b97bbe591c1baeadb99a7a3b6142e0a905b87/axis2-transport-jms-1.8.2.jar
MD5: 4e8a441201d85d9d4c6c03471d6f831a
SHA1: ad1b97bbe591c1baeadb99a7a3b6142e0a905b87
SHA256: 36c36b7d952f26c74a17e5508a21139a659d716ff895605c1d6ba4fcaaeb2e43
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-jms-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-jms High
Vendor gradle artifactid axis2-transport-jms Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name jms Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-jms Medium
Vendor pom artifactid axis2-transport-jms Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - JMS High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-jms High
Product gradle artifactid axis2-transport-jms Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name jms Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-jms Medium
Product Manifest bundle-symbolicname axis2-transport-jms Medium
Product pom artifactid axis2-transport-jms Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - JMS High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-local-1.8.2.jar
Description:
This inclues all the available transports in Axis2
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-local/1.8.2/dcb081b09a74099f1984673e0a6bd4a0a201937f/axis2-transport-local-1.8.2.jar
MD5: f3309955aadc0e594da94e86171c7aa6
SHA1: dcb081b09a74099f1984673e0a6bd4a0a201937f
SHA256: e7508c7883d52192511a389d45d237f0bed15afc9e25ef9cdc8a45bbebf7058c
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-local-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-local High
Vendor gradle artifactid axis2-transport-local Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name local Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-local Medium
Vendor pom artifactid axis2-transport-local Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - Local High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-local High
Product gradle artifactid axis2-transport-local Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name local Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-local Medium
Product Manifest bundle-symbolicname axis2-transport-local Medium
Product pom artifactid axis2-transport-local Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - Local High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-mail-1.8.2.jar
Description:
Apache Axis2 - Mail Transport
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-mail/1.8.2/c10a6989b99b37fbc7c539a3a485912d6e50e664/axis2-transport-mail-1.8.2.jar
MD5: c94f0fea50463da2d0a066cbf9a667c3
SHA1: c10a6989b99b37fbc7c539a3a485912d6e50e664
SHA256: a085708bfa7d0115572f53b91af45816863b2479624174a816f3e52e697387c2
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-mail-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-mail High
Vendor gradle artifactid axis2-transport-mail Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name mail Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-mail Medium
Vendor pom artifactid axis2-transport-mail Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - Mail High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-mail High
Product gradle artifactid axis2-transport-mail Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name mail Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-mail Medium
Product Manifest bundle-symbolicname axis2-transport-mail Medium
Product pom artifactid axis2-transport-mail Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - Mail High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-tcp-1.8.2.jar
Description:
This inclues all the available transports in Axis2
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-tcp/1.8.2/9de3b387839a75ba7f4e104c27bad7959e4ddbcb/axis2-transport-tcp-1.8.2.jar
MD5: cc0981794bcce2ed0f01e7aad8bb4e95
SHA1: 9de3b387839a75ba7f4e104c27bad7959e4ddbcb
SHA256: 3970c698005ab3d3a8902906444b04233b3918b26e9f6d6030fcda2ad6e806f6
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-tcp-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-tcp High
Vendor gradle artifactid axis2-transport-tcp Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name tcp Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-tcp Medium
Vendor pom artifactid axis2-transport-tcp Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - TCP High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-tcp High
Product gradle artifactid axis2-transport-tcp Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name tcp Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-tcp Medium
Product Manifest bundle-symbolicname axis2-transport-tcp Medium
Product pom artifactid axis2-transport-tcp Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - TCP High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-udp-1.8.2.jar
Description:
UDP transport for Axis2
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-udp/1.8.2/654da73f59c64e694ae13d2811bf3ded04dbfe9c/axis2-transport-udp-1.8.2.jar
MD5: 264ae2ec85cec1b8a205e9a34a184ad5
SHA1: 654da73f59c64e694ae13d2811bf3ded04dbfe9c
SHA256: eda14a611623e129e4978b75033167b5894064ed6fdaa5b94900b9e5b5d15121
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-udp-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-udp High
Vendor gradle artifactid axis2-transport-udp Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name transport Highest
Vendor jar package name udp Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-udp Medium
Vendor pom artifactid axis2-transport-udp Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - UDP High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-udp High
Product gradle artifactid axis2-transport-udp Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name transport Highest
Product jar package name udp Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-udp Medium
Product Manifest bundle-symbolicname axis2-transport-udp Medium
Product pom artifactid axis2-transport-udp Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - UDP High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-transport-xmpp-1.8.2.jar
Description:
This inclues all the available transports in Axis2
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-transport-xmpp/1.8.2/c825cee68e03372a18b8108aff4b70789508d27d/axis2-transport-xmpp-1.8.2.jar
MD5: a9994ec4dbdb4c9a88860f9701787c6e
SHA1: c825cee68e03372a18b8108aff4b70789508d27d
SHA256: 98be29abde7038efc717325eddfb28540467b4b0c1b87a2e507a8ad0ccdb2e8f
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-transport-xmpp-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-transport-xmpp High
Vendor gradle artifactid axis2-transport-xmpp Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name transport Highest
Vendor jar package name xmpp Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname axis2-transport-xmpp Medium
Vendor pom artifactid axis2-transport-xmpp Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - Transport - XMPP High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-transport-xmpp High
Product gradle artifactid axis2-transport-xmpp Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name transport Highest
Product jar package name xmpp Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name axis2-transport-xmpp Medium
Product Manifest bundle-symbolicname axis2-transport-xmpp Medium
Product pom artifactid axis2-transport-xmpp Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - Transport - XMPP High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Bundle-Version 1.8.2 High
Version pom version 1.8.2 Highest
axis2-xmlbeans-1.8.2.jar
Description:
XMLBeans data binding support for Axis2
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.axis2/axis2-xmlbeans/1.8.2/715ac0b934fc83597be5466631ea3e9592049272/axis2-xmlbeans-1.8.2.jar
MD5: 07cfe72d45bbe72b6862bb17cc864f0f
SHA1: 715ac0b934fc83597be5466631ea3e9592049272
SHA256: af059f743ef568b315343e84b974f16bd8a154fa834bdea194fab712ebb60702
Referenced In Project/Scope: server-start:runtimeClasspath
axis2-xmlbeans-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name axis2-xmlbeans High
Vendor gradle artifactid axis2-xmlbeans Highest
Vendor gradle groupid org.apache.axis2 Highest
Vendor jar package name apache Highest
Vendor jar package name axis2 Highest
Vendor jar package name xmlbeans Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid axis2-xmlbeans Low
Vendor pom groupid org.apache.axis2 Highest
Vendor pom name Apache Axis2 - XMLBeans Data Binding High
Vendor pom parent-artifactid axis2 Low
Vendor pom url http://axis.apache.org/axis2/java/core/ Highest
Product file name axis2-xmlbeans High
Product gradle artifactid axis2-xmlbeans Highest
Product jar package name apache Highest
Product jar package name axis2 Highest
Product jar package name xmlbeans Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Implementation-Title Apache Axis2 - XMLBeans Data Binding High
Product Manifest specification-title Apache Axis2 - XMLBeans Data Binding Medium
Product pom artifactid axis2-xmlbeans Highest
Product pom groupid org.apache.axis2 Highest
Product pom name Apache Axis2 - XMLBeans Data Binding High
Product pom parent-artifactid axis2 Medium
Product pom url http://axis.apache.org/axis2/java/core/ Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version Manifest Implementation-Version 1.8.2 High
Version pom version 1.8.2 Highest
bcmail-jdk18on-1.78.1.jar
Description:
The Bouncy Castle Java S/MIME APIs for handling S/MIME protocols. This jar contains S/MIME APIs for JDK 1.8 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. The JavaMail API and the Java activation framework will also be needed.
License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.bouncycastle/bcmail-jdk18on/1.78.1/566ad481fe9f470d5af73b9b52ade2fbe379a094/bcmail-jdk18on-1.78.1.jar
MD5: 801b8f3a9a907f6ee2290bbe1fc47080
SHA1: 566ad481fe9f470d5af73b9b52ade2fbe379a094
SHA256: e8b3bfd9dc80884b1d3f824c3fb543e55d544da313b52d5884902a9b264b43f8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
bcmail-jdk18on-1.78.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bcmail-jdk18on High
Vendor gradle artifactid bcmail-jdk18on Highest
Vendor gradle groupid org.bouncycastle Highest
Vendor jar package name bouncycastle Low
Vendor jar package name mail Low
Vendor jar package name smime Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcmail Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid bcmail-jdk18on Low
Vendor pom developer email feedback-crypto@bouncycastle.org Low
Vendor pom developer id feedback-crypto Medium
Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium
Vendor pom groupid org.bouncycastle Highest
Vendor pom name Bouncy Castle S/MIME API High
Vendor pom url https://www.bouncycastle.org/java.html Highest
Product file name bcmail-jdk18on High
Product gradle artifactid bcmail-jdk18on Highest
Product jar package name mail Low
Product jar package name smime Low
Product Manifest Bundle-Name bcmail Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcmail Medium
Product Manifest multi-release true Low
Product pom artifactid bcmail-jdk18on Highest
Product pom developer email feedback-crypto@bouncycastle.org Low
Product pom developer id feedback-crypto Low
Product pom developer name The Legion of the Bouncy Castle Inc. Low
Product pom groupid org.bouncycastle Highest
Product pom name Bouncy Castle S/MIME API High
Product pom url https://www.bouncycastle.org/java.html Medium
Version file version 1.78.1 High
Version gradle version 1.78.1 Highest
Version Manifest Bundle-Version 1.78.1 High
Version pom version 1.78.1 Highest
bcpkix-jdk15on-1.58.0.0.jar
Description:
Spongy Castle is a package-rename (org.bouncycastle.* to org.spongycastle.*) of Bouncy Castle
intended for the Android platform. Android unfortunately ships with a stripped-down version of
Bouncy Castle, which prevents easy upgrades - Spongy Castle overcomes this and provides a full,
up-to-date version of the Bouncy Castle cryptographic libs.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.madgag.spongycastle/bcpkix-jdk15on/1.58.0.0/a0502b8f7dcd70612c0f5be77f3cd76e4665d268/bcpkix-jdk15on-1.58.0.0.jar
MD5: 9df80baea46f7f6d4bb773801e2f6b99
SHA1: a0502b8f7dcd70612c0f5be77f3cd76e4665d268
SHA256: 89b776cc46caf6f9c29de3fdfe3aad06313b05646778a60873fcfd41f09a87ce
Referenced In Project/Scope: server-start:runtimeClasspath
bcpkix-jdk15on-1.58.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bcpkix-jdk15on High
Vendor gradle artifactid bcpkix-jdk15on Highest
Vendor gradle groupid com.madgag.spongycastle Highest
Vendor jar package name spongycastle Low
Vendor pom artifactid bcpkix-jdk15on Low
Vendor pom developer id rtyley Medium
Vendor pom developer name Roberto Tyley Medium
Vendor pom groupid com.madgag.spongycastle Highest
Vendor pom name Spongy Castle High
Vendor pom url http://rtyley.github.io/spongycastle/ Highest
Product file name bcpkix-jdk15on High
Product gradle artifactid bcpkix-jdk15on Highest
Product pom artifactid bcpkix-jdk15on Highest
Product pom developer id rtyley Low
Product pom developer name Roberto Tyley Low
Product pom groupid com.madgag.spongycastle Highest
Product pom name Spongy Castle High
Product pom url http://rtyley.github.io/spongycastle/ Medium
Version file version 1.58.0.0 High
Version gradle version 1.58.0.0 Highest
Version pom version 1.58.0.0 Highest
pkg:maven/com.madgag.spongycastle/bcpkix-jdk15on@1.58.0.0
(Confidence :High)
bcpkix-jdk18on-1.78.1.jar
Description:
The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.8 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs.
License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.bouncycastle/bcpkix-jdk18on/1.78.1/17b3541f736df97465f87d9f5b5dfa4991b37bb3/bcpkix-jdk18on-1.78.1.jar
MD5: bbe33d493826742ce3cda5fe5181b668
SHA1: 17b3541f736df97465f87d9f5b5dfa4991b37bb3
SHA256: 4b48ea084e5232b9d79ebca1887b9de037b124931807cd60710748c2aee08cc9
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
bcpkix-jdk18on-1.78.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bcpkix-jdk18on High
Vendor gradle artifactid bcpkix-jdk18on Highest
Vendor gradle groupid org.bouncycastle Highest
Vendor jar package name bouncycastle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcpkix Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid bcpkix-jdk18on Low
Vendor pom developer email feedback-crypto@bouncycastle.org Low
Vendor pom developer id feedback-crypto Medium
Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium
Vendor pom groupid org.bouncycastle Highest
Vendor pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High
Vendor pom url https://www.bouncycastle.org/java.html Highest
Product file name bcpkix-jdk18on High
Product gradle artifactid bcpkix-jdk18on Highest
Product Manifest Bundle-Name bcpkix Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcpkix Medium
Product Manifest multi-release true Low
Product pom artifactid bcpkix-jdk18on Highest
Product pom developer email feedback-crypto@bouncycastle.org Low
Product pom developer id feedback-crypto Low
Product pom developer name The Legion of the Bouncy Castle Inc. Low
Product pom groupid org.bouncycastle Highest
Product pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High
Product pom url https://www.bouncycastle.org/java.html Medium
Version file version 1.78.1 High
Version gradle version 1.78.1 Highest
Version Manifest Bundle-Version 1.78.1 High
Version pom version 1.78.1 Highest
bcprov-jdk18on-1.78.1.jar
Description:
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up.
License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.bouncycastle/bcprov-jdk18on/1.78.1/39e9e45359e20998eb79c1828751f94a818d25f8/bcprov-jdk18on-1.78.1.jar
MD5: 9646d6d9c087fd408fafe0e3cfe56c25
SHA1: 39e9e45359e20998eb79c1828751f94a818d25f8
SHA256: add5915e6acfc6ab5836e1fd8a5e21c6488536a8c1f21f386eeb3bf280b702d7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
bcprov-jdk18on-1.78.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bcprov-jdk18on High
Vendor gradle artifactid bcprov-jdk18on Highest
Vendor gradle groupid org.bouncycastle Highest
Vendor jar package name bouncycastle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcprov Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid bcprov-jdk18on Low
Vendor pom developer email feedback-crypto@bouncycastle.org Low
Vendor pom developer id feedback-crypto Medium
Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium
Vendor pom groupid org.bouncycastle Highest
Vendor pom name Bouncy Castle Provider High
Vendor pom url https://www.bouncycastle.org/java.html Highest
Product file name bcprov-jdk18on High
Product gradle artifactid bcprov-jdk18on Highest
Product Manifest Bundle-Name bcprov Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcprov Medium
Product Manifest multi-release true Low
Product pom artifactid bcprov-jdk18on Highest
Product pom developer email feedback-crypto@bouncycastle.org Low
Product pom developer id feedback-crypto Low
Product pom developer name The Legion of the Bouncy Castle Inc. Low
Product pom groupid org.bouncycastle Highest
Product pom name Bouncy Castle Provider High
Product pom url https://www.bouncycastle.org/java.html Medium
Version file version 1.78.1 High
Version gradle version 1.78.1 Highest
Version Manifest Bundle-Version 1.78.1 High
Version pom version 1.78.1 Highest
bctls-jdk18on-1.78.1.jar
Description:
The Bouncy Castle Java APIs for TLS and DTLS, including a provider for the JSSE.
License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.bouncycastle/bctls-jdk18on/1.78.1/d15b33dde190c21124fbde8dd712defe22bb8bfe/bctls-jdk18on-1.78.1.jar
MD5: 82a0526b15534997e6de21431050c5d4
SHA1: d15b33dde190c21124fbde8dd712defe22bb8bfe
SHA256: 483bd1582d3957adfe100747f22c6da0ff9532d6464f9c454181f99bfa44e52b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
bctls-jdk18on-1.78.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bctls-jdk18on High
Vendor gradle artifactid bctls-jdk18on Highest
Vendor gradle groupid org.bouncycastle Highest
Vendor jar package name bouncycastle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bctls Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid bctls-jdk18on Low
Vendor pom developer email feedback-crypto@bouncycastle.org Low
Vendor pom developer id feedback-crypto Medium
Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium
Vendor pom groupid org.bouncycastle Highest
Vendor pom name Bouncy Castle JSSE provider and TLS/DTLS API High
Vendor pom url https://www.bouncycastle.org/java.html Highest
Product file name bctls-jdk18on High
Product gradle artifactid bctls-jdk18on Highest
Product Manifest Bundle-Name bctls Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bctls Medium
Product Manifest multi-release true Low
Product pom artifactid bctls-jdk18on Highest
Product pom developer email feedback-crypto@bouncycastle.org Low
Product pom developer id feedback-crypto Low
Product pom developer name The Legion of the Bouncy Castle Inc. Low
Product pom groupid org.bouncycastle Highest
Product pom name Bouncy Castle JSSE provider and TLS/DTLS API High
Product pom url https://www.bouncycastle.org/java.html Medium
Version file version 1.78.1 High
Version gradle version 1.78.1 Highest
Version Manifest Bundle-Version 1.78.1 High
Version pom version 1.78.1 Highest
bcutil-jdk18on-1.78.1.jar
Description:
The Bouncy Castle Java APIs for ASN.1 extension and utility APIs used to support bcpkix and bctls. This jar contains APIs for JDK 1.8 and up.
License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.bouncycastle/bcutil-jdk18on/1.78.1/5353ca39fe2f148dab9ca1d637a43d0750456254/bcutil-jdk18on-1.78.1.jar
MD5: 228149d265033bae6701f70580aa7bf2
SHA1: 5353ca39fe2f148dab9ca1d637a43d0750456254
SHA256: d9fa56f97b0f761ce3bc8d9d74c5d7137a987bf5bd3abfe1003f9bafa45a1d2f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
bcutil-jdk18on-1.78.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bcutil-jdk18on High
Vendor gradle artifactid bcutil-jdk18on Highest
Vendor gradle groupid org.bouncycastle Highest
Vendor jar package name bouncycastle Low
Vendor jar package name oer Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcutil Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid bcutil-jdk18on Low
Vendor pom developer email feedback-crypto@bouncycastle.org Low
Vendor pom developer id feedback-crypto Medium
Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium
Vendor pom groupid org.bouncycastle Highest
Vendor pom name Bouncy Castle ASN.1 Extension and Utility APIs High
Vendor pom url https://www.bouncycastle.org/java.html Highest
Product file name bcutil-jdk18on High
Product gradle artifactid bcutil-jdk18on Highest
Product jar package name oer Low
Product Manifest Bundle-Name bcutil Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcutil Medium
Product Manifest multi-release true Low
Product pom artifactid bcutil-jdk18on Highest
Product pom developer email feedback-crypto@bouncycastle.org Low
Product pom developer id feedback-crypto Low
Product pom developer name The Legion of the Bouncy Castle Inc. Low
Product pom groupid org.bouncycastle Highest
Product pom name Bouncy Castle ASN.1 Extension and Utility APIs High
Product pom url https://www.bouncycastle.org/java.html Medium
Version file version 1.78.1 High
Version gradle version 1.78.1 Highest
Version Manifest Bundle-Version 1.78.1 High
Version pom version 1.78.1 Highest
bit-io-1.4.3.jar
Description:
library for reading/writing non-octet aligned values
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.github.jinahya/bit-io/1.4.3/46abf1c2d8af5e1d2e1cad7e7c64bd9822a88656/bit-io-1.4.3.jar
MD5: 4bac73c8be3680928158794389d22a3e
SHA1: 46abf1c2d8af5e1d2e1cad7e7c64bd9822a88656
SHA256: a72ab0e8eb9f86d2d5db7b57d7772023f171e58ce74821f9f47a506f9afdccbe
Referenced In Project/Scope: server-start:runtimeClasspath
bit-io-1.4.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bit-io High
Vendor gradle artifactid bit-io Highest
Vendor gradle groupid com.github.jinahya Highest
Vendor jar package name bit Highest
Vendor jar package name github Highest
Vendor jar package name io Highest
Vendor jar package name jinahya Highest
Vendor Manifest bundle-docurl https://jinahya.com Low
Vendor Manifest bundle-symbolicname com.github.jinahya.bit-io Medium
Vendor pom artifactid bit-io Low
Vendor pom groupid com.github.jinahya Highest
Vendor pom name ${project.artifactId} High
Vendor pom organization name Jinahya, Inc. High
Vendor pom organization url https://jinahya.com Medium
Vendor pom parent-artifactid jinahya-parent Low
Vendor pom url jinahya/ Highest
Vendor pom url jinahya/${project.artifactId} Highest
Product file name bit-io High
Product gradle artifactid bit-io Highest
Product jar package name bit Highest
Product jar package name github Highest
Product jar package name io Highest
Product jar package name jinahya Highest
Product Manifest bundle-docurl https://jinahya.com Low
Product Manifest Bundle-Name bit-io Medium
Product Manifest bundle-symbolicname com.github.jinahya.bit-io Medium
Product pom artifactid bit-io Highest
Product pom groupid com.github.jinahya Highest
Product pom name ${project.artifactId} High
Product pom organization name Jinahya, Inc. Low
Product pom organization url https://jinahya.com Low
Product pom parent-artifactid jinahya-parent Medium
Product pom url jinahya/ High
Product pom url jinahya/${project.artifactId} High
Version file version 1.4.3 High
Version gradle version 1.4.3 Highest
Version Manifest Bundle-Version 1.4.3 High
Version pom parent-version 1.4.3 Low
Version pom version 1.4.3 Highest
bson-5.6.4.jar
Description:
The BSON library
License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.mongodb/bson/5.6.4/57f50acb18b1d9c953f80a685d8c72698eb8c92a/bson-5.6.4.jar
MD5: b752694441c61feb4c18b4377cea5f8a
SHA1: 57f50acb18b1d9c953f80a685d8c72698eb8c92a
SHA256: 2ac120779879b262e3f65ac4e94105bd439ad33511f783846c1fe8278d6541f8
Referenced In Project/Scope: server-start:runtimeClasspath
bson-5.6.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bson High
Vendor gradle artifactid bson Highest
Vendor gradle groupid org.mongodb Highest
Vendor jar package name bson Highest
Vendor jar package name bson Low
Vendor Manifest automatic-module-name org.mongodb.bson Medium
Vendor Manifest bundle-symbolicname org.mongodb.bson Medium
Vendor pom artifactid bson Low
Vendor pom developer name Various Medium
Vendor pom developer org MongoDB Medium
Vendor pom groupid org.mongodb Highest
Vendor pom name BSON High
Vendor pom url https://bsonspec.org Highest
Product file name bson High
Product gradle artifactid bson Highest
Product jar package name bson Highest
Product Manifest automatic-module-name org.mongodb.bson Medium
Product Manifest Bundle-Name bson Medium
Product Manifest bundle-symbolicname org.mongodb.bson Medium
Product pom artifactid bson Highest
Product pom developer name Various Low
Product pom developer org MongoDB Low
Product pom groupid org.mongodb Highest
Product pom name BSON High
Product pom url https://bsonspec.org Medium
Version file version 5.6.4 High
Version gradle version 5.6.4 Highest
Version Manifest build-version 5.6.4 Medium
Version Manifest Bundle-Version 5.6.4 High
Version pom version 5.6.4 Highest
bson-record-codec-5.6.4.jar
Description:
The BSON Codec for Java records
License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.mongodb/bson-record-codec/5.6.4/b3381732c44aaba3582d142e10e96d2a880281b3/bson-record-codec-5.6.4.jar
MD5: 9ae2940d1df485cbe9145590f43d5450
SHA1: b3381732c44aaba3582d142e10e96d2a880281b3
SHA256: 4c75d0a88cf71bef3c8db61355b199bffb733d3100580cf12caa4966e088c780
Referenced In Project/Scope: server-start:runtimeClasspath
bson-record-codec-5.6.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name bson-record-codec High
Vendor gradle artifactid bson-record-codec Highest
Vendor gradle groupid org.mongodb Highest
Vendor jar package name bson Highest
Vendor jar package name bson Low
Vendor jar package name codecs Low
Vendor jar package name record Highest
Vendor jar package name record Low
Vendor Manifest automatic-module-name org.mongodb.bson.record.codec Medium
Vendor Manifest bundle-symbolicname org.mongodb.bson-record-codec Medium
Vendor pom artifactid bson-record-codec Low
Vendor pom developer name Various Medium
Vendor pom developer org MongoDB Medium
Vendor pom groupid org.mongodb Highest
Vendor pom name BSON Record Codec High
Vendor pom url https://bsonspec.org Highest
Product file name bson-record-codec High
Product gradle artifactid bson-record-codec Highest
Product jar package name bson Highest
Product jar package name codecs Low
Product jar package name record Highest
Product jar package name record Low
Product Manifest automatic-module-name org.mongodb.bson.record.codec Medium
Product Manifest Bundle-Name bson-record-codec Medium
Product Manifest bundle-symbolicname org.mongodb.bson-record-codec Medium
Product pom artifactid bson-record-codec Highest
Product pom developer name Various Low
Product pom developer org MongoDB Low
Product pom groupid org.mongodb Highest
Product pom name BSON Record Codec High
Product pom url https://bsonspec.org Medium
Version file version 5.6.4 High
Version gradle version 5.6.4 Highest
Version Manifest build-version 5.6.4 Medium
Version Manifest Bundle-Version 5.6.4 High
Version pom version 5.6.4 Highest
cache-api-1.1.0.jar
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.cache/cache-api/1.1.0/77bdcff7814076dfa61611b0db88487c515150b6/cache-api-1.1.0.jar
MD5: ac907ad12e9a7ac5d41abf703855002f
SHA1: 77bdcff7814076dfa61611b0db88487c515150b6
SHA256: 6c980ad1ae4a6dda3bdb62986c3ef5b41ccf766e12353587ee4e4307e27e155a
Referenced In Project/Scope: server-start:webapps
cache-api-1.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cache-api High
Vendor gradle artifactid cache-api Highest
Vendor gradle groupid javax.cache Highest
Vendor jar package name cache Highest
Vendor jar package name javax Highest
Vendor jar package name spi Highest
Vendor Manifest bundle-symbolicname javax.cache.api Medium
Vendor pom artifactid cache-api Low
Vendor pom groupid javax.cache Highest
Vendor pom name JSR107 API and SPI High
Vendor pom url jsr107/jsr107spec Highest
Product file name cache-api High
Product gradle artifactid cache-api Highest
Product jar package name cache Highest
Product jar package name javax Highest
Product jar package name spi Highest
Product Manifest Bundle-Name JSR107 API and SPI Medium
Product Manifest bundle-symbolicname javax.cache.api Medium
Product pom artifactid cache-api Highest
Product pom groupid javax.cache Highest
Product pom name JSR107 API and SPI High
Product pom url jsr107/jsr107spec High
Version file version 1.1.0 High
Version gradle version 1.1.0 Highest
Version Manifest Bundle-Version 1.1.0 High
Version pom version 1.1.0 Highest
pkg:maven/javax.cache/cache-api@1.1.0
(Confidence :High)
caffeine-3.2.2.jar
Description:
A high performance caching library
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.github.ben-manes.caffeine/caffeine/3.2.2/8b0a31cb57ac00e18161d5586759912bd2637398/caffeine-3.2.2.jar
MD5: 202a61e2492ad488df931367241a110c
SHA1: 8b0a31cb57ac00e18161d5586759912bd2637398
SHA256: c74a6c72221dfb76eb92f2bb40108ea561a7da2f315dc3b1e64afa8f077f210c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
caffeine-3.2.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name caffeine High
Vendor gradle artifactid caffeine Highest
Vendor gradle groupid com.github.ben-manes.caffeine Highest
Vendor jar package name benmanes Highest
Vendor jar package name benmanes Low
Vendor jar package name caffeine Highest
Vendor jar package name caffeine Low
Vendor jar package name github Highest
Vendor jar package name github Low
Vendor Manifest automatic-module-name com.github.benmanes.caffeine Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Vendor pom artifactid caffeine Low
Vendor pom developer email ben.manes@gmail.com Low
Vendor pom developer id ben-manes Medium
Vendor pom developer name Ben Manes Medium
Vendor pom groupid com.github.ben-manes.caffeine Highest
Vendor pom name Caffeine cache High
Vendor pom url ben-manes/caffeine Highest
Product file name caffeine High
Product gradle artifactid caffeine Highest
Product jar package name benmanes Highest
Product jar package name benmanes Low
Product jar package name cache Low
Product jar package name caffeine Highest
Product jar package name caffeine Low
Product jar package name github Highest
Product Manifest automatic-module-name com.github.benmanes.caffeine Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium
Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Product Manifest Implementation-Title A high performance caching library High
Product pom artifactid caffeine Highest
Product pom developer email ben.manes@gmail.com Low
Product pom developer id ben-manes Low
Product pom developer name Ben Manes Low
Product pom groupid com.github.ben-manes.caffeine Highest
Product pom name Caffeine cache High
Product pom url ben-manes/caffeine High
Version file version 3.2.2 High
Version gradle version 3.2.2 Highest
Version Manifest Bundle-Version 3.2.2 High
Version Manifest Implementation-Version 3.2.2 High
Version pom version 3.2.2 Highest
pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.2
(Confidence :High)
checker-qual-3.33.0.jar
Description:
checker-qual contains annotations (type qualifiers) that a programmer
writes to specify Java code for type-checking by the Checker Framework.
License:
The MIT License: http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.checkerframework/checker-qual/3.33.0/de2b60b62da487644fc11f734e73c8b0b431238f/checker-qual-3.33.0.jar
MD5: fc9418b779d9d57dcd52197006cbdb9b
SHA1: de2b60b62da487644fc11f734e73c8b0b431238f
SHA256: e316255bbfcd9fe50d165314b85abb2b33cb2a66a93c491db648e498a82c2de1
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
checker-qual-3.33.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor gradle artifactid checker-qual Highest
Vendor gradle groupid org.checkerframework Highest
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Highest
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Vendor pom artifactid checker-qual Low
Vendor pom developer email mernst@cs.washington.edu Low
Vendor pom developer email smillst@cs.washington.edu Low
Vendor pom developer id mernst Medium
Vendor pom developer id smillst Medium
Vendor pom developer name Michael Ernst Medium
Vendor pom developer name Suzanne Millstein Medium
Vendor pom developer org University of Washington Medium
Vendor pom developer org URL https://www.cs.washington.edu/ Medium
Vendor pom groupid org.checkerframework Highest
Vendor pom name Checker Qual High
Vendor pom url https://checkerframework.org/ Highest
Product file name checker-qual High
Product gradle artifactid checker-qual Highest
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest automatic-module-name org.checkerframework.checker.qual Medium
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Product pom artifactid checker-qual Highest
Product pom developer email mernst@cs.washington.edu Low
Product pom developer email smillst@cs.washington.edu Low
Product pom developer id mernst Low
Product pom developer id smillst Low
Product pom developer name Michael Ernst Low
Product pom developer name Suzanne Millstein Low
Product pom developer org University of Washington Low
Product pom developer org URL https://www.cs.washington.edu/ Low
Product pom groupid org.checkerframework Highest
Product pom name Checker Qual High
Product pom url https://checkerframework.org/ Medium
Version file version 3.33.0 High
Version gradle version 3.33.0 Highest
Version Manifest Bundle-Version 3.33.0 High
Version Manifest Implementation-Version 3.33.0 High
Version pom version 3.33.0 Highest
pkg:maven/org.checkerframework/checker-qual@3.33.0
(Confidence :High)
checker-qual-3.43.0.jar
Description:
checker-qual contains annotations (type qualifiers) that a programmer
writes to specify Java code for type-checking by the Checker Framework.
License:
The MIT License: http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.checkerframework/checker-qual/3.43.0/9425eee39e56b116d2b998b7c2cebcbd11a3c98b/checker-qual-3.43.0.jar
MD5: 4f56e65c8f302ca8b4cb384c9b4a53b6
SHA1: 9425eee39e56b116d2b998b7c2cebcbd11a3c98b
SHA256: 3fbc2e98f05854c3df16df9abaa955b91b15b3ecac33623208ed6424640ef0f6
Referenced In Project/Scope: server-start:webapps
checker-qual-3.43.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor gradle artifactid checker-qual Highest
Vendor gradle groupid org.checkerframework Highest
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Vendor pom artifactid checker-qual Low
Vendor pom developer email mernst@cs.washington.edu Low
Vendor pom developer email smillst@cs.washington.edu Low
Vendor pom developer id mernst Medium
Vendor pom developer id smillst Medium
Vendor pom developer name Michael Ernst Medium
Vendor pom developer name Suzanne Millstein Medium
Vendor pom developer org University of Washington Medium
Vendor pom developer org URL https://www.cs.washington.edu/ Medium
Vendor pom groupid org.checkerframework Highest
Vendor pom name Checker Qual High
Vendor pom url https://checkerframework.org/ Highest
Product file name checker-qual High
Product gradle artifactid checker-qual Highest
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Product pom artifactid checker-qual Highest
Product pom developer email mernst@cs.washington.edu Low
Product pom developer email smillst@cs.washington.edu Low
Product pom developer id mernst Low
Product pom developer id smillst Low
Product pom developer name Michael Ernst Low
Product pom developer name Suzanne Millstein Low
Product pom developer org University of Washington Low
Product pom developer org URL https://www.cs.washington.edu/ Low
Product pom groupid org.checkerframework Highest
Product pom name Checker Qual High
Product pom url https://checkerframework.org/ Medium
Version file version 3.43.0 High
Version gradle version 3.43.0 Highest
Version Manifest Bundle-Version 3.43.0 High
Version Manifest Implementation-Version 3.43.0 High
Version pom version 3.43.0 Highest
pkg:maven/org.checkerframework/checker-qual@3.43.0
(Confidence :High)
checksums-2.26.30.jar
Description:
The AWS SDK for Java - Checksums module contains checksums and related items that are used by other modules in
the library.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/checksums/2.26.30/e78aca472796c4514b9daaf2587023b0774f05eb/checksums-2.26.30.jar
MD5: 2afd0c0927ee2ddc6b675d730159c20e
SHA1: e78aca472796c4514b9daaf2587023b0774f05eb
SHA256: bacf64eb32432314b87bbeece07a9eb45e486c187f777ce47304f6907b4facd2
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
checksums-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name checksums High
Vendor gradle artifactid checksums Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name checksums Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.checksums Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid checksums Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Checksums High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name checksums High
Product gradle artifactid checksums Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name checksums Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.checksums Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid checksums Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Checksums High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
checksums-spi-2.26.30.jar
Description:
The AWS SDK for Java - Checksums SPI module contains checksum interfaces that are used by other modules
in the library.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/checksums-spi/2.26.30/985e999e5d17c4c1667c27e9d4809d2b861cf858/checksums-spi-2.26.30.jar
MD5: 875d89f3daa16757ac8abd09edf2b818
SHA1: 985e999e5d17c4c1667c27e9d4809d2b861cf858
SHA256: 61f232c27a1cd4cdbe4fb90131fbf3b54ef170fa2e00d048bfc341e8d097ee80
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
checksums-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name checksums-spi High
Vendor gradle artifactid checksums-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name checksums Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.checksums.spi Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid checksums-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Checksums SPI High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name checksums-spi High
Product gradle artifactid checksums-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name checksums Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.checksums.spi Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid checksums-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Checksums SPI High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
classgraph-4.8.184.jar
Description:
The uber-fast, ultra-lightweight classpath and module scanner for JVM languages.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.github.classgraph/classgraph/4.8.184/a4f7ddec0f831dcf7ec3db32ae2c7e628c89f1a6/classgraph-4.8.184.jar
MD5: f17699e5f6be5a692cde649b5d97b3a1
SHA1: a4f7ddec0f831dcf7ec3db32ae2c7e628c89f1a6
SHA256: 6e564e29cec95a392268a609f09071d56199383d906ac70e91753a7998d1a3e8
Referenced In Project/Scope: server-start:webapps
classgraph-4.8.184.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name classgraph High
Vendor gradle artifactid classgraph Highest
Vendor gradle groupid io.github.classgraph Highest
Vendor jar package name classgraph Highest
Vendor jar package name github Highest
Vendor jar package name io Highest
Vendor jar package name scanner Highest
Vendor Manifest build-jdk-spec 24 Low
Vendor Manifest bundle-category Utilities Low
Vendor Manifest bundle-symbolicname io.github.classgraph.classgraph Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid classgraph Low
Vendor pom developer email luke.hutch@gmail.com Low
Vendor pom developer name Luke Hutchison Medium
Vendor pom developer org ClassGraph Medium
Vendor pom developer org URL https://github.com/classgraph Medium
Vendor pom groupid io.github.classgraph Highest
Vendor pom name ClassGraph High
Vendor pom url classgraph/classgraph Highest
Product file name classgraph High
Product gradle artifactid classgraph Highest
Product jar package name classgraph Highest
Product jar package name github Highest
Product jar package name io Highest
Product jar package name scanner Highest
Product Manifest build-jdk-spec 24 Low
Product Manifest bundle-category Utilities Low
Product Manifest Bundle-Name ClassGraph Medium
Product Manifest bundle-symbolicname io.github.classgraph.classgraph Medium
Product Manifest Implementation-Title ClassGraph High
Product Manifest multi-release true Low
Product Manifest specification-title ClassGraph Medium
Product pom artifactid classgraph Highest
Product pom developer email luke.hutch@gmail.com Low
Product pom developer name Luke Hutchison Low
Product pom developer org ClassGraph Low
Product pom developer org URL https://github.com/classgraph Low
Product pom groupid io.github.classgraph Highest
Product pom name ClassGraph High
Product pom url classgraph/classgraph High
Version file version 4.8.184 High
Version gradle version 4.8.184 Highest
Version Manifest Bundle-Version 4.8.184 High
Version Manifest Implementation-Version 4.8.184 High
Version pom version 4.8.184 Highest
pkg:maven/io.github.classgraph/classgraph@4.8.184
(Confidence :High)
codemodel-2.3.6.jar
Description:
The core functionality of the CodeModel java source code generation library
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/codemodel/2.3.6/4473f359afb95b57935cd8fa3b071bd73371632c/codemodel-2.3.6.jar
MD5: 6398352cf3ba0f9b32d0d1e93f6dae33
SHA1: 4473f359afb95b57935cd8fa3b071bd73371632c
SHA256: 8f1afd4e2027af351353598a5643fae148593cb6a931270724a7e47a741013b4
Referenced In Project/Scope: server-start:runtimeClasspath
codemodel-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name codemodel High
Vendor gradle artifactid codemodel Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name codemodel Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.jaxb.codemodel Medium
Vendor Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor pom artifactid codemodel Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name Codemodel Core High
Vendor pom parent-artifactid jaxb-codemodel-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name codemodel High
Product gradle artifactid codemodel Highest
Product jar package name codemodel Highest
Product jar package name sun Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Codemodel Core Medium
Product Manifest bundle-symbolicname org.glassfish.jaxb.codemodel Medium
Product Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Product Manifest Implementation-Title Codemodel Core High
Product pom artifactid codemodel Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name Codemodel Core High
Product pom parent-artifactid jaxb-codemodel-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest Bundle-Version 2.3.6 High
Version Manifest implementation-build-id 2.3.6 Low
Version Manifest Implementation-Version 2.3.6 High
Version pom version 2.3.6 Highest
pkg:maven/org.glassfish.jaxb/codemodel@2.3.6
(Confidence :High)
command-local-connector-0.9.7-classes.jar
Description:
Web application: command-local-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/ca1d7331fa3e76b5cf7244cc4eea850ae24b6222/command-local-connector-0.9.7-classes.jar
MD5: e473ffac0429ea9735a6395ed5e0df36
SHA1: ca1d7331fa3e76b5cf7244cc4eea850ae24b6222
SHA256: 68bb678a07eb225d792fc3777e6fe704fc2cfa04c5038e700c376eb547dde46a
Referenced In Project/Scope: server-start:compileClasspath
command-local-connector-0.9.7-classes.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name command-local-connector High
Vendor gradle artifactid command-local-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name io Low
Vendor jar package name message Low
Vendor jar package name transconnect Low
Vendor pom artifactid command-local-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name command-local-connector High
Product gradle artifactid command-local-connector Highest
Product jar package name connector Low
Product jar package name message Low
Product jar package name transconnect Low
Product pom artifactid command-local-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.7 High
Version gradle version 0.9.7 Highest
Version pom version 0.9.7 Highest
pkg:maven/io.transconnect.connector/command-local-connector@0.9.7
(Confidence :High)
command-local-connector-0.9.7.war
Description:
Web application: command-local-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war
MD5: 43f9f276dba8e3917b72bde1343579e2
SHA1: d680bfd369d6c065c4883af2f263ec5ef36801bf
SHA256: 7a1cd3b2ad04fa3c04c8c57361d012e84c981bc70bb5262a65107b3457759257
Referenced In Project/Scope: server-start:webapps
command-local-connector-0.9.7.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name command-local-connector High
Vendor gradle artifactid command-local-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid command-local-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name command-local-connector High
Product gradle artifactid command-local-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid command-local-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.7 High
Version gradle version 0.9.7 Highest
Version pom version 0.9.7 Highest
pkg:maven/io.transconnect.connector/command-local-connector@0.9.7
(Confidence :High)
command-local-connector-0.9.7.war: angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-local-connector-0.9.7.war: angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
command-local-connector-0.9.7.war: asm-9.4.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/asm-9.4.jar
MD5: ffa64f03a23a4823d98703e6ce6ff397
SHA1: b4e0e2d2e023aa317b7cfcfc916377ea348e07d1
SHA256: 39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.4 High
Version Manifest Implementation-Version 9.4 High
command-local-connector-0.9.7.war: jackson-core-2.17.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jackson-core-2.17.1.jar
MD5: 9363584821290882417f1c3ceab784df
SHA1: 5e52a11644cd59a28ef79f02bddc2cc3bab45edb
SHA256: ddb26c8a1f1a84535e8213c48b35b253370434e3287b3cf15777856fc4e58ce6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
Related Dependencies
command-local-connector-0.9.7.war: jackson-annotations-2.17.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jackson-annotations-2.17.1.jar
MD5: dbeffa5994a6234489a205fd7f33d9b9
SHA1: fca7ef6192c9ad05d07bc50da991bf937a84af3a
SHA256: fccad82e13172c0e4384db71577219c9b8631c0820f4b18daaa57016fb661c76
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.17.1
command-local-connector-0.9.7.war: jackson-databind-2.17.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jackson-databind-2.17.1.jar
MD5: f0a1c37dc7d937f14e183d84f15c0f83
SHA1: 0524dcbcccdde7d45a679dfc333e4763feb09079
SHA256: b6ca2f7d5b1ab245cec5495ec339773d2d90554c48592590673fb18f4400a948
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
command-local-connector-0.9.7.war: jackson-dataformat-yaml-2.17.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jackson-dataformat-yaml-2.17.1.jar
MD5: 3257d599754342666ba50b7eaed555b5
SHA1: b4c7b8a9ea3f398116a75c146b982b22afebc4ee
SHA256: 83f38459593bc10caeb1fa2653616813b1743b6bed67163c8ae8e5a4d32a5456
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
command-local-connector-0.9.7.war: jackson-datatype-jsr310-2.17.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jackson-datatype-jsr310-2.17.1.jar
MD5: 9761d8656aeac7db968998100b91f36e
SHA1: 0969b0c3cb8c75d759e9a6c585c44c9b9f3a4f75
SHA256: 56765d55ac8cffdd757c1a534ec965e70b01176f64dfd7e70b0db34d8babc9fa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.17.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.17.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-local-connector-0.9.7.war: jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
command-local-connector-0.9.7.war: jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
command-local-connector-0.9.7.war: jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
command-local-connector-0.9.7.war: jaxb-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/jaxb-0.9.5.jar
MD5: 62dd26407b3fe4a95c87d9fa0800a192
SHA1: 3cf649244df727ca00cbbf2149f3d71781faac64
SHA256: f26be27f61e1161a03ec62e1b83c9374082a45eceed34315e5b56fa7af92bd65
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name jaxb High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name jaxb Medium
Version file version 0.9.5 High
command-local-connector-0.9.7.war: org.eclipse.persistence.core-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/org.eclipse.persistence.core-5.0.0-B10.jar
MD5: 0220aebe0d5d2e3e17212b4f170bc861
SHA1: 7ab1bff81e53437b06882cac903427164e047cc8
SHA256: be3b97f65e605c29b539db0c7adb134ec61413943368432705c4731965b1370a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.core High
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Vendor Manifest extension-name org.eclipse.persistence.core Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Vendor pom artifactid eclipse.persistence.core Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink Core High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.core High
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink Core Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Product Manifest extension-name org.eclipse.persistence.core Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Product pom artifactid eclipse.persistence.core Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink Core High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.core@5.0.0-B10
(Confidence :High)
command-local-connector-0.9.7.war: org.eclipse.persistence.moxy-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/org.eclipse.persistence.moxy-5.0.0-B10.jar
MD5: 550ec8c0a31fbc5b6d0cd63f75b7d897
SHA1: aede7488445daebad7fb1f7202593e0800e858db
SHA256: 6d040ff629d81d54a7d5f18e73370288126062db7325a87e13fc97bbe65f935a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.moxy High
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Vendor Manifest extension-name org.eclipse.persistence.moxy Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Vendor pom artifactid eclipse.persistence.moxy Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink MOXy High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.moxy High
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink MOXy Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Product Manifest extension-name org.eclipse.persistence.moxy Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Product pom artifactid eclipse.persistence.moxy Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink MOXy High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.moxy@5.0.0-B10
(Confidence :High)
command-local-connector-0.9.7.war: snakeyaml-2.2.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/snakeyaml-2.2.jar
MD5: d78aacf5f2de5b52f1a327470efd1ad7
SHA1: 3af797a25458550a16bf89acc8e4ab2b7f2bfce0
SHA256: 1467931448a0817696ae2805b7b8b20bfb082652bf9c4efaed528930dc49389b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.2 High
Version pom version 2.2 Highest
command-local-connector-0.9.7.war: war-connector-bridge-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/war-connector-bridge-0.9.5.jar
MD5: d30d230b69cd912e0a5b520226115414
SHA1: f87d602579133c6c538e341a3891458f176c5666
SHA256: 9bc5dafd561bc7a99979f603ac5331eacd3d3c8f21f717b24fed1ff8045ec421
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 0.9.5 High
command-local-connector-0.9.7.war: yaml-descriptor-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-local-connector/0.9.7/d680bfd369d6c065c4883af2f263ec5ef36801bf/command-local-connector-0.9.7.war/WEB-INF/lib/yaml-descriptor-0.9.5.jar
MD5: 139586d6d73e3a49bd3e7fba273f0199
SHA1: 0484c4ecddab80a4c8b1a4d12667750af151e8bd
SHA256: ff7826a7641fb90aca304878bc97d505da06d971d2df3f0b272f621aeaa3abff
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 0.9.5 High
command-ssh-connector-0.9.7-classes.jar
Description:
Web application: command-ssh-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/fab8f780880444e700a1b2fa875b0e064e3222c/command-ssh-connector-0.9.7-classes.jar
MD5: 7f8edcbc4f0f7ce2a4de8e49844b3c79
SHA1: 0fab8f780880444e700a1b2fa875b0e064e3222c
SHA256: 809e10a5a0face4e560c834b515345abe625f291d818c694b63f126bfec598f8
Referenced In Project/Scope: server-start:compileClasspath
command-ssh-connector-0.9.7-classes.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name command-ssh-connector High
Vendor gradle artifactid command-ssh-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Vendor pom artifactid command-ssh-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name command-ssh-connector High
Product gradle artifactid command-ssh-connector Highest
Product jar package name connector Low
Product jar package name secureshell Low
Product jar package name transconnect Low
Product pom artifactid command-ssh-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.7 High
Version gradle version 0.9.7 Highest
Version pom version 0.9.7 Highest
pkg:maven/io.transconnect.connector/command-ssh-connector@0.9.7
(Confidence :High)
command-ssh-connector-0.9.7.war
Description:
Web application: command-ssh-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war
MD5: 42140b4bc1060d19585e580ec547fadd
SHA1: d952b98bcc6334dc7f71d5e5d780c8d0e3799c70
SHA256: 068cf35a42301d17d2d9a35dc439a35603599ab7c420c56b9bdcaaf21dff13ce
Referenced In Project/Scope: server-start:webapps
command-ssh-connector-0.9.7.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name command-ssh-connector High
Vendor gradle artifactid command-ssh-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid command-ssh-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name command-ssh-connector High
Product gradle artifactid command-ssh-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid command-ssh-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.7 High
Version gradle version 0.9.7 Highest
Version pom version 0.9.7 Highest
pkg:maven/io.transconnect.connector/command-ssh-connector@0.9.7
(Confidence :High)
command-ssh-connector-0.9.7.war: angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-ssh-connector-0.9.7.war: angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
command-ssh-connector-0.9.7.war: asm-9.4.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/asm-9.4.jar
MD5: ffa64f03a23a4823d98703e6ce6ff397
SHA1: b4e0e2d2e023aa317b7cfcfc916377ea348e07d1
SHA256: 39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.4 High
Version Manifest Implementation-Version 9.4 High
command-ssh-connector-0.9.7.war: bcpkix-jdk18on-1.81.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/bcpkix-jdk18on-1.81.jar
MD5: a66bdc5d32d086737b86803cd87cd187
SHA1: 819fd6f5d170c8b8bf8c5acc73816e9c36574042
SHA256: b38c604871f3690109a3c00982d9145634125de3365a817ba16eb90d88e242c9
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name bcpkix-jdk18on High
Vendor jar package name bouncycastle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcpkix Medium
Vendor Manifest multi-release true Low
Product file name bcpkix-jdk18on High
Product Manifest Bundle-Name bcpkix Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcpkix Medium
Product Manifest multi-release true Low
Version file name bcpkix-jdk18on Medium
Version file version 1.81 High
Version Manifest Bundle-Version 1.81 High
command-ssh-connector-0.9.7.war: bcprov-jdk18on-1.81.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/bcprov-jdk18on-1.81.jar
MD5: 3913a176dc36b31e867be5360f3ee524
SHA1: d17c094daef57dbd80af71687a475aa6df7cbe54
SHA256: 249f396412b0c0ce67f25c8197da757b241b8be3ec4199386c00704a2457459b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name bcprov-jdk18on High
Vendor jar package name bouncycastle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcprov Medium
Vendor Manifest multi-release true Low
Product file name bcprov-jdk18on High
Product Manifest Bundle-Name bcprov Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcprov Medium
Product Manifest multi-release true Low
Version file name bcprov-jdk18on Medium
Version file version 1.81 High
Version Manifest Bundle-Version 1.81 High
command-ssh-connector-0.9.7.war: bcutil-jdk18on-1.81.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/bcutil-jdk18on-1.81.jar
MD5: c75f3409ceba35d90b00dd9d1937d9db
SHA1: e2dd79395ab435094142b6aba219f35adcba0f01
SHA256: 31a5fe3a7ba42e3457b83930f0ff8d679fb5b76eaadf2b51f5740c92a394bf52
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name bcutil-jdk18on High
Vendor jar package name bouncycastle Low
Vendor jar package name oer Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname bcutil Medium
Vendor Manifest multi-release true Low
Product file name bcutil-jdk18on High
Product jar package name oer Low
Product Manifest Bundle-Name bcutil Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname bcutil Medium
Product Manifest multi-release true Low
Version file name bcutil-jdk18on Medium
Version file version 1.81 High
Version Manifest Bundle-Version 1.81 High
command-ssh-connector-0.9.7.war: checker-qual-3.33.0.jar
License:
MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/checker-qual-3.33.0.jar
MD5: fc9418b779d9d57dcd52197006cbdb9b
SHA1: de2b60b62da487644fc11f734e73c8b0b431238f
SHA256: e316255bbfcd9fe50d165314b85abb2b33cb2a66a93c491db648e498a82c2de1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Highest
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest automatic-module-name org.checkerframework.checker.qual Medium
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Version file version 3.33.0 High
Version Manifest Implementation-Version 3.33.0 High
command-ssh-connector-0.9.7.war: error_prone_annotations-2.18.0.jar
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/error_prone_annotations-2.18.0.jar
MD5: 64145d0e7fee5a69ed7b84cf402de998
SHA1: 89b684257096f548fa39a7df9fdaa409d4d4df91
SHA256: 9e6814cb71816988a4fd1b07a993a8f21bb7058d522c162b1de849e19bea54ae
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.errorprone.annotations Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.errorprone.annotations Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.18.0 High
Version pom version 2.18.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.18.0
(Confidence :High)
command-ssh-connector-0.9.7.war: failureaccess-1.0.1.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes is conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.1 High
Version Manifest Bundle-Version 1.0.1 High
Version pom parent-version 1.0.1 Low
Version pom version 1.0.1 Highest
pkg:maven/com.google.guava/failureaccess@1.0.1
(Confidence :High)
command-ssh-connector-0.9.7.war: guava-32.1.1-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/guava-32.1.1-jre.jar
MD5: 55870c9a31bf9ba2815f252a93ab0850
SHA1: ad575652d84153075dd41ec6177ccb15251262b2
SHA256: 91fbba37f1c8b251cf9ea9e7d3a369eb79eb1e6a5df1d4bbf483dd0380740281
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version pom version 32.1.1-jre Highest
command-ssh-connector-0.9.7.war: jackson-core-2.17.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jackson-core-2.17.1.jar
MD5: 9363584821290882417f1c3ceab784df
SHA1: 5e52a11644cd59a28ef79f02bddc2cc3bab45edb
SHA256: ddb26c8a1f1a84535e8213c48b35b253370434e3287b3cf15777856fc4e58ce6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
Related Dependencies
command-ssh-connector-0.9.7.war: jackson-annotations-2.17.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jackson-annotations-2.17.1.jar
MD5: dbeffa5994a6234489a205fd7f33d9b9
SHA1: fca7ef6192c9ad05d07bc50da991bf937a84af3a
SHA256: fccad82e13172c0e4384db71577219c9b8631c0820f4b18daaa57016fb661c76
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.17.1
command-ssh-connector-0.9.7.war: jackson-databind-2.17.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jackson-databind-2.17.1.jar
MD5: f0a1c37dc7d937f14e183d84f15c0f83
SHA1: 0524dcbcccdde7d45a679dfc333e4763feb09079
SHA256: b6ca2f7d5b1ab245cec5495ec339773d2d90554c48592590673fb18f4400a948
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
command-ssh-connector-0.9.7.war: jackson-dataformat-yaml-2.17.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jackson-dataformat-yaml-2.17.1.jar
MD5: 3257d599754342666ba50b7eaed555b5
SHA1: b4c7b8a9ea3f398116a75c146b982b22afebc4ee
SHA256: 83f38459593bc10caeb1fa2653616813b1743b6bed67163c8ae8e5a4d32a5456
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
command-ssh-connector-0.9.7.war: jackson-datatype-jsr310-2.17.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jackson-datatype-jsr310-2.17.1.jar
MD5: 9761d8656aeac7db968998100b91f36e
SHA1: 0969b0c3cb8c75d759e9a6c585c44c9b9f3a4f75
SHA256: 56765d55ac8cffdd757c1a534ec965e70b01176f64dfd7e70b0db34d8babc9fa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.17.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.17.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
command-ssh-connector-0.9.7.war: jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
command-ssh-connector-0.9.7.war: jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
command-ssh-connector-0.9.7.war: jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
command-ssh-connector-0.9.7.war: jaxb-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jaxb-0.9.5.jar
MD5: 62dd26407b3fe4a95c87d9fa0800a192
SHA1: 3cf649244df727ca00cbbf2149f3d71781faac64
SHA256: f26be27f61e1161a03ec62e1b83c9374082a45eceed34315e5b56fa7af92bd65
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name jaxb High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name jaxb Medium
Version file version 0.9.5 High
command-ssh-connector-0.9.7.war: jsch-2.27.2.jar
Description:
JSch is a pure Java implementation of SSH2
License:
Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.txt
Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.JZlib.txt
ISC: https://github.com/mwiede/jsch/blob/master/LICENSE.jBCrypt.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jsch-2.27.2.jar
MD5: 4eca4e07bfbf4ae21d315f89106dcd15
SHA1: 56de78977abe1df48e4cb68415aa60d44c1fda28
SHA256: 5e7ac4c352834764b0437ed45435fa2cf911d038c17748e1f7800df85d0a8290
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsch High
Vendor jar package name com Highest
Vendor jar package name jcraft Highest
Vendor jar package name jsch Highest
Vendor Manifest build-jdk-spec 24 Low
Vendor Manifest bundle-symbolicname com.github.mwiede.jsch Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jsch Low
Vendor pom developer email mwiede@gmx.de Low
Vendor pom developer email ymnk at jcraft D0t com Low
Vendor pom developer id mwiede Medium
Vendor pom developer id norrisjeremy Medium
Vendor pom developer id ymnk Medium
Vendor pom developer name Atsuhiko Yamanaka Medium
Vendor pom developer name Jeremy Norris Medium
Vendor pom developer name Matthias Wiedemann Medium
Vendor pom developer org Community Medium
Vendor pom developer org JCraft,Inc. Medium
Vendor pom developer org URL http://www.jcraft.com/ Medium
Vendor pom developer org URL https://github.com/mwiede Medium
Vendor pom developer org URL https://github.com/norrisjeremy Medium
Vendor pom groupid com.github.mwiede Highest
Vendor pom name JSch High
Vendor pom url mwiede/jsch Highest
Product file name jsch High
Product jar package name 24 Highest
Product jar package name com Highest
Product jar package name jcraft Highest
Product jar package name jsch Highest
Product Manifest build-jdk-spec 24 Low
Product Manifest Bundle-Name JSch Medium
Product Manifest bundle-symbolicname com.github.mwiede.jsch Medium
Product Manifest Implementation-Title JSch High
Product Manifest multi-release true Low
Product Manifest specification-title JSch Medium
Product pom artifactid jsch Highest
Product pom developer email mwiede@gmx.de Low
Product pom developer email ymnk at jcraft D0t com Low
Product pom developer id mwiede Low
Product pom developer id norrisjeremy Low
Product pom developer id ymnk Low
Product pom developer name Atsuhiko Yamanaka Low
Product pom developer name Jeremy Norris Low
Product pom developer name Matthias Wiedemann Low
Product pom developer org Community Low
Product pom developer org JCraft,Inc. Low
Product pom developer org URL http://www.jcraft.com/ Low
Product pom developer org URL https://github.com/mwiede Low
Product pom developer org URL https://github.com/norrisjeremy Low
Product pom groupid com.github.mwiede Highest
Product pom name JSch High
Product pom url mwiede/jsch High
Version file version 2.27.2 High
Version Manifest Bundle-Version 2.27.2 High
Version Manifest Implementation-Version 2.27.2 High
Version pom version 2.27.2 Highest
command-ssh-connector-0.9.7.war: jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
command-ssh-connector-0.9.7.war: org.eclipse.persistence.core-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/org.eclipse.persistence.core-5.0.0-B10.jar
MD5: 0220aebe0d5d2e3e17212b4f170bc861
SHA1: 7ab1bff81e53437b06882cac903427164e047cc8
SHA256: be3b97f65e605c29b539db0c7adb134ec61413943368432705c4731965b1370a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.core High
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Vendor Manifest extension-name org.eclipse.persistence.core Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Vendor pom artifactid eclipse.persistence.core Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink Core High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.core High
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink Core Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Product Manifest extension-name org.eclipse.persistence.core Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Product pom artifactid eclipse.persistence.core Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink Core High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.core@5.0.0-B10
(Confidence :High)
command-ssh-connector-0.9.7.war: org.eclipse.persistence.moxy-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/org.eclipse.persistence.moxy-5.0.0-B10.jar
MD5: 550ec8c0a31fbc5b6d0cd63f75b7d897
SHA1: aede7488445daebad7fb1f7202593e0800e858db
SHA256: 6d040ff629d81d54a7d5f18e73370288126062db7325a87e13fc97bbe65f935a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.moxy High
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Vendor Manifest extension-name org.eclipse.persistence.moxy Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Vendor pom artifactid eclipse.persistence.moxy Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink MOXy High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.moxy High
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink MOXy Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Product Manifest extension-name org.eclipse.persistence.moxy Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Product pom artifactid eclipse.persistence.moxy Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink MOXy High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.moxy@5.0.0-B10
(Confidence :High)
command-ssh-connector-0.9.7.war: snakeyaml-2.2.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/snakeyaml-2.2.jar
MD5: d78aacf5f2de5b52f1a327470efd1ad7
SHA1: 3af797a25458550a16bf89acc8e4ab2b7f2bfce0
SHA256: 1467931448a0817696ae2805b7b8b20bfb082652bf9c4efaed528930dc49389b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.2 High
Version pom version 2.2 Highest
command-ssh-connector-0.9.7.war: war-connector-bridge-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/war-connector-bridge-0.9.5.jar
MD5: d30d230b69cd912e0a5b520226115414
SHA1: f87d602579133c6c538e341a3891458f176c5666
SHA256: 9bc5dafd561bc7a99979f603ac5331eacd3d3c8f21f717b24fed1ff8045ec421
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 0.9.5 High
command-ssh-connector-0.9.7.war: yaml-descriptor-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/command-ssh-connector/0.9.7/d952b98bcc6334dc7f71d5e5d780c8d0e3799c70/command-ssh-connector-0.9.7.war/WEB-INF/lib/yaml-descriptor-0.9.5.jar
MD5: 139586d6d73e3a49bd3e7fba273f0199
SHA1: 0484c4ecddab80a4c8b1a4d12667750af151e8bd
SHA256: ff7826a7641fb90aca304878bc97d505da06d971d2df3f0b272f621aeaa3abff
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 0.9.5 High
commons-beanutils-1.11.0.jar
Description:
Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-beanutils/commons-beanutils/1.11.0/ac03ea606d13de04c2e4508227680faff151f491/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256: 9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-beanutils High
Vendor gradle artifactid commons-beanutils Highest
Vendor gradle groupid commons-beanutils Highest
Vendor jar package name apache Highest
Vendor jar package name beanutils Highest
Vendor jar package name commons Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-beanutils Low
Vendor pom developer email britter@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email craigmcc@apache.org Low
Vendor pom developer email dion@apache.org Low
Vendor pom developer email epugh@apache.org Low
Vendor pom developer email geirm@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jcarman@apache.org Low
Vendor pom developer email jconlon@apache.org Low
Vendor pom developer email jstrachan@apache.org Low
Vendor pom developer email morgand@apache.org Low
Vendor pom developer email mvdb@apache.org Low
Vendor pom developer email niallp@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer email scolebourne@apache.org Low
Vendor pom developer email skitching@apache.org Low
Vendor pom developer email stain@apache.org Low
Vendor pom developer email tobrien@apache.org Low
Vendor pom developer email yoavs@apache.org Low
Vendor pom developer id britter Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id dion Medium
Vendor pom developer id epugh Medium
Vendor pom developer id geirm Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id jconlon Medium
Vendor pom developer id jstrachan Medium
Vendor pom developer id morgand Medium
Vendor pom developer id mvdb Medium
Vendor pom developer id niallp Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer id skitching Medium
Vendor pom developer id stain Medium
Vendor pom developer id tobrien Medium
Vendor pom developer id yoavs Medium
Vendor pom developer name Benedikt Ritter Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name David Eric Pugh Medium
Vendor pom developer name Dion Gillard Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Geir Magnusson Jr. Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name James Strachan Medium
Vendor pom developer name John E. Conlon Medium
Vendor pom developer name Martin van den Bemt Medium
Vendor pom developer name Morgan James Delagrange Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Simon Kitching Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Stian Soiland-Reyes Medium
Vendor pom developer name Tim O'Brien Medium
Vendor pom developer name Yoav Shapira Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-beanutils Highest
Vendor pom name Apache Commons BeanUtils High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-beanutils Highest
Product file name commons-beanutils High
Product gradle artifactid commons-beanutils Highest
Product jar package name apache Highest
Product jar package name beanutils Highest
Product jar package name commons Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils Low
Product Manifest Bundle-Name Apache Commons BeanUtils Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium
Product Manifest Implementation-Title Apache Commons BeanUtils High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons BeanUtils Medium
Product pom artifactid commons-beanutils Highest
Product pom developer email britter@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email craigmcc@apache.org Low
Product pom developer email dion@apache.org Low
Product pom developer email epugh@apache.org Low
Product pom developer email geirm@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jcarman@apache.org Low
Product pom developer email jconlon@apache.org Low
Product pom developer email jstrachan@apache.org Low
Product pom developer email morgand@apache.org Low
Product pom developer email mvdb@apache.org Low
Product pom developer email niallp@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer email scolebourne@apache.org Low
Product pom developer email skitching@apache.org Low
Product pom developer email stain@apache.org Low
Product pom developer email tobrien@apache.org Low
Product pom developer email yoavs@apache.org Low
Product pom developer id britter Low
Product pom developer id chtompki Low
Product pom developer id craigmcc Low
Product pom developer id dion Low
Product pom developer id epugh Low
Product pom developer id geirm Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id jconlon Low
Product pom developer id jstrachan Low
Product pom developer id morgand Low
Product pom developer id mvdb Low
Product pom developer id niallp Low
Product pom developer id rdonkin Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id scolebourne Low
Product pom developer id skitching Low
Product pom developer id stain Low
Product pom developer id tobrien Low
Product pom developer id yoavs Low
Product pom developer name Benedikt Ritter Low
Product pom developer name Craig McClanahan Low
Product pom developer name David Eric Pugh Low
Product pom developer name Dion Gillard Low
Product pom developer name Gary Gregory Low
Product pom developer name Geir Magnusson Jr. Low
Product pom developer name James Carman Low
Product pom developer name James Strachan Low
Product pom developer name John E. Conlon Low
Product pom developer name Martin van den Bemt Low
Product pom developer name Morgan James Delagrange Low
Product pom developer name Niall Pemberton Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Simon Kitching Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Stian Soiland-Reyes Low
Product pom developer name Tim O'Brien Low
Product pom developer name Yoav Shapira Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-beanutils Highest
Product pom name Apache Commons BeanUtils High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-beanutils Medium
Version file version 1.11.0 High
Version gradle version 1.11.0 Highest
Version Manifest Bundle-Version 1.11.0 High
Version Manifest Implementation-Version 1.11.0 High
Version pom parent-version 1.11.0 Low
Version pom version 1.11.0 Highest
commons-cli-1.5.0.jar
Description:
Apache Commons CLI provides a simple API for presenting, processing and validating a Command Line Interface.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-cli/commons-cli/1.5.0/dc98be5d5390230684a092589d70ea76a147925c/commons-cli-1.5.0.jar
MD5: 6c3b2052160144196118b1f019504388
SHA1: dc98be5d5390230684a092589d70ea76a147925c
SHA256: bc8bb01fc0fad250385706e20f927ddcff6173f6339b387dc879237752567ac6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-cli-1.5.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-cli High
Vendor gradle artifactid commons-cli Highest
Vendor gradle groupid commons-cli Highest
Vendor jar package name apache Highest
Vendor jar package name cli Highest
Vendor jar package name commons Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-cli/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.cli Medium
Vendor Manifest implementation-build UNKNOWN@re81a871025cd2dd5bc1d3b473c3c495533e7b8f4; 2021-10-23 21:47:04+0000 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-cli Low
Vendor pom developer email bob@werken.com Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email ebourg@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jbjk@mac.com Low
Vendor pom developer email jstrachan@apache.org Low
Vendor pom developer email roxspring@imapmail.org Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer id bob Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id ebourg Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jkeyes Medium
Vendor pom developer id jstrachan Medium
Vendor pom developer id roxspring Medium
Vendor pom developer id tn Medium
Vendor pom developer name Bob McWhirter Medium
Vendor pom developer name Emmanuel Bourg Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name James Strachan Medium
Vendor pom developer name John Keyes Medium
Vendor pom developer name Rob Oxspring Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer org Ariane Software Medium
Vendor pom developer org Indigo Stone Medium
Vendor pom developer org integral Source Medium
Vendor pom developer org SpiritSoft, Inc. Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org Werken Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-cli Highest
Vendor pom name Apache Commons CLI High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-cli/ Highest
Product file name commons-cli High
Product gradle artifactid commons-cli Highest
Product jar package name apache Highest
Product jar package name cli Highest
Product jar package name commons Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-cli/ Low
Product Manifest Bundle-Name Apache Commons CLI Medium
Product Manifest bundle-symbolicname org.apache.commons.cli Medium
Product Manifest implementation-build UNKNOWN@re81a871025cd2dd5bc1d3b473c3c495533e7b8f4; 2021-10-23 21:47:04+0000 Low
Product Manifest Implementation-Title Apache Commons CLI High
Product Manifest specification-title Apache Commons CLI Medium
Product pom artifactid commons-cli Highest
Product pom developer email bob@werken.com Low
Product pom developer email chtompki@apache.org Low
Product pom developer email ebourg@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jbjk@mac.com Low
Product pom developer email jstrachan@apache.org Low
Product pom developer email roxspring@imapmail.org Low
Product pom developer email tn@apache.org Low
Product pom developer id bob Low
Product pom developer id chtompki Low
Product pom developer id ebourg Low
Product pom developer id ggregory Low
Product pom developer id jkeyes Low
Product pom developer id jstrachan Low
Product pom developer id roxspring Low
Product pom developer id tn Low
Product pom developer name Bob McWhirter Low
Product pom developer name Emmanuel Bourg Low
Product pom developer name Gary Gregory Low
Product pom developer name James Strachan Low
Product pom developer name John Keyes Low
Product pom developer name Rob Oxspring Low
Product pom developer name Rob Tompkins Low
Product pom developer name Thomas Neidhart Low
Product pom developer org Ariane Software Low
Product pom developer org Indigo Stone Low
Product pom developer org integral Source Low
Product pom developer org SpiritSoft, Inc. Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org Werken Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-cli Highest
Product pom name Apache Commons CLI High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-cli/ Medium
Version file version 1.5.0 High
Version gradle version 1.5.0 Highest
Version Manifest Bundle-Version 1.5.0 High
Version Manifest Implementation-Version 1.5.0 High
Version pom parent-version 1.5.0 Low
Version pom version 1.5.0 Highest
pkg:maven/commons-cli/commons-cli@1.5.0
(Confidence :High)
commons-codec-1.17.1.jar
Description:
The Apache Commons Codec component contains encoders and decoders for
various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-codec/commons-codec/1.17.1/973638b7149d333563584137ebf13a691bb60579/commons-codec-1.17.1.jar
MD5: 7b3438ab4c6d91e0066d410947e43f3e
SHA1: 973638b7149d333563584137ebf13a691bb60579
SHA256: f9f6cb103f2ddc3c99a9d80ada2ae7bf0685111fd6bffccb72033d1da4e6ff23
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
commons-codec-1.17.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-codec High
Vendor gradle artifactid commons-codec Highest
Vendor gradle groupid commons-codec Highest
Vendor jar package name apache Highest
Vendor jar package name codec Highest
Vendor jar package name commons Highest
Vendor jar package name digest Highest
Vendor Manifest automatic-module-name org.apache.commons.codec Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-codec Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email dgraham@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jon@collab.net Low
Vendor pom developer email julius@apache.org Low
Vendor pom developer email mattsicker@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@totalsync.com Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer email tobrien@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id dgraham Medium
Vendor pom developer id dlr Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jon Medium
Vendor pom developer id julius Medium
Vendor pom developer id mattsicker Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id tn Medium
Vendor pom developer id tobrien Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name David Graham Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jon S. Stevens Medium
Vendor pom developer name Julius Davies Medium
Vendor pom developer name Matt Sicker Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer name Tim OBrien Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL http://juliusdavies.ca/ Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-codec Highest
Vendor pom name Apache Commons Codec High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest
Product file name commons-codec High
Product gradle artifactid commons-codec Highest
Product jar package name apache Highest
Product jar package name codec Highest
Product jar package name commons Highest
Product jar package name digest Highest
Product Manifest automatic-module-name org.apache.commons.codec Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium
Product Manifest Implementation-Title Apache Commons Codec High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Codec Medium
Product pom artifactid commons-codec Highest
Product pom developer email bayard@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email dgraham@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jon@collab.net Low
Product pom developer email julius@apache.org Low
Product pom developer email mattsicker@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@totalsync.com Low
Product pom developer email tn@apache.org Low
Product pom developer email tobrien@apache.org Low
Product pom developer id bayard Low
Product pom developer id chtompki Low
Product pom developer id dgraham Low
Product pom developer id dlr Low
Product pom developer id ggregory Low
Product pom developer id jon Low
Product pom developer id julius Low
Product pom developer id mattsicker Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id tn Low
Product pom developer id tobrien Low
Product pom developer name Daniel Rall Low
Product pom developer name David Graham Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name Jon S. Stevens Low
Product pom developer name Julius Davies Low
Product pom developer name Matt Sicker Low
Product pom developer name Rob Tompkins Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Thomas Neidhart Low
Product pom developer name Tim OBrien Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL http://juliusdavies.ca/ Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-codec Highest
Product pom name Apache Commons Codec High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-codec/ Medium
Version file version 1.17.1 High
Version gradle version 1.17.1 Highest
Version Manifest Bundle-Version 1.17.1 High
Version Manifest Implementation-Version 1.17.1 High
Version pom parent-version 1.17.1 Low
Version pom version 1.17.1 Highest
pkg:maven/commons-codec/commons-codec@1.17.1
(Confidence :High)
commons-codec-1.21.0.jar
Description:
The Apache Commons Codec component contains encoders and decoders for
formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-codec/commons-codec/1.21.0/d95f998db5f89900fe895daf6cd2cddcb2f1d64b/commons-codec-1.21.0.jar
MD5: c49977029838babaf8a71485aa9aaef8
SHA1: d95f998db5f89900fe895daf6cd2cddcb2f1d64b
SHA256: 4da851cb6abfb98bfe9eb77c5e5fc47f5414fa28b94e21b7fd9a646705dc167f
Referenced In Project/Scope: server-start:runtimeClasspath
commons-codec-1.21.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-codec High
Vendor gradle artifactid commons-codec Highest
Vendor gradle groupid commons-codec Highest
Vendor jar package name apache Highest
Vendor jar package name codec Highest
Vendor jar package name commons Highest
Vendor jar package name digest Highest
Vendor Manifest automatic-module-name org.apache.commons.codec Medium
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-codec Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email dgraham@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jon@collab.net Low
Vendor pom developer email julius@apache.org Low
Vendor pom developer email mattsicker@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@totalsync.com Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer email tobrien@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id dgraham Medium
Vendor pom developer id dlr Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jon Medium
Vendor pom developer id julius Medium
Vendor pom developer id mattsicker Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id tn Medium
Vendor pom developer id tobrien Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name David Graham Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jon S. Stevens Medium
Vendor pom developer name Julius Davies Medium
Vendor pom developer name Matt Sicker Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer name Tim OBrien Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://juliusdavies.ca/ Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-codec Highest
Vendor pom name Apache Commons Codec High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest
Product file name commons-codec High
Product gradle artifactid commons-codec Highest
Product jar package name apache Highest
Product jar package name codec Highest
Product jar package name commons Highest
Product jar package name digest Highest
Product Manifest automatic-module-name org.apache.commons.codec Medium
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium
Product Manifest Implementation-Title Apache Commons Codec High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Codec Medium
Product pom artifactid commons-codec Highest
Product pom developer email bayard@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email dgraham@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jon@collab.net Low
Product pom developer email julius@apache.org Low
Product pom developer email mattsicker@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@totalsync.com Low
Product pom developer email tn@apache.org Low
Product pom developer email tobrien@apache.org Low
Product pom developer id bayard Low
Product pom developer id chtompki Low
Product pom developer id dgraham Low
Product pom developer id dlr Low
Product pom developer id ggregory Low
Product pom developer id jon Low
Product pom developer id julius Low
Product pom developer id mattsicker Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id tn Low
Product pom developer id tobrien Low
Product pom developer name Daniel Rall Low
Product pom developer name David Graham Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name Jon S. Stevens Low
Product pom developer name Julius Davies Low
Product pom developer name Matt Sicker Low
Product pom developer name Rob Tompkins Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Thomas Neidhart Low
Product pom developer name Tim OBrien Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://juliusdavies.ca/ Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-codec Highest
Product pom name Apache Commons Codec High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-codec/ Medium
Version file version 1.21.0 High
Version gradle version 1.21.0 Highest
Version Manifest Bundle-Version 1.21.0 High
Version Manifest Implementation-Version 1.21.0 High
Version pom parent-version 1.21.0 Low
Version pom version 1.21.0 Highest
pkg:maven/commons-codec/commons-codec@1.21.0
(Confidence :High)
commons-collections-3.2.2.jar
Description:
Types that extend and augment the Java Collections Framework.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-collections/commons-collections/3.2.2/8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256: eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-collections-3.2.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-collections High
Vendor gradle artifactid commons-collections Highest
Vendor gradle groupid commons-collections Highest
Vendor jar package name apache Highest
Vendor jar package name collections Highest
Vendor jar package name commons Highest
Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium
Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Vendor Manifest implementation-url http://commons.apache.org/collections/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-collections Low
Vendor pom developer id amamment Medium
Vendor pom developer id bayard Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id geirm Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id matth Medium
Vendor pom developer id morgand Medium
Vendor pom developer id psteitz Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name Arun M. Thomas Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name Geir Magnusson Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Matthew Hawthorne Medium
Vendor pom developer name Morgan Delagrange Medium
Vendor pom developer name Phil Steitz Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom groupid commons-collections Highest
Vendor pom name Apache Commons Collections High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url http://commons.apache.org/collections/ Highest
Product file name commons-collections High
Product gradle artifactid commons-collections Highest
Product jar package name apache Highest
Product jar package name collections Highest
Product jar package name commons Highest
Product Manifest bundle-docurl http://commons.apache.org/collections/ Low
Product Manifest Bundle-Name Apache Commons Collections Medium
Product Manifest bundle-symbolicname org.apache.commons.collections Medium
Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Product Manifest Implementation-Title Apache Commons Collections High
Product Manifest implementation-url http://commons.apache.org/collections/ Low
Product Manifest specification-title Apache Commons Collections Medium
Product pom artifactid commons-collections Highest
Product pom developer id amamment Low
Product pom developer id bayard Low
Product pom developer id craigmcc Low
Product pom developer id geirm Low
Product pom developer id jcarman Low
Product pom developer id matth Low
Product pom developer id morgand Low
Product pom developer id psteitz Low
Product pom developer id rdonkin Low
Product pom developer id rwaldhoff Low
Product pom developer id scolebourne Low
Product pom developer name Arun M. Thomas Low
Product pom developer name Craig McClanahan Low
Product pom developer name Geir Magnusson Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Matthew Hawthorne Low
Product pom developer name Morgan Delagrange Low
Product pom developer name Phil Steitz Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Stephen Colebourne Low
Product pom groupid commons-collections Highest
Product pom name Apache Commons Collections High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url http://commons.apache.org/collections/ Medium
Version file version 3.2.2 High
Version gradle version 3.2.2 Highest
Version Manifest Bundle-Version 3.2.2 High
Version Manifest Implementation-Version 3.2.2 High
Version pom parent-version 3.2.2 Low
Version pom version 3.2.2 Highest
commons-collections4-4.4.jar
Description:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-collections4/4.4/62ebe7544cb7164d87e0637a2a6a2bdc981395e8/commons-collections4-4.4.jar
MD5: 4a37023740719b391f10030362c86be6
SHA1: 62ebe7544cb7164d87e0637a2a6a2bdc981395e8
SHA256: 1df8b9430b5c8ed143d7815e403e33ef5371b2400aadbe9bda0883762e0846d1
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-collections4-4.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-collections4 High
Vendor gradle artifactid commons-collections4 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name collections4 Highest
Vendor jar package name commons Highest
Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium
Vendor Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-collections4 Low
Vendor pom developer id adriannistor Medium
Vendor pom developer id amamment Medium
Vendor pom developer id bayard Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id dlaha Medium
Vendor pom developer id geirm Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id luc Medium
Vendor pom developer id matth Medium
Vendor pom developer id mbenson Medium
Vendor pom developer id morgand Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer id tn Medium
Vendor pom developer name Adrian Nistor Medium
Vendor pom developer name Arun M. Thomas Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name Dipanjan Laha Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Geir Magnusson Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Luc Maisonobe Medium
Vendor pom developer name Matt Benson Medium
Vendor pom developer name Matthew Hawthorne Medium
Vendor pom developer name Morgan Delagrange Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Collections High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url https://commons.apache.org/proper/commons-collections/ Highest
Product file name commons-collections4 High
Product gradle artifactid commons-collections4 Highest
Product jar package name apache Highest
Product jar package name collections4 Highest
Product jar package name commons Highest
Product Manifest automatic-module-name org.apache.commons.collections4 Medium
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low
Product Manifest Bundle-Name Apache Commons Collections Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium
Product Manifest Implementation-Title Apache Commons Collections High
Product Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low
Product Manifest specification-title Apache Commons Collections Medium
Product pom artifactid commons-collections4 Highest
Product pom developer id adriannistor Low
Product pom developer id amamment Low
Product pom developer id bayard Low
Product pom developer id chtompki Low
Product pom developer id craigmcc Low
Product pom developer id dlaha Low
Product pom developer id geirm Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id luc Low
Product pom developer id matth Low
Product pom developer id mbenson Low
Product pom developer id morgand Low
Product pom developer id rdonkin Low
Product pom developer id rwaldhoff Low
Product pom developer id scolebourne Low
Product pom developer id tn Low
Product pom developer name Adrian Nistor Low
Product pom developer name Arun M. Thomas Low
Product pom developer name Craig McClanahan Low
Product pom developer name Dipanjan Laha Low
Product pom developer name Gary Gregory Low
Product pom developer name Geir Magnusson Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Luc Maisonobe Low
Product pom developer name Matt Benson Low
Product pom developer name Matthew Hawthorne Low
Product pom developer name Morgan Delagrange Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Thomas Neidhart Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Collections High
Product pom parent-artifactid commons-parent Medium
Product pom url https://commons.apache.org/proper/commons-collections/ Medium
Version file version 4.4 High
Version gradle version 4.4 Highest
Version Manifest Implementation-Version 4.4 High
Version pom parent-version 4.4 Low
Version pom version 4.4 Highest
commons-compress-1.27.1.jar
Description:
Apache Commons Compress defines an API for working with
compression and archive formats. These include bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-compress/1.27.1/a19151084758e2fbb6b41eddaa88e7b8ff4e6599/commons-compress-1.27.1.jar
MD5: 1db4bd87b0082044c6e7a6af0b977a3e
SHA1: a19151084758e2fbb6b41eddaa88e7b8ff4e6599
SHA256: 293d80f54b536b74095dcd7ea3cf0a29bbfc3402519281332495f4420d370d16
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-compress-1.27.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-compress High
Vendor gradle artifactid commons-compress Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name compress Highest
Vendor Manifest automatic-module-name org.apache.commons.compress Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium
Vendor Manifest extension-name org.apache.commons.compress Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-compress Low
Vendor pom developer email bodewig at apache.org Low
Vendor pom developer email chtompki at apache.org Low
Vendor pom developer email damjan at apache.org Low
Vendor pom developer email ebourg at apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email grobmeier at apache.org Low
Vendor pom developer email julius at apache.org Low
Vendor pom developer email peterlee at apache.org Low
Vendor pom developer email sebb at apache.org Low
Vendor pom developer email tcurdt at apache.org Low
Vendor pom developer id bodewig Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id damjan Medium
Vendor pom developer id ebourg Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id grobmeier Medium
Vendor pom developer id julius Medium
Vendor pom developer id peterlee Medium
Vendor pom developer id sebb Medium
Vendor pom developer id tcurdt Medium
Vendor pom developer name Christian Grobmeier Medium
Vendor pom developer name Damjan Jovanovic Medium
Vendor pom developer name Emmanuel Bourg Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Julius Davies Medium
Vendor pom developer name Peter Alfred Lee Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Sebastian Bazley Medium
Vendor pom developer name Stefan Bodewig Medium
Vendor pom developer name Torsten Curdt Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Compress High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest
Product file name commons-compress High
Product gradle artifactid commons-compress Highest
Product jar package name 9 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name compress Highest
Product Manifest automatic-module-name org.apache.commons.compress Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low
Product Manifest Bundle-Name Apache Commons Compress Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium
Product Manifest extension-name org.apache.commons.compress Medium
Product Manifest Implementation-Title Apache Commons Compress High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Apache Commons Compress Medium
Product pom artifactid commons-compress Highest
Product pom developer email bodewig at apache.org Low
Product pom developer email chtompki at apache.org Low
Product pom developer email damjan at apache.org Low
Product pom developer email ebourg at apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email grobmeier at apache.org Low
Product pom developer email julius at apache.org Low
Product pom developer email peterlee at apache.org Low
Product pom developer email sebb at apache.org Low
Product pom developer email tcurdt at apache.org Low
Product pom developer id bodewig Low
Product pom developer id chtompki Low
Product pom developer id damjan Low
Product pom developer id ebourg Low
Product pom developer id ggregory Low
Product pom developer id grobmeier Low
Product pom developer id julius Low
Product pom developer id peterlee Low
Product pom developer id sebb Low
Product pom developer id tcurdt Low
Product pom developer name Christian Grobmeier Low
Product pom developer name Damjan Jovanovic Low
Product pom developer name Emmanuel Bourg Low
Product pom developer name Gary Gregory Low
Product pom developer name Julius Davies Low
Product pom developer name Peter Alfred Lee Low
Product pom developer name Rob Tompkins Low
Product pom developer name Sebastian Bazley Low
Product pom developer name Stefan Bodewig Low
Product pom developer name Torsten Curdt Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Compress High
Product pom parent-artifactid commons-parent Medium
Product pom url https://commons.apache.org/proper/commons-compress/ Medium
Version file version 1.27.1 High
Version gradle version 1.27.1 Highest
Version Manifest Bundle-Version 1.27.1 High
Version Manifest Implementation-Version 1.27.1 High
Version pom parent-version 1.27.1 Low
Version pom version 1.27.1 Highest
commons-fileupload-1.6.0.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-fileupload/commons-fileupload/1.6.0/2392704cccb4632b3ccd9b8cfbe2943cca6fc455/commons-fileupload-1.6.0.jar
MD5: c10bfd8952ec31282fffd3b2625d87ce
SHA1: 2392704cccb4632b3ccd9b8cfbe2943cca6fc455
SHA256: 9383272c93569afeabedb16923a94a6dc8a5bd7a2f9f83bf326af4ee68434629
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-fileupload-1.6.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-fileupload High
Vendor gradle artifactid commons-fileupload Highest
Vendor gradle groupid commons-fileupload Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name fileupload Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-fileupload Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-fileupload Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email dion@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jason@zenplex.com Low
Vendor pom developer email jmcnally@collab.net Low
Vendor pom developer email jochen.wiedmann@gmail.com Low
Vendor pom developer email martinc@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email sean |at| seansullivan |dot| com Low
Vendor pom developer email simonetripodi@apache.org Low
Vendor pom developer id chtompki Medium
Vendor pom developer id dion Medium
Vendor pom developer id dlr Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jmcnally Medium
Vendor pom developer id jochen Medium
Vendor pom developer id jvanzyl Medium
Vendor pom developer id martinc Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id simonetripodi Medium
Vendor pom developer id sullis Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name dIon Gillard Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Jason van Zyl Medium
Vendor pom developer name Jochen Wiedmann Medium
Vendor pom developer name John McNally Medium
Vendor pom developer name Martin Cooper Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Sean C. Sullivan Medium
Vendor pom developer name Simone Tripodi Medium
Vendor pom developer org Adobe Medium
Vendor pom developer org CollabNet Medium
Vendor pom developer org Multitask Consulting Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org Yahoo! Medium
Vendor pom developer org Zenplex Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-fileupload Highest
Vendor pom name Apache Commons FileUpload High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-fileupload/ Highest
Product file name commons-fileupload High
Product gradle artifactid commons-fileupload Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name fileupload Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-fileupload Medium
Product Manifest Implementation-Title Apache Commons FileUpload High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons FileUpload Medium
Product pom artifactid commons-fileupload Highest
Product pom developer email chtompki@apache.org Low
Product pom developer email dion@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jason@zenplex.com Low
Product pom developer email jmcnally@collab.net Low
Product pom developer email jochen.wiedmann@gmail.com Low
Product pom developer email martinc@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email sean |at| seansullivan |dot| com Low
Product pom developer email simonetripodi@apache.org Low
Product pom developer id chtompki Low
Product pom developer id dion Low
Product pom developer id dlr Low
Product pom developer id ggregory Low
Product pom developer id jmcnally Low
Product pom developer id jochen Low
Product pom developer id jvanzyl Low
Product pom developer id martinc Low
Product pom developer id rdonkin Low
Product pom developer id simonetripodi Low
Product pom developer id sullis Low
Product pom developer name Daniel Rall Low
Product pom developer name dIon Gillard Low
Product pom developer name Gary Gregory Low
Product pom developer name Jason van Zyl Low
Product pom developer name Jochen Wiedmann Low
Product pom developer name John McNally Low
Product pom developer name Martin Cooper Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Sean C. Sullivan Low
Product pom developer name Simone Tripodi Low
Product pom developer org Adobe Low
Product pom developer org CollabNet Low
Product pom developer org Multitask Consulting Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org Yahoo! Low
Product pom developer org Zenplex Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-fileupload Highest
Product pom name Apache Commons FileUpload High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-fileupload/ Medium
Version file version 1.6.0 High
Version gradle version 1.6.0 Highest
Version Manifest Bundle-Version 1.6.0 High
Version Manifest Implementation-Version 1.6.0 High
Version pom parent-version 1.6.0 Low
Version pom version 1.6.0 Highest
commons-fileupload2-core-2.0.0-M5.jar
Description:
The Apache Commons FileUpload Core component provides the framework for a simple yet flexible means of adding support for multipart
file upload functionality to servlets, portlets, and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-fileupload2-core/2.0.0-M5/bfabb601638301c1b85891e4deaa2ae233a7138e/commons-fileupload2-core-2.0.0-M5.jar
MD5: 000adbe4fbf2d84fb394eb8d1cd05121
SHA1: bfabb601638301c1b85891e4deaa2ae233a7138e
SHA256: f129b10b022a8072b1672069a49b34699877645bb2bdfe0a5cef819f788771ff
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-fileupload2-core-2.0.0-M5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-fileupload2-core High
Vendor gradle artifactid commons-fileupload2-core Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name core Highest
Vendor jar package name fileupload2 Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/commons-fileupload2-core/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-fileupload2-core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-fileupload2-core Low
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons FileUpload Core High
Vendor pom parent-artifactid commons-fileupload2 Low
Product file name commons-fileupload2-core High
Product gradle artifactid commons-fileupload2-core Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name core Highest
Product jar package name fileupload2 Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/commons-fileupload2-core/ Low
Product Manifest Bundle-Name Apache Commons FileUpload Core Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-fileupload2-core Medium
Product Manifest Implementation-Title Apache Commons FileUpload Core High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons FileUpload Core Medium
Product pom artifactid commons-fileupload2-core Highest
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons FileUpload Core High
Product pom parent-artifactid commons-fileupload2 Medium
Version gradle version 2.0.0-M5 Highest
Version Manifest Implementation-Version 2.0.0-M5 High
Version pom version 2.0.0-M5 Highest
commons-fileupload2-jakarta-servlet6-2.0.0-M5.jar
Description:
The Apache Commons FileUpload Jakarta component provides a simple yet flexible means of adding support for multipart
file upload functionality to Jakarta servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-fileupload2-jakarta-servlet6/2.0.0-M5/d20835e2ef6e38ac370f4d2cba5c690146cb8be5/commons-fileupload2-jakarta-servlet6-2.0.0-M5.jar
MD5: 0f803f5ded1bdaf8e7b87d589eee9be5
SHA1: d20835e2ef6e38ac370f4d2cba5c690146cb8be5
SHA256: aa34cbcfc3836f9e90a399756e1e85572d4e5f264b3ef26c1f3b8fdde31abd0f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-fileupload2-jakarta-servlet6-2.0.0-M5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-fileupload2-jakarta-servlet6 High
Vendor gradle artifactid commons-fileupload2-jakarta-servlet6 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name fileupload2 Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/commons-fileupload2-jakarta-servlet6/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-fileupload2-jakarta-servlet6 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-fileupload2-jakarta-servlet6 Low
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons FileUpload Jakarta Servlet 6 High
Vendor pom parent-artifactid commons-fileupload2 Low
Product file name commons-fileupload2-jakarta-servlet6 High
Product gradle artifactid commons-fileupload2-jakarta-servlet6 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name fileupload2 Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-fileupload/commons-fileupload2-jakarta-servlet6/ Low
Product Manifest Bundle-Name Apache Commons FileUpload Jakarta Servlet 6 Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-fileupload2-jakarta-servlet6 Medium
Product Manifest Implementation-Title Apache Commons FileUpload Jakarta Servlet 6 High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons FileUpload Jakarta Servlet 6 Medium
Product pom artifactid commons-fileupload2-jakarta-servlet6 Highest
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons FileUpload Jakarta Servlet 6 High
Product pom parent-artifactid commons-fileupload2 Medium
Version gradle version 2.0.0-M5 Highest
Version Manifest Implementation-Version 2.0.0-M5 High
Version pom version 2.0.0-M5 Highest
commons-httpclient-3.1.jar
Description:
The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily.
License:
Apache License: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-httpclient/commons-httpclient/3.1/964cd74171f427720480efdec40a7c7f6e58426a/commons-httpclient-3.1.jar
MD5: 8ad8c9229ef2d59ab9f59f7050e846a5
SHA1: 964cd74171f427720480efdec40a7c7f6e58426a
SHA256: dbd4953d013e10e7c1cc3701a3e6ccd8c950c892f08d804fabfac21705930443
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-httpclient-3.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-httpclient High
Vendor gradle artifactid commons-httpclient Highest
Vendor gradle groupid commons-httpclient Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name commons Low
Vendor jar package name httpclient Low
Vendor manifest: org/apache/commons/httpclient Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid commons-httpclient Low
Vendor pom developer email adrian.sutton -at- ephox.com Low
Vendor pom developer email dion -at- apache.org Low
Vendor pom developer email jericho -at- apache.org Low
Vendor pom developer email jsdever -at- apache.org Low
Vendor pom developer email mbecke -at- apache.org Low
Vendor pom developer email oglueck -at- apache.org Low
Vendor pom developer email olegk -at- apache.org Low
Vendor pom developer email rwaldhoff -at- apache Low
Vendor pom developer email sullis -at- apache.org Low
Vendor pom developer id adrian Medium
Vendor pom developer id dion Medium
Vendor pom developer id jericho Medium
Vendor pom developer id jsdever Medium
Vendor pom developer id mbecke Medium
Vendor pom developer id oglueck Medium
Vendor pom developer id olegk Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sullis Medium
Vendor pom developer name Adrian Sutton Medium
Vendor pom developer name dIon Gillard Medium
Vendor pom developer name Jeff Dever Medium
Vendor pom developer name Michael Becke Medium
Vendor pom developer name Oleg Kalnichevski Medium
Vendor pom developer name Ortwin Glueck Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Sean C. Sullivan Medium
Vendor pom developer name Sung-Gu Medium
Vendor pom developer org Britannica Medium
Vendor pom developer org Independent consultant Medium
Vendor pom developer org Intencha Medium
Vendor pom developer org Multitask Consulting Medium
Vendor pom groupid commons-httpclient Highest
Vendor pom name HttpClient High
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://jakarta.apache.org/ Medium
Vendor pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Highest
Product file name commons-httpclient High
Product gradle artifactid commons-httpclient Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name commons Low
Product jar package name httpclient Highest
Product jar package name httpclient Low
Product manifest: org/apache/commons/httpclient Implementation-Title org.apache.commons.httpclient Medium
Product manifest: org/apache/commons/httpclient Specification-Title Jakarta Commons HttpClient Medium
Product pom artifactid commons-httpclient Highest
Product pom developer email adrian.sutton -at- ephox.com Low
Product pom developer email dion -at- apache.org Low
Product pom developer email jericho -at- apache.org Low
Product pom developer email jsdever -at- apache.org Low
Product pom developer email mbecke -at- apache.org Low
Product pom developer email oglueck -at- apache.org Low
Product pom developer email olegk -at- apache.org Low
Product pom developer email rwaldhoff -at- apache Low
Product pom developer email sullis -at- apache.org Low
Product pom developer id adrian Low
Product pom developer id dion Low
Product pom developer id jericho Low
Product pom developer id jsdever Low
Product pom developer id mbecke Low
Product pom developer id oglueck Low
Product pom developer id olegk Low
Product pom developer id rwaldhoff Low
Product pom developer id sullis Low
Product pom developer name Adrian Sutton Low
Product pom developer name dIon Gillard Low
Product pom developer name Jeff Dever Low
Product pom developer name Michael Becke Low
Product pom developer name Oleg Kalnichevski Low
Product pom developer name Ortwin Glueck Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Sean C. Sullivan Low
Product pom developer name Sung-Gu Low
Product pom developer org Britannica Low
Product pom developer org Independent consultant Low
Product pom developer org Intencha Low
Product pom developer org Multitask Consulting Low
Product pom groupid commons-httpclient Highest
Product pom name HttpClient High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://jakarta.apache.org/ Low
Product pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Medium
Version file version 3.1 High
Version gradle version 3.1 Highest
Version manifest: org/apache/commons/httpclient Implementation-Version 3.1 Medium
Version pom version 3.1 Highest
CVE-2012-5783 suppress
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CWE-295 Improper Certificate Validation
CVSSv2:
Base Score: MEDIUM (5.8)
Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - BROKEN_LINK
cve@mitre.org - ISSUE_TRACKING,PATCH,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY
cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY
Vulnerable Software & Versions:
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9%40%3Cdev.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457%40%3Cdev.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303%40%3Cgitbox.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89%40%3Cdev.jackrabbit.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d%40%3Ccommits.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381%40%3Ccommits.turbine.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8%40%3Csolr-user.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17%40%3Cdev.jackrabbit.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4%40%3Cgitbox.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://priyankn.github.io/2021-02-26-CVE-2020-13956/
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security@apache.org - https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9%40%3Cdev.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457%40%3Cdev.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303%40%3Cgitbox.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89%40%3Cdev.jackrabbit.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90%40%3Cissues.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d%40%3Ccommits.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec%40%3Cissues.bookkeeper.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381%40%3Ccommits.turbine.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8%40%3Csolr-user.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17%40%3Cdev.jackrabbit.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4%40%3Cgitbox.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858%40%3Cissues.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca%40%3Cissues.bookkeeper.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3%40%3Cissues.hive.apache.org%3E
security@apache.org - MAILING_LIST,VENDOR_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - THIRD_PARTY_ADVISORY
security@apache.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
commons-io-2.18.0.jar
Description:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-io/commons-io/2.18.0/44084ef756763795b31c578403dd028ff4a22950/commons-io-2.18.0.jar
MD5: 8cce74ccf461cd6502ae04c908eca917
SHA1: 44084ef756763795b31c578403dd028ff4a22950
SHA256: f3ca0f8d63c40e23a56d54101c60d5edee136b42d84bfb85bc7963093109cf8b
Referenced In Project/Scope: server-start:webapps
commons-io-2.18.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-io High
Vendor gradle artifactid commons-io Highest
Vendor gradle groupid commons-io Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name file Highest
Vendor jar package name io Highest
Vendor Manifest automatic-module-name org.apache.commons.io Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-io Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email dion@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jeremias@apache.org Low
Vendor pom developer email jochen.wiedmann@gmail.com Low
Vendor pom developer email krosenvold@apache.org Low
Vendor pom developer email martinc@apache.org Low
Vendor pom developer email matth@apache.org Low
Vendor pom developer email nicolaken@apache.org Low
Vendor pom developer email roxspring@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id dion Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jeremias Medium
Vendor pom developer id jochen Medium
Vendor pom developer id jukka Medium
Vendor pom developer id krosenvold Medium
Vendor pom developer id martinc Medium
Vendor pom developer id matth Medium
Vendor pom developer id niallp Medium
Vendor pom developer id nicolaken Medium
Vendor pom developer id roxspring Medium
Vendor pom developer id sanders Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name dIon Gillard Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jeremias Maerki Medium
Vendor pom developer name Jochen Wiedmann Medium
Vendor pom developer name Jukka Zitting Medium
Vendor pom developer name Kristian Rosenvold Medium
Vendor pom developer name Martin Cooper Medium
Vendor pom developer name Matthew Hawthorne Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Nicola Ken Barozzi Medium
Vendor pom developer name Rob Oxspring Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-io Highest
Vendor pom name Apache Commons IO High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-io/ Highest
Product file name commons-io High
Product gradle artifactid commons-io Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name file Highest
Product jar package name io Highest
Product Manifest automatic-module-name org.apache.commons.io Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low
Product Manifest Bundle-Name Apache Commons IO Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium
Product Manifest Implementation-Title Apache Commons IO High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons IO Medium
Product pom artifactid commons-io Highest
Product pom developer email bayard@apache.org Low
Product pom developer email dion@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jeremias@apache.org Low
Product pom developer email jochen.wiedmann@gmail.com Low
Product pom developer email krosenvold@apache.org Low
Product pom developer email martinc@apache.org Low
Product pom developer email matth@apache.org Low
Product pom developer email nicolaken@apache.org Low
Product pom developer email roxspring@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer id bayard Low
Product pom developer id dion Low
Product pom developer id ggregory Low
Product pom developer id jeremias Low
Product pom developer id jochen Low
Product pom developer id jukka Low
Product pom developer id krosenvold Low
Product pom developer id martinc Low
Product pom developer id matth Low
Product pom developer id niallp Low
Product pom developer id nicolaken Low
Product pom developer id roxspring Low
Product pom developer id sanders Low
Product pom developer id scolebourne Low
Product pom developer name dIon Gillard Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name Jeremias Maerki Low
Product pom developer name Jochen Wiedmann Low
Product pom developer name Jukka Zitting Low
Product pom developer name Kristian Rosenvold Low
Product pom developer name Martin Cooper Low
Product pom developer name Matthew Hawthorne Low
Product pom developer name Niall Pemberton Low
Product pom developer name Nicola Ken Barozzi Low
Product pom developer name Rob Oxspring Low
Product pom developer name Scott Sanders Low
Product pom developer name Stephen Colebourne Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-io Highest
Product pom name Apache Commons IO High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-io/ Medium
Version file version 2.18.0 High
Version gradle version 2.18.0 Highest
Version Manifest Bundle-Version 2.18.0 High
Version Manifest Implementation-Version 2.18.0 High
Version pom parent-version 2.18.0 Low
Version pom version 2.18.0 Highest
commons-io-2.21.0.jar
Description:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-io/commons-io/2.21.0/52a6f68fe5afe335cde95461dd5c3412f04996f7/commons-io-2.21.0.jar
MD5: bc7e020873f086ede85f97bd9f013215
SHA1: 52a6f68fe5afe335cde95461dd5c3412f04996f7
SHA256: 7d643a2afea8b058b762aa6fb90e5b256f6c729739f8b3784c3370ddc609e88d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-io-2.21.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-io High
Vendor gradle artifactid commons-io Highest
Vendor gradle groupid commons-io Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name file Highest
Vendor jar package name io Highest
Vendor Manifest automatic-module-name org.apache.commons.io Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium
Vendor Manifest enabledynamicagentloading -XX:+EnableDynamicAgentLoading Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-io Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email dion@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jeremias@apache.org Low
Vendor pom developer email jochen.wiedmann@gmail.com Low
Vendor pom developer email krosenvold@apache.org Low
Vendor pom developer email martinc@apache.org Low
Vendor pom developer email matth@apache.org Low
Vendor pom developer email nicolaken@apache.org Low
Vendor pom developer email roxspring@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id dion Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jeremias Medium
Vendor pom developer id jochen Medium
Vendor pom developer id jukka Medium
Vendor pom developer id krosenvold Medium
Vendor pom developer id martinc Medium
Vendor pom developer id matth Medium
Vendor pom developer id niallp Medium
Vendor pom developer id nicolaken Medium
Vendor pom developer id roxspring Medium
Vendor pom developer id sanders Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name dIon Gillard Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jeremias Maerki Medium
Vendor pom developer name Jochen Wiedmann Medium
Vendor pom developer name Jukka Zitting Medium
Vendor pom developer name Kristian Rosenvold Medium
Vendor pom developer name Martin Cooper Medium
Vendor pom developer name Matthew Hawthorne Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Nicola Ken Barozzi Medium
Vendor pom developer name Rob Oxspring Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-io Highest
Vendor pom name Apache Commons IO High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-io/ Highest
Product file name commons-io High
Product gradle artifactid commons-io Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name file Highest
Product jar package name io Highest
Product Manifest automatic-module-name org.apache.commons.io Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low
Product Manifest Bundle-Name Apache Commons IO Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium
Product Manifest enabledynamicagentloading -XX:+EnableDynamicAgentLoading Low
Product Manifest Implementation-Title Apache Commons IO High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons IO Medium
Product pom artifactid commons-io Highest
Product pom developer email bayard@apache.org Low
Product pom developer email dion@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jeremias@apache.org Low
Product pom developer email jochen.wiedmann@gmail.com Low
Product pom developer email krosenvold@apache.org Low
Product pom developer email martinc@apache.org Low
Product pom developer email matth@apache.org Low
Product pom developer email nicolaken@apache.org Low
Product pom developer email roxspring@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer id bayard Low
Product pom developer id dion Low
Product pom developer id ggregory Low
Product pom developer id jeremias Low
Product pom developer id jochen Low
Product pom developer id jukka Low
Product pom developer id krosenvold Low
Product pom developer id martinc Low
Product pom developer id matth Low
Product pom developer id niallp Low
Product pom developer id nicolaken Low
Product pom developer id roxspring Low
Product pom developer id sanders Low
Product pom developer id scolebourne Low
Product pom developer name dIon Gillard Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name Jeremias Maerki Low
Product pom developer name Jochen Wiedmann Low
Product pom developer name Jukka Zitting Low
Product pom developer name Kristian Rosenvold Low
Product pom developer name Martin Cooper Low
Product pom developer name Matthew Hawthorne Low
Product pom developer name Niall Pemberton Low
Product pom developer name Nicola Ken Barozzi Low
Product pom developer name Rob Oxspring Low
Product pom developer name Scott Sanders Low
Product pom developer name Stephen Colebourne Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-io Highest
Product pom name Apache Commons IO High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-io/ Medium
Version file version 2.21.0 High
Version gradle version 2.21.0 Highest
Version Manifest Bundle-Version 2.21.0 High
Version Manifest Implementation-Version 2.21.0 High
Version pom parent-version 2.21.0 Low
Version pom version 2.21.0 Highest
commons-lang3-3.16.0.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-lang3/3.16.0/3eb54effe40946dfb06dc5cd6c7ce4116cd51ea4/commons-lang3-3.16.0.jar
MD5: 67bc6dbd753fc276d69aeb4cfa205e15
SHA1: 3eb54effe40946dfb06dc5cd6c7ce4116cd51ea4
SHA256: 08709dd74d602b705ce4017d26544210056a4ba583d5b20c09373406fe7a00f8
Referenced In Project/Scope: server-start:compileClasspath
commons-lang3-3.16.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang3 High
Vendor gradle artifactid commons-lang3 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name lang3 Highest
Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-lang3 Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email britter@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email djones@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jcarman@apache.org Low
Vendor pom developer email joerg.schaible@gmx.de Low
Vendor pom developer email lguibert@apache.org Low
Vendor pom developer email oheger@apache.org Low
Vendor pom developer email pbenedict@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email scolebourne@joda.org Low
Vendor pom developer email stevencaswell@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id britter Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id djones Medium
Vendor pom developer id dlr Medium
Vendor pom developer id fredrik Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id joehni Medium
Vendor pom developer id lguibert Medium
Vendor pom developer id mbenson Medium
Vendor pom developer id niallp Medium
Vendor pom developer id oheger Medium
Vendor pom developer id pbenedict Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id scaswell Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name Benedikt Ritter Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name Duncan Jones Medium
Vendor pom developer name Fredrik Westermarck Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Joerg Schaible Medium
Vendor pom developer name Loic Guibert Medium
Vendor pom developer name Matt Benson Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Oliver Heger Medium
Vendor pom developer name Paul Benedict Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Steven Caswell Medium
Vendor pom developer org Carman Consulting, Inc. Medium
Vendor pom developer org CollabNet, Inc. Medium
Vendor pom developer org SITA ATS Ltd Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Lang High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest
Product file name commons-lang3 High
Product gradle artifactid commons-lang3 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name lang3 Highest
Product Manifest automatic-module-name org.apache.commons.lang3 Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product Manifest Implementation-Title Apache Commons Lang High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Lang Medium
Product pom artifactid commons-lang3 Highest
Product pom developer email bayard@apache.org Low
Product pom developer email britter@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email djones@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jcarman@apache.org Low
Product pom developer email joerg.schaible@gmx.de Low
Product pom developer email lguibert@apache.org Low
Product pom developer email oheger@apache.org Low
Product pom developer email pbenedict@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email scolebourne@joda.org Low
Product pom developer email stevencaswell@apache.org Low
Product pom developer id bayard Low
Product pom developer id britter Low
Product pom developer id chtompki Low
Product pom developer id djones Low
Product pom developer id dlr Low
Product pom developer id fredrik Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id joehni Low
Product pom developer id lguibert Low
Product pom developer id mbenson Low
Product pom developer id niallp Low
Product pom developer id oheger Low
Product pom developer id pbenedict Low
Product pom developer id rdonkin Low
Product pom developer id scaswell Low
Product pom developer id scolebourne Low
Product pom developer name Benedikt Ritter Low
Product pom developer name Daniel Rall Low
Product pom developer name Duncan Jones Low
Product pom developer name Fredrik Westermarck Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Joerg Schaible Low
Product pom developer name Loic Guibert Low
Product pom developer name Matt Benson Low
Product pom developer name Niall Pemberton Low
Product pom developer name Oliver Heger Low
Product pom developer name Paul Benedict Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Steven Caswell Low
Product pom developer org Carman Consulting, Inc. Low
Product pom developer org CollabNet, Inc. Low
Product pom developer org SITA ATS Ltd Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Lang High
Product pom parent-artifactid commons-parent Medium
Product pom url https://commons.apache.org/proper/commons-lang/ Medium
Version file version 3.16.0 High
Version gradle version 3.16.0 Highest
Version Manifest Bundle-Version 3.16.0 High
Version Manifest Implementation-Version 3.16.0 High
Version pom parent-version 3.16.0 Low
Version pom version 3.16.0 Highest
CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
commons-lang3-3.18.0.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-lang3/3.18.0/fb14946f0e39748a6571de0635acbe44e7885491/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256: 4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Project/Scope: server-start:webapps
commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang3 High
Vendor gradle artifactid commons-lang3 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name lang3 Highest
Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-lang3 Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email britter@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email djones@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jcarman@apache.org Low
Vendor pom developer email joerg.schaible@gmx.de Low
Vendor pom developer email lguibert@apache.org Low
Vendor pom developer email oheger@apache.org Low
Vendor pom developer email pbenedict@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email scolebourne@joda.org Low
Vendor pom developer email stevencaswell@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id britter Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id djones Medium
Vendor pom developer id dlr Medium
Vendor pom developer id fredrik Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id joehni Medium
Vendor pom developer id lguibert Medium
Vendor pom developer id mbenson Medium
Vendor pom developer id niallp Medium
Vendor pom developer id oheger Medium
Vendor pom developer id pbenedict Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id scaswell Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name Benedikt Ritter Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name Duncan Jones Medium
Vendor pom developer name Fredrik Westermarck Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Joerg Schaible Medium
Vendor pom developer name Loic Guibert Medium
Vendor pom developer name Matt Benson Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Oliver Heger Medium
Vendor pom developer name Paul Benedict Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Steven Caswell Medium
Vendor pom developer org Carman Consulting, Inc. Medium
Vendor pom developer org CollabNet, Inc. Medium
Vendor pom developer org SITA ATS Ltd Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Lang High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest
Product file name commons-lang3 High
Product gradle artifactid commons-lang3 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name lang3 Highest
Product Manifest automatic-module-name org.apache.commons.lang3 Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product Manifest Implementation-Title Apache Commons Lang High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Lang Medium
Product pom artifactid commons-lang3 Highest
Product pom developer email bayard@apache.org Low
Product pom developer email britter@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email djones@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jcarman@apache.org Low
Product pom developer email joerg.schaible@gmx.de Low
Product pom developer email lguibert@apache.org Low
Product pom developer email oheger@apache.org Low
Product pom developer email pbenedict@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email scolebourne@joda.org Low
Product pom developer email stevencaswell@apache.org Low
Product pom developer id bayard Low
Product pom developer id britter Low
Product pom developer id chtompki Low
Product pom developer id djones Low
Product pom developer id dlr Low
Product pom developer id fredrik Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id joehni Low
Product pom developer id lguibert Low
Product pom developer id mbenson Low
Product pom developer id niallp Low
Product pom developer id oheger Low
Product pom developer id pbenedict Low
Product pom developer id rdonkin Low
Product pom developer id scaswell Low
Product pom developer id scolebourne Low
Product pom developer name Benedikt Ritter Low
Product pom developer name Daniel Rall Low
Product pom developer name Duncan Jones Low
Product pom developer name Fredrik Westermarck Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Joerg Schaible Low
Product pom developer name Loic Guibert Low
Product pom developer name Matt Benson Low
Product pom developer name Niall Pemberton Low
Product pom developer name Oliver Heger Low
Product pom developer name Paul Benedict Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Steven Caswell Low
Product pom developer org Carman Consulting, Inc. Low
Product pom developer org CollabNet, Inc. Low
Product pom developer org SITA ATS Ltd Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Lang High
Product pom parent-artifactid commons-parent Medium
Product pom url https://commons.apache.org/proper/commons-lang/ Medium
Version file version 3.18.0 High
Version gradle version 3.18.0 Highest
Version Manifest Bundle-Version 3.18.0 High
Version Manifest Implementation-Version 3.18.0 High
Version pom parent-version 3.18.0 Low
Version pom version 3.18.0 Highest
commons-lang3-3.20.0.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17, 21 and 25 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-lang3/3.20.0/65897b3e5731220962e659e001904af3c3cbeba9/commons-lang3-3.20.0.jar
MD5: 4b29562ded527aa074e1d44f8646dac5
SHA1: 65897b3e5731220962e659e001904af3c3cbeba9
SHA256: 69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4
Referenced In Project/Scope: server-start:runtimeClasspath
commons-lang3-3.20.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang3 High
Vendor gradle artifactid commons-lang3 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name lang3 Highest
Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-lang3 Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email britter@apache.org Low
Vendor pom developer email chtompki@apache.org Low
Vendor pom developer email djones@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jcarman@apache.org Low
Vendor pom developer email joerg.schaible@gmx.de Low
Vendor pom developer email lguibert@apache.org Low
Vendor pom developer email oheger@apache.org Low
Vendor pom developer email pbenedict@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email scolebourne@joda.org Low
Vendor pom developer email stevencaswell@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id britter Medium
Vendor pom developer id chtompki Medium
Vendor pom developer id djones Medium
Vendor pom developer id dlr Medium
Vendor pom developer id fredrik Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id joehni Medium
Vendor pom developer id lguibert Medium
Vendor pom developer id mbenson Medium
Vendor pom developer id niallp Medium
Vendor pom developer id oheger Medium
Vendor pom developer id pbenedict Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id scaswell Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name Benedikt Ritter Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name Duncan Jones Medium
Vendor pom developer name Fredrik Westermarck Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Joerg Schaible Medium
Vendor pom developer name Loic Guibert Medium
Vendor pom developer name Matt Benson Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Oliver Heger Medium
Vendor pom developer name Paul Benedict Medium
Vendor pom developer name Rob Tompkins Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Steven Caswell Medium
Vendor pom developer org Carman Consulting, Inc. Medium
Vendor pom developer org CollabNet, Inc. Medium
Vendor pom developer org SITA ATS Ltd Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Lang High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest
Product file name commons-lang3 High
Product gradle artifactid commons-lang3 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name lang3 Highest
Product Manifest automatic-module-name org.apache.commons.lang3 Medium
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product Manifest Implementation-Title Apache Commons Lang High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Lang Medium
Product pom artifactid commons-lang3 Highest
Product pom developer email bayard@apache.org Low
Product pom developer email britter@apache.org Low
Product pom developer email chtompki@apache.org Low
Product pom developer email djones@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jcarman@apache.org Low
Product pom developer email joerg.schaible@gmx.de Low
Product pom developer email lguibert@apache.org Low
Product pom developer email oheger@apache.org Low
Product pom developer email pbenedict@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email scolebourne@joda.org Low
Product pom developer email stevencaswell@apache.org Low
Product pom developer id bayard Low
Product pom developer id britter Low
Product pom developer id chtompki Low
Product pom developer id djones Low
Product pom developer id dlr Low
Product pom developer id fredrik Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id joehni Low
Product pom developer id lguibert Low
Product pom developer id mbenson Low
Product pom developer id niallp Low
Product pom developer id oheger Low
Product pom developer id pbenedict Low
Product pom developer id rdonkin Low
Product pom developer id scaswell Low
Product pom developer id scolebourne Low
Product pom developer name Benedikt Ritter Low
Product pom developer name Daniel Rall Low
Product pom developer name Duncan Jones Low
Product pom developer name Fredrik Westermarck Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Joerg Schaible Low
Product pom developer name Loic Guibert Low
Product pom developer name Matt Benson Low
Product pom developer name Niall Pemberton Low
Product pom developer name Oliver Heger Low
Product pom developer name Paul Benedict Low
Product pom developer name Rob Tompkins Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Steven Caswell Low
Product pom developer org Carman Consulting, Inc. Low
Product pom developer org CollabNet, Inc. Low
Product pom developer org SITA ATS Ltd Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Lang High
Product pom parent-artifactid commons-parent Medium
Product pom url https://commons.apache.org/proper/commons-lang/ Medium
Version file version 3.20.0 High
Version gradle version 3.20.0 Highest
Version Manifest Bundle-Version 3.20.0 High
Version Manifest Implementation-Version 3.20.0 High
Version pom parent-version 3.20.0 Low
Version pom version 3.20.0 Highest
commons-math3-3.6.1.jar
Description:
The Apache Commons Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.commons/commons-math3/3.6.1/e4ba98f1d4b3c80ec46392f25e094a6a2e58fcbf/commons-math3-3.6.1.jar
MD5: 5b730d97e4e6368069de1983937c508e
SHA1: e4ba98f1d4b3c80ec46392f25e094a6a2e58fcbf
SHA256: 1e56d7b058d28b65abd256b8458e3885b674c1d588fa43cd7d1cbb9c7ef2b308
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-math3-3.6.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-math3 High
Vendor gradle artifactid commons-math3 Highest
Vendor gradle groupid org.apache.commons Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name math3 Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.math3 Medium
Vendor Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-math3 Low
Vendor pom developer email achou at apache dot org Low
Vendor pom developer email billbarker at apache dot org Low
Vendor pom developer email brentworden at apache dot org Low
Vendor pom developer email celestin at apache dot org Low
Vendor pom developer email dimpbx at apache dot org Low
Vendor pom developer email erans at apache dot org Low
Vendor pom developer email evanward at apache dot org Low
Vendor pom developer email gregs at apache dot org Low
Vendor pom developer email j3322ptm at yahoo dot de Low
Vendor pom developer email luc at apache dot org Low
Vendor pom developer email mdiggory at apache dot org Low
Vendor pom developer email mikl at apache dot org Low
Vendor pom developer email oertl at apache dot org Low
Vendor pom developer email rdonkin at apache dot org Low
Vendor pom developer email tn at apache dot org Low
Vendor pom developer email tobrien at apache dot org Low
Vendor pom developer id achou Medium
Vendor pom developer id billbarker Medium
Vendor pom developer id brentworden Medium
Vendor pom developer id celestin Medium
Vendor pom developer id dimpbx Medium
Vendor pom developer id erans Medium
Vendor pom developer id evanward Medium
Vendor pom developer id gregs Medium
Vendor pom developer id luc Medium
Vendor pom developer id mdiggory Medium
Vendor pom developer id mikl Medium
Vendor pom developer id oertl Medium
Vendor pom developer id pietsch Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id tn Medium
Vendor pom developer id tobrien Medium
Vendor pom developer name Albert Davidson Chou Medium
Vendor pom developer name Bill Barker Medium
Vendor pom developer name Brent Worden Medium
Vendor pom developer name Dimitri Pourbaix Medium
Vendor pom developer name Evan Ward Medium
Vendor pom developer name Gilles Sadowski Medium
Vendor pom developer name Greg Sterijevski Medium
Vendor pom developer name J. Pietschmann Medium
Vendor pom developer name Luc Maisonobe Medium
Vendor pom developer name Mark Diggory Medium
Vendor pom developer name Mikkel Meyer Andersen Medium
Vendor pom developer name Otmar Ertl Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Sébastien Brisard Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer name Tim O'Brien Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Math High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url http://commons.apache.org/proper/commons-math/ Highest
Product file name commons-math3 High
Product gradle artifactid commons-math3 Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name math3 Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low
Product Manifest Bundle-Name Apache Commons Math Medium
Product Manifest bundle-symbolicname org.apache.commons.math3 Medium
Product Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low
Product Manifest Implementation-Title Apache Commons Math High
Product Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low
Product Manifest specification-title Apache Commons Math Medium
Product pom artifactid commons-math3 Highest
Product pom developer email achou at apache dot org Low
Product pom developer email billbarker at apache dot org Low
Product pom developer email brentworden at apache dot org Low
Product pom developer email celestin at apache dot org Low
Product pom developer email dimpbx at apache dot org Low
Product pom developer email erans at apache dot org Low
Product pom developer email evanward at apache dot org Low
Product pom developer email gregs at apache dot org Low
Product pom developer email j3322ptm at yahoo dot de Low
Product pom developer email luc at apache dot org Low
Product pom developer email mdiggory at apache dot org Low
Product pom developer email mikl at apache dot org Low
Product pom developer email oertl at apache dot org Low
Product pom developer email rdonkin at apache dot org Low
Product pom developer email tn at apache dot org Low
Product pom developer email tobrien at apache dot org Low
Product pom developer id achou Low
Product pom developer id billbarker Low
Product pom developer id brentworden Low
Product pom developer id celestin Low
Product pom developer id dimpbx Low
Product pom developer id erans Low
Product pom developer id evanward Low
Product pom developer id gregs Low
Product pom developer id luc Low
Product pom developer id mdiggory Low
Product pom developer id mikl Low
Product pom developer id oertl Low
Product pom developer id pietsch Low
Product pom developer id rdonkin Low
Product pom developer id tn Low
Product pom developer id tobrien Low
Product pom developer name Albert Davidson Chou Low
Product pom developer name Bill Barker Low
Product pom developer name Brent Worden Low
Product pom developer name Dimitri Pourbaix Low
Product pom developer name Evan Ward Low
Product pom developer name Gilles Sadowski Low
Product pom developer name Greg Sterijevski Low
Product pom developer name J. Pietschmann Low
Product pom developer name Luc Maisonobe Low
Product pom developer name Mark Diggory Low
Product pom developer name Mikkel Meyer Andersen Low
Product pom developer name Otmar Ertl Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Sébastien Brisard Low
Product pom developer name Thomas Neidhart Low
Product pom developer name Tim O'Brien Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Math High
Product pom parent-artifactid commons-parent Medium
Product pom url http://commons.apache.org/proper/commons-math/ Medium
Version file version 3.6.1 High
Version gradle version 3.6.1 Highest
Version Manifest Bundle-Version 3.6.1 High
Version Manifest Implementation-Version 3.6.1 High
Version pom parent-version 3.6.1 Low
Version pom version 3.6.1 Highest
pkg:maven/org.apache.commons/commons-math3@3.6.1
(Confidence :High)
commons-net-3.5.jar
Description:
Apache Commons Net library contains a collection of network utilities and protocol implementations.
Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/commons-net/commons-net/3.5/342fc284019f590e1308056990fdb24a08f06318/commons-net-3.5.jar
MD5: 67cdd14323977fa71a21d9603b3d59b6
SHA1: 342fc284019f590e1308056990fdb24a08f06318
SHA256: c25b0da668b3c5649f002d504def22d1b4cb30d206f05428d2fe168fa1a901c2
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
commons-net-3.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name commons-net High
Vendor gradle artifactid commons-net Highest
Vendor gradle groupid commons-net Highest
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name echo Highest
Vendor jar package name finger Highest
Vendor jar package name ftp Highest
Vendor jar package name net Highest
Vendor jar package name nntp Highest
Vendor jar package name pop3 Highest
Vendor jar package name smtp Highest
Vendor jar package name telnet Highest
Vendor jar package name whois Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-net/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.net Medium
Vendor Manifest implementation-build tags/NET_3_5_RC3@r1741905; 2016-05-01 22:35:55+0000 Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-net/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-net Low
Vendor pom developer email bruno.davanzo@hp.com Low
Vendor pom developer email dfs@apache.org Low
Vendor pom developer email Jeff.Brekke@qg.com Low
Vendor pom developer email rwinston@apache.org Low
Vendor pom developer email rwinston@checkfree.com Low
Vendor pom developer email scohen@apache.org Low
Vendor pom developer id brekke Medium
Vendor pom developer id brudav Medium
Vendor pom developer id dfs Medium
Vendor pom developer id rwinston Medium
Vendor pom developer id scohen Medium
Vendor pom developer name Bruno D'Avanzo Medium
Vendor pom developer name Daniel F. Savarese Medium
Vendor pom developer name Jeffrey D. Brekke Medium
Vendor pom developer name Rory Winston Medium
Vendor pom developer name Steve Cohen Medium
Vendor pom developer org
<a href="http://www.savarese.com/">Savarese Software Research</a>
Medium
Vendor pom developer org Hewlett-Packard Medium
Vendor pom developer org javactivity.org Medium
Vendor pom developer org Quad/Graphics, Inc. Medium
Vendor pom groupid commons-net Highest
Vendor pom name Apache Commons Net High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url http://commons.apache.org/proper/commons-net/ Highest
Product file name commons-net High
Product gradle artifactid commons-net Highest
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name echo Highest
Product jar package name finger Highest
Product jar package name ftp Highest
Product jar package name net Highest
Product jar package name nntp Highest
Product jar package name pop3 Highest
Product jar package name smtp Highest
Product jar package name telnet Highest
Product jar package name whois Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-net/ Low
Product Manifest Bundle-Name Apache Commons Net Medium
Product Manifest bundle-symbolicname org.apache.commons.net Medium
Product Manifest implementation-build tags/NET_3_5_RC3@r1741905; 2016-05-01 22:35:55+0000 Low
Product Manifest Implementation-Title Apache Commons Net High
Product Manifest implementation-url http://commons.apache.org/proper/commons-net/ Low
Product Manifest specification-title Apache Commons Net Medium
Product pom artifactid commons-net Highest
Product pom developer email bruno.davanzo@hp.com Low
Product pom developer email dfs@apache.org Low
Product pom developer email Jeff.Brekke@qg.com Low
Product pom developer email rwinston@apache.org Low
Product pom developer email rwinston@checkfree.com Low
Product pom developer email scohen@apache.org Low
Product pom developer id brekke Low
Product pom developer id brudav Low
Product pom developer id dfs Low
Product pom developer id rwinston Low
Product pom developer id scohen Low
Product pom developer name Bruno D'Avanzo Low
Product pom developer name Daniel F. Savarese Low
Product pom developer name Jeffrey D. Brekke Low
Product pom developer name Rory Winston Low
Product pom developer name Steve Cohen Low
Product pom developer org
<a href="http://www.savarese.com/">Savarese Software Research</a>
Low
Product pom developer org Hewlett-Packard Low
Product pom developer org javactivity.org Low
Product pom developer org Quad/Graphics, Inc. Low
Product pom groupid commons-net Highest
Product pom name Apache Commons Net High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url http://commons.apache.org/proper/commons-net/ Medium
Version file version 3.5 High
Version gradle version 3.5 Highest
Version Manifest Implementation-Version 3.5 High
Version pom parent-version 3.5 Low
Version pom version 3.5 Highest
CVE-2021-37533 suppress
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A
References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security@apache.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
security@apache.org - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY
security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY
security@apache.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions:
conscrypt-openjdk-uber-2.5.2.jar
Description:
Conscrypt: OpenJdk UberJAR
License:
Apache 2: https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.conscrypt/conscrypt-openjdk-uber/2.5.2/d858f142ea189c62771c505a6548d8606ac098fe/conscrypt-openjdk-uber-2.5.2.jar
MD5: 34c8ec40831d77372b2bea95139783b0
SHA1: d858f142ea189c62771c505a6548d8606ac098fe
SHA256: eaf537d98e033d0f0451cd1b8cc74e02d7b55ec882da63c88060d806ba89c348
Referenced In Project/Scope: server-start:runtimeClasspath
conscrypt-openjdk-uber-2.5.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name conscrypt-openjdk-uber High
Vendor gradle artifactid conscrypt-openjdk-uber Highest
Vendor gradle groupid org.conscrypt Highest
Vendor jar package name conscrypt Highest
Vendor jar package name conscrypt Low
Vendor Manifest automatic-module-name org.conscrypt Medium
Vendor Manifest bundle-symbolicname org.conscrypt Medium
Vendor Manifest source-compatibility 1.7 Low
Vendor Manifest target-compatibility 1.7 Low
Vendor pom artifactid conscrypt-openjdk-uber Low
Vendor pom developer email conscrypt@googlegroups.com Low
Vendor pom developer id conscrypt Medium
Vendor pom developer name Conscrypt Contributors Medium
Vendor pom developer org Google, Inc. Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid org.conscrypt Highest
Vendor pom name org.conscrypt:conscrypt-openjdk-uber High
Vendor pom url https://conscrypt.org/ Highest
Product file name conscrypt-openjdk-uber High
Product gradle artifactid conscrypt-openjdk-uber Highest
Product jar package name conscrypt Highest
Product Manifest automatic-module-name org.conscrypt Medium
Product Manifest Bundle-Name org.conscrypt Medium
Product Manifest bundle-symbolicname org.conscrypt Medium
Product Manifest Implementation-Title conscrypt-openjdk-uber High
Product Manifest source-compatibility 1.7 Low
Product Manifest target-compatibility 1.7 Low
Product pom artifactid conscrypt-openjdk-uber Highest
Product pom developer email conscrypt@googlegroups.com Low
Product pom developer id conscrypt Low
Product pom developer name Conscrypt Contributors Low
Product pom developer org Google, Inc. Low
Product pom developer org URL https://www.google.com Low
Product pom groupid org.conscrypt Highest
Product pom name org.conscrypt:conscrypt-openjdk-uber High
Product pom url https://conscrypt.org/ Medium
Version file version 2.5.2 High
Version gradle version 2.5.2 Highest
Version Manifest Bundle-Version 2.5.2 High
Version Manifest Implementation-Version 2.5.2 High
Version pom version 2.5.2 Highest
pkg:maven/org.conscrypt/conscrypt-openjdk-uber@2.5.2
(Confidence :High)
conscrypt-openjdk-uber-2.5.2.jar: conscrypt_openjdk_jni-windows-x86.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.conscrypt/conscrypt-openjdk-uber/2.5.2/d858f142ea189c62771c505a6548d8606ac098fe/conscrypt-openjdk-uber-2.5.2.jar/META-INF/native/conscrypt_openjdk_jni-windows-x86.dll
MD5: 1c95af66b90409a88bbd9641c1d67adb
SHA1: cf9c2e9cda771c1451411b00198c289f2ae84bcf
SHA256: 6d050d27ce99019efd6764e8b85b3a33845e85a67809a03343dd0304e83e8472
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name conscrypt_openjdk_jni-windows-x86 High
Product file name conscrypt_openjdk_jni-windows-x86 High
Version file name conscrypt_openjdk_jni-windows-x86 Medium
Version file version 86 Medium
conscrypt-openjdk-uber-2.5.2.jar: conscrypt_openjdk_jni-windows-x86_64.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.conscrypt/conscrypt-openjdk-uber/2.5.2/d858f142ea189c62771c505a6548d8606ac098fe/conscrypt-openjdk-uber-2.5.2.jar/META-INF/native/conscrypt_openjdk_jni-windows-x86_64.dll
MD5: bd8a94b5e92cfeb8653cca1b9f54a2d2
SHA1: 53d42334c8c56bf9007df6898604c67b033171ab
SHA256: a72c7d3d5f0f5afb8b048b3db9ba1a167120ff5094a0612bfa5ed96b27667910
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name conscrypt_openjdk_jni-windows-x86_64 High
Product file name conscrypt_openjdk_jni-windows-x86_64 High
converter-gson-3.0.0.jar
Description:
A Retrofit Converter which uses Gson for serialization.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.squareup.retrofit2/converter-gson/3.0.0/f267e39336e822e2abb835818606986a96b4d5aa/converter-gson-3.0.0.jar
MD5: 82ad40143911013d2720aa463d40f3f5
SHA1: f267e39336e822e2abb835818606986a96b4d5aa
SHA256: ada634bb1203903755d21ff3de9ecccb139061fce05aa6182345d4c97c369e07
Referenced In Project/Scope: server-start:runtimeClasspath
converter-gson-3.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name converter-gson High
Vendor gradle artifactid converter-gson Highest
Vendor gradle groupid com.squareup.retrofit2 Highest
Vendor jar package name converter Highest
Vendor jar package name converter Low
Vendor jar package name gson Highest
Vendor jar package name gson Low
Vendor jar package name retrofit2 Highest
Vendor jar package name retrofit2 Low
Vendor Manifest automatic-module-name retrofit2.converter.gson Medium
Vendor pom artifactid converter-gson Low
Vendor pom developer id square Medium
Vendor pom developer name Square, Inc. Medium
Vendor pom groupid com.squareup.retrofit2 Highest
Vendor pom name Converter: Gson High
Vendor pom url square/retrofit Highest
Product file name converter-gson High
Product gradle artifactid converter-gson Highest
Product jar package name converter Highest
Product jar package name converter Low
Product jar package name gson Highest
Product jar package name gson Low
Product jar package name retrofit2 Highest
Product Manifest automatic-module-name retrofit2.converter.gson Medium
Product pom artifactid converter-gson Highest
Product pom developer id square Low
Product pom developer name Square, Inc. Low
Product pom groupid com.squareup.retrofit2 Highest
Product pom name Converter: Gson High
Product pom url square/retrofit High
Version file version 3.0.0 High
Version gradle version 3.0.0 Highest
Version pom version 3.0.0 Highest
pkg:maven/com.squareup.retrofit2/converter-gson@3.0.0
(Confidence :High)
corba-api-5.0.0.jar
Description:
JOnAS : Java Open Application Server
License:
http://www.gnu.org/copyleft/lesser.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ow2.jonas.osgi/corba-api/5.0.0/d932a5864db93ff61f7dbf230f13f7220dbc97db/corba-api-5.0.0.jar
MD5: b7e245207bf4fc407a41a84718d80b56
SHA1: d932a5864db93ff61f7dbf230f13f7220dbc97db
SHA256: da070a03a717673d4e4a4dd0c9d612d33b11ab0ea8ffa5db87d481c0f632edc0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
corba-api-5.0.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name corba-api High
Vendor gradle artifactid corba-api Highest
Vendor gradle groupid org.ow2.jonas.osgi Highest
Vendor jar package name corba Highest
Vendor Manifest bundle-docurl http://www.ow2.org Low
Vendor Manifest bundle-symbolicname org.ow2.jonas.osgi.corba-api Medium
Vendor pom artifactid corba-api Low
Vendor pom groupid org.ow2.jonas.osgi Highest
Vendor pom name JOnAS :: Libraries :: Externals :: CORBA API High
Vendor pom parent-artifactid jonas-externals Low
Product file name corba-api High
Product gradle artifactid corba-api Highest
Product jar package name corba Highest
Product Manifest bundle-docurl http://www.ow2.org Low
Product Manifest Bundle-Name JOnAS :: Libraries :: Externals :: CORBA API Medium
Product Manifest bundle-symbolicname org.ow2.jonas.osgi.corba-api Medium
Product pom artifactid corba-api Highest
Product pom groupid org.ow2.jonas.osgi Highest
Product pom name JOnAS :: Libraries :: Externals :: CORBA API High
Product pom parent-artifactid jonas-externals Medium
Version file version 5.0.0 High
Version gradle version 5.0.0 Highest
Version Manifest Bundle-Version 5.0.0 High
Version pom version 5.0.0 Highest
pkg:maven/org.ow2.jonas.osgi/corba-api@5.0.0
(Confidence :High)
core-1.58.0.0.jar
Description:
Spongy Castle is a package-rename (org.bouncycastle.* to org.spongycastle.*) of Bouncy Castle
intended for the Android platform. Android unfortunately ships with a stripped-down version of
Bouncy Castle, which prevents easy upgrades - Spongy Castle overcomes this and provides a full,
up-to-date version of the Bouncy Castle cryptographic libs.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.madgag.spongycastle/core/1.58.0.0/e08789f8f1e74f155db8b69c3575b5cb213c156c/core-1.58.0.0.jar
MD5: 1a51c2d5dd9f788e14bd9358718994ea
SHA1: e08789f8f1e74f155db8b69c3575b5cb213c156c
SHA256: 199617dd5698c5a9312b898c0a4cec7ce9dd8649d07f65d91629f58229d72728
Referenced In Project/Scope: server-start:runtimeClasspath
core-1.58.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name core High
Vendor gradle artifactid core Highest
Vendor gradle groupid com.madgag.spongycastle Highest
Vendor jar package name spongycastle Low
Vendor pom artifactid core Low
Vendor pom developer id rtyley Medium
Vendor pom developer name Roberto Tyley Medium
Vendor pom groupid com.madgag.spongycastle Highest
Vendor pom name Spongy Castle High
Vendor pom url http://rtyley.github.io/spongycastle/ Highest
Product file name core High
Product gradle artifactid core Highest
Product pom artifactid core Highest
Product pom developer id rtyley Low
Product pom developer name Roberto Tyley Low
Product pom groupid com.madgag.spongycastle Highest
Product pom name Spongy Castle High
Product pom url http://rtyley.github.io/spongycastle/ Medium
Version file version 1.58.0.0 High
Version gradle version 1.58.0.0 Highest
Version pom version 1.58.0.0 Highest
pkg:maven/com.madgag.spongycastle/core@1.58.0.0
(Confidence :High)
crt-core-2.26.30.jar
Description:
The AWS SDK for Java - AWS CRT Core holds common types that are built on the AWS Common Runtime
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/crt-core/2.26.30/f1cc08e3ec48f58539399fb275a03864949aea92/crt-core-2.26.30.jar
MD5: 3c069e2fe3caf12fddb16ef9b8464a18
SHA1: f1cc08e3ec48f58539399fb275a03864949aea92
SHA256: 4870b200c6057a0d5d6f46a9a7702ec4dc85cac088a8e7e773230e54137ade1b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
crt-core-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name crt-core High
Vendor gradle artifactid crt-core Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name crtcore Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.crtcore Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid crt-core Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: AWS CRT Core High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name crt-core High
Product gradle artifactid crt-core Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name crtcore Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.crtcore Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid crt-core Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: AWS CRT Core High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
cryptacular-1.2.7.jar
Description:
The spectacular complement to the Bouncy Castle crypto API for Java.
License:
Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
GNU Lesser General Public License: https://www.gnu.org/licenses/lgpl-3.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.cryptacular/cryptacular/1.2.7/8e2849cd0cc8856899c1190ec8bc9f261fb215e/cryptacular-1.2.7.jar
MD5: 9171ea0e9f71e98984def0861f5a9a7b
SHA1: 08e2849cd0cc8856899c1190ec8bc9f261fb215e
SHA256: fd5e655cc48c2c4568d8a40770dc07442316d61bcc1c24f199b84deee7e4f727
Referenced In Project/Scope: server-start:webapps
cryptacular-1.2.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cryptacular High
Vendor gradle artifactid cryptacular Highest
Vendor gradle groupid org.cryptacular Highest
Vendor hint analyzer vendor Virginia Tech Highest
Vendor hint analyzer vendor vt Highest
Vendor jar package name cryptacular Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-symbolicname org.cryptacular Medium
Vendor pom artifactid cryptacular Low
Vendor pom developer email dfisher@vt.edu Low
Vendor pom developer email serac@vt.edu Low
Vendor pom developer id dfisher Medium
Vendor pom developer id serac Medium
Vendor pom developer name Daniel Fisher Medium
Vendor pom developer name Marvin S. Addison Medium
Vendor pom developer org Virginia Tech Medium
Vendor pom developer org URL https://www.vt.edu Medium
Vendor pom groupid org.cryptacular Highest
Vendor pom name Cryptacular Library High
Vendor pom url https://www.cryptacular.org Highest
Product file name cryptacular High
Product gradle artifactid cryptacular Highest
Product jar package name cryptacular Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Bundle-Name Cryptacular Library Medium
Product Manifest bundle-symbolicname org.cryptacular Medium
Product pom artifactid cryptacular Highest
Product pom developer email dfisher@vt.edu Low
Product pom developer email serac@vt.edu Low
Product pom developer id dfisher Low
Product pom developer id serac Low
Product pom developer name Daniel Fisher Low
Product pom developer name Marvin S. Addison Low
Product pom developer org Virginia Tech Low
Product pom developer org URL https://www.vt.edu Low
Product pom groupid org.cryptacular Highest
Product pom name Cryptacular Library High
Product pom url https://www.cryptacular.org Medium
Version file version 1.2.7 High
Version gradle version 1.2.7 Highest
Version Manifest Bundle-Version 1.2.7 High
Version pom version 1.2.7 Highest
curvesapi-1.06.jar
Description:
Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS.
License:
BSD License: http://opensource.org/licenses/BSD-3-Clause
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.github.virtuald/curvesapi/1.06/159dd2e8956459a4eb0a9a6ecda9004d8d289708/curvesapi-1.06.jar
MD5: 049221bdb7f8d8a2065c02000e854ed4
SHA1: 159dd2e8956459a4eb0a9a6ecda9004d8d289708
SHA256: 38bb45c99e6153260c19b97b99b6a7370a067de63344de6d1ea11922acaed86b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
curvesapi-1.06.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name curvesapi High
Vendor gradle artifactid curvesapi Highest
Vendor gradle groupid com.github.virtuald Highest
Vendor jar package name graphbuilder Low
Vendor jar package name math Low
Vendor pom artifactid curvesapi Low
Vendor pom developer id stormdollar Medium
Vendor pom developer id virtuald Medium
Vendor pom developer name Dustin Spicuzza Medium
Vendor pom developer name stormdollar Medium
Vendor pom groupid com.github.virtuald Highest
Vendor pom name curvesapi High
Vendor pom url virtuald/curvesapi Highest
Product file name curvesapi High
Product gradle artifactid curvesapi Highest
Product jar package name math Low
Product pom artifactid curvesapi Highest
Product pom developer id stormdollar Low
Product pom developer id virtuald Low
Product pom developer name Dustin Spicuzza Low
Product pom developer name stormdollar Low
Product pom groupid com.github.virtuald Highest
Product pom name curvesapi High
Product pom url virtuald/curvesapi High
Version file version 1.06 High
Version gradle version 1.06 Highest
Version pom version 1.06 Highest
pkg:maven/com.github.virtuald/curvesapi@1.06
(Confidence :High)
cxf-core-4.1.3.jar
Description:
Apache CXF Core
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-core/4.1.3/9a499cf61c9a6e1bc533bdfef26b202e91187ef/cxf-core-4.1.3.jar
MD5: 5538cfb8358d6043d7b8c69badfc7939
SHA1: 09a499cf61c9a6e1bc533bdfef26b202e91187ef
SHA256: aa4699bd27b916285a8c07e444ab6cb462e094aa53cf8646acadef79fcdb7165
Referenced In Project/Scope: server-start:webapps
cxf-core-4.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-core High
Vendor gradle artifactid cxf-core Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor Manifest automatic-module-name org.apache.cxf.core Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-core Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Core High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-core High
Product gradle artifactid cxf-core Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name http Highest
Product Manifest automatic-module-name org.apache.cxf.core Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Core Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-core Medium
Product pom artifactid cxf-core Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Core High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-bindings-soap-4.1.3.jar
Description:
Apache CXF Runtime SOAP Binding
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-bindings-soap/4.1.3/dbdbbe48c8e7776fdbce9f2dede4ebb8c2a5af7d/cxf-rt-bindings-soap-4.1.3.jar
MD5: 9f488dbcbe3a463bc2448ebe3529d1cd
SHA1: dbdbbe48c8e7776fdbce9f2dede4ebb8c2a5af7d
SHA256: c67ad59e3e59507f5dde2e15fc7ab70ce0bd61eddb85436de137067c2dde87f8
Referenced In Project/Scope: server-start:webapps
cxf-rt-bindings-soap-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-bindings-soap High
Vendor gradle artifactid cxf-rt-bindings-soap Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name binding Highest
Vendor jar package name cxf Highest
Vendor jar package name soap Highest
Vendor Manifest automatic-module-name org.apache.cxf.binding.soap Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-bindings-soap Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-bindings-soap Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime SOAP Binding High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-bindings-soap High
Product gradle artifactid cxf-rt-bindings-soap Highest
Product jar package name apache Highest
Product jar package name binding Highest
Product jar package name cxf Highest
Product jar package name soap Highest
Product Manifest automatic-module-name org.apache.cxf.binding.soap Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime SOAP Binding Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-bindings-soap Medium
Product pom artifactid cxf-rt-bindings-soap Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime SOAP Binding High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-bindings-xml-4.1.3.jar
Description:
Apache CXF Runtime XML Binding
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-bindings-xml/4.1.3/4489f6c0f782bfccce768d57ea2e5bcbc485ee33/cxf-rt-bindings-xml-4.1.3.jar
MD5: 47ffaa294fe17675d75ca3c42c311cdd
SHA1: 4489f6c0f782bfccce768d57ea2e5bcbc485ee33
SHA256: 981cc1d4149370d8dce61ff7bcfee1e5e81113e9716948f257cff52715b4c2f8
Referenced In Project/Scope: server-start:webapps
cxf-rt-bindings-xml-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-bindings-xml High
Vendor gradle artifactid cxf-rt-bindings-xml Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name binding Highest
Vendor jar package name bindings Highest
Vendor jar package name cxf Highest
Vendor jar package name xml Highest
Vendor Manifest automatic-module-name org.apache.cxf.binding.xml Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-bindings-xml Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-bindings-xml Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime XML Binding High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-bindings-xml High
Product gradle artifactid cxf-rt-bindings-xml Highest
Product jar package name apache Highest
Product jar package name binding Highest
Product jar package name bindings Highest
Product jar package name cxf Highest
Product jar package name xml Highest
Product Manifest automatic-module-name org.apache.cxf.binding.xml Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime XML Binding Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-bindings-xml Medium
Product pom artifactid cxf-rt-bindings-xml Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime XML Binding High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-databinding-jaxb-4.1.3.jar
Description:
Apache CXF Runtime JAXB DataBinding
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-databinding-jaxb/4.1.3/3d884d64f6a942be085aeac7a172ee0141e6b840/cxf-rt-databinding-jaxb-4.1.3.jar
MD5: dbe02efaa5b4cd3b1ce77b1dd6e23ee6
SHA1: 3d884d64f6a942be085aeac7a172ee0141e6b840
SHA256: 0557e40d5a0a218124b536320de7f3e27b817088bfb6757d122a406ce6fa5086
Referenced In Project/Scope: server-start:webapps
cxf-rt-databinding-jaxb-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-databinding-jaxb High
Vendor gradle artifactid cxf-rt-databinding-jaxb Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name jaxb Highest
Vendor Manifest automatic-module-name org.apache.cxf.databinding.jaxb Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-databinding-jaxb Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-databinding-jaxb Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime JAXB DataBinding High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-databinding-jaxb High
Product gradle artifactid cxf-rt-databinding-jaxb Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name jaxb Highest
Product Manifest automatic-module-name org.apache.cxf.databinding.jaxb Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime JAXB DataBinding Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-databinding-jaxb Medium
Product pom artifactid cxf-rt-databinding-jaxb Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime JAXB DataBinding High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-frontend-jaxrs-4.1.3.jar
Description:
Apache CXF Runtime JAX-RS Frontend
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-frontend-jaxrs/4.1.3/889baca6714d0e9fa257a4a712bf3861a18f277c/cxf-rt-frontend-jaxrs-4.1.3.jar
MD5: e0a41fe98c31428df98f13442a315140
SHA1: 889baca6714d0e9fa257a4a712bf3861a18f277c
SHA256: 32c40f7efd104393f233522343690e6f432dfc59b83d706ad3ee83dfefd10224
Referenced In Project/Scope: server-start:webapps
cxf-rt-frontend-jaxrs-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-frontend-jaxrs High
Vendor gradle artifactid cxf-rt-frontend-jaxrs Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name jaxrs Highest
Vendor Manifest automatic-module-name org.apache.cxf.frontend.jaxrs Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-jaxrs Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-frontend-jaxrs Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime JAX-RS Frontend High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-frontend-jaxrs High
Product gradle artifactid cxf-rt-frontend-jaxrs Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name jaxrs Highest
Product Manifest automatic-module-name org.apache.cxf.frontend.jaxrs Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime JAX-RS Frontend Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-jaxrs Medium
Product pom artifactid cxf-rt-frontend-jaxrs Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime JAX-RS Frontend High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-frontend-jaxws-4.1.3.jar
Description:
Apache CXF Runtime JAX-WS Frontend
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-frontend-jaxws/4.1.3/92962bd9181a8a40e21b14bf87a2d96f0e920d9f/cxf-rt-frontend-jaxws-4.1.3.jar
MD5: 9ceaa9feadb7ce1bc5f560b0d12a4fd4
SHA1: 92962bd9181a8a40e21b14bf87a2d96f0e920d9f
SHA256: 6c0e493d72773e40d2edd02d0819c3bb6dc4f7f3aa6558f1979ea02dfe04ab37
Referenced In Project/Scope: server-start:webapps
cxf-rt-frontend-jaxws-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-frontend-jaxws High
Vendor gradle artifactid cxf-rt-frontend-jaxws Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name jaxws Highest
Vendor Manifest automatic-module-name org.apache.cxf.frontend.jaxws Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-jaxws Medium
Vendor Manifest export-service org.apache.aries.blueprint.NamespaceHandler;osgi.service.blueprint.namespace="http://cxf.apache.org/blueprint/jaxws" Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-frontend-jaxws Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime JAX-WS Frontend High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-frontend-jaxws High
Product gradle artifactid cxf-rt-frontend-jaxws Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name jaxws Highest
Product Manifest automatic-module-name org.apache.cxf.frontend.jaxws Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime JAX-WS Frontend Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-jaxws Medium
Product Manifest export-service org.apache.aries.blueprint.NamespaceHandler;osgi.service.blueprint.namespace="http://cxf.apache.org/blueprint/jaxws" Low
Product pom artifactid cxf-rt-frontend-jaxws Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime JAX-WS Frontend High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-frontend-simple-4.1.3.jar
Description:
Apache CXF Runtime Simple Frontend
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-frontend-simple/4.1.3/973b57d25f61b5c6ee6e99479889f24376931008/cxf-rt-frontend-simple-4.1.3.jar
MD5: f00eb07dd3f5931fd950b94dec6a1587
SHA1: 973b57d25f61b5c6ee6e99479889f24376931008
SHA256: 4fbfaabafdf0bd722b93a5811b250163335a79ce4475bbe8aa4a835470711b09
Referenced In Project/Scope: server-start:webapps
cxf-rt-frontend-simple-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-frontend-simple High
Vendor gradle artifactid cxf-rt-frontend-simple Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name frontend Highest
Vendor jar package name simple Highest
Vendor Manifest automatic-module-name org.apache.cxf.frontend.simple Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-simple Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-frontend-simple Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime Simple Frontend High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-frontend-simple High
Product gradle artifactid cxf-rt-frontend-simple Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name frontend Highest
Product jar package name simple Highest
Product Manifest automatic-module-name org.apache.cxf.frontend.simple Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime Simple Frontend Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-frontend-simple Medium
Product pom artifactid cxf-rt-frontend-simple Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime Simple Frontend High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-rs-service-description-common-openapi-4.1.3.jar
Description:
Apache CXF JAX-RS Service Description OpenAPI/Swagger Common
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-rs-service-description-common-openapi/4.1.3/a79b27b32a4e33975f576a6fd420897e5204ad68/cxf-rt-rs-service-description-common-openapi-4.1.3.jar
MD5: 00b1ef82b9a4c579e21d5d442b6b94a7
SHA1: a79b27b32a4e33975f576a6fd420897e5204ad68
SHA256: c7ad82c11baea78f7d2e28b576ac482c35751a32693adfbf950e605876f485cb
Referenced In Project/Scope: server-start:webapps
cxf-rt-rs-service-description-common-openapi-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-rs-service-description-common-openapi High
Vendor gradle artifactid cxf-rt-rs-service-description-common-openapi Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name common Highest
Vendor jar package name cxf Highest
Vendor Manifest automatic-module-name org.apache.cxf.rs.common.openapi Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-common-openapi Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-rs-service-description-common-openapi Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF JAX-RS Service Description OpenAPI/Swagger Common High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-rs-service-description-common-openapi High
Product gradle artifactid cxf-rt-rs-service-description-common-openapi Highest
Product jar package name apache Highest
Product jar package name common Highest
Product jar package name cxf Highest
Product Manifest automatic-module-name org.apache.cxf.rs.common.openapi Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF JAX-RS Service Description OpenAPI/Swagger Common Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-common-openapi Medium
Product pom artifactid cxf-rt-rs-service-description-common-openapi Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF JAX-RS Service Description OpenAPI/Swagger Common High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-rs-service-description-openapi-v3-4.1.3.jar
Description:
Apache CXF JAX-RS Service Description OpenAPI v3
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-rs-service-description-openapi-v3/4.1.3/635a614ebb7ae827e1596ef1ebde12556757c0df/cxf-rt-rs-service-description-openapi-v3-4.1.3.jar
MD5: 2eb05cbfb66cafe7abc21f81a21e0d87
SHA1: 635a614ebb7ae827e1596ef1ebde12556757c0df
SHA256: e7ae62718604176bc0504cc3d1e820533ecaba1683870f8d50fc0f0beb604c1c
Referenced In Project/Scope: server-start:webapps
cxf-rt-rs-service-description-openapi-v3-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-rs-service-description-openapi-v3 High
Vendor gradle artifactid cxf-rt-rs-service-description-openapi-v3 Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name openapi Highest
Vendor Manifest automatic-module-name org.apache.cxf.rs.openapi.v3 Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-openapi-v3 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-rs-service-description-openapi-v3 Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF JAX-RS Service Description OpenAPI v3 High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-rs-service-description-openapi-v3 High
Product gradle artifactid cxf-rt-rs-service-description-openapi-v3 Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name openapi Highest
Product Manifest automatic-module-name org.apache.cxf.rs.openapi.v3 Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF JAX-RS Service Description OpenAPI v3 Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-openapi-v3 Medium
Product pom artifactid cxf-rt-rs-service-description-openapi-v3 Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF JAX-RS Service Description OpenAPI v3 High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-rs-service-description-swagger-ui-4.1.3.jar
Description:
Apache CXF JAX-RS Service Description Swagger UI integration
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-rs-service-description-swagger-ui/4.1.3/c51ff4d1d56bcd916be5e776712fa6d46ae49c27/cxf-rt-rs-service-description-swagger-ui-4.1.3.jar
MD5: fc57e079685b355137edf9435ae5ccfd
SHA1: c51ff4d1d56bcd916be5e776712fa6d46ae49c27
SHA256: 2cd6003bd4c29a569f0a9d350cd2815a6d27a99dba7add705d684206622aea15
Referenced In Project/Scope: server-start:webapps
cxf-rt-rs-service-description-swagger-ui-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-rs-service-description-swagger-ui High
Vendor gradle artifactid cxf-rt-rs-service-description-swagger-ui Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name swagger Highest
Vendor Manifest automatic-module-name org.apache.cxf.rs.swagger.ui Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-swagger-ui Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-rs-service-description-swagger-ui Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF JAX-RS Service Description Swagger UI integration High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-rs-service-description-swagger-ui High
Product gradle artifactid cxf-rt-rs-service-description-swagger-ui Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name swagger Highest
Product Manifest automatic-module-name org.apache.cxf.rs.swagger.ui Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF JAX-RS Service Description Swagger UI integration Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-rs-service-description-swagger-ui Medium
Product pom artifactid cxf-rt-rs-service-description-swagger-ui Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF JAX-RS Service Description Swagger UI integration High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-security-4.1.3.jar
Description:
Apache CXF Runtime Security functionality
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-security/4.1.3/877eae8797230986b3ea84472ac2690dfc9e85f6/cxf-rt-security-4.1.3.jar
MD5: be086b7699952f09379a2c0ec9fdd7c1
SHA1: 877eae8797230986b3ea84472ac2690dfc9e85f6
SHA256: 818b5f33c82828c12bba0bf63bcb2abcb7c75d67f9528a86c3d0ac7bb72ebfed
Referenced In Project/Scope: server-start:webapps
cxf-rt-security-4.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-security High
Vendor gradle artifactid cxf-rt-security Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name rt Highest
Vendor jar package name security Highest
Vendor Manifest automatic-module-name org.apache.cxf.security Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-security Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-security Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime Security functionality High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-security High
Product gradle artifactid cxf-rt-security Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name rt Highest
Product jar package name security Highest
Product Manifest automatic-module-name org.apache.cxf.security Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime Security functionality Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-security Medium
Product pom artifactid cxf-rt-security Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime Security functionality High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-security-saml-4.1.3.jar
Description:
Apache CXF Runtime SAML Security functionality
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-security-saml/4.1.3/ffd8c1fe3bb1c7fec7dc271171168ff86e1f6c54/cxf-rt-security-saml-4.1.3.jar
MD5: d1e6b425bf13087d3ea6443762a73e69
SHA1: ffd8c1fe3bb1c7fec7dc271171168ff86e1f6c54
SHA256: dee72a10058d0618002b85c39f64832ae9fa10a4530894f4069d0f260b6909d4
Referenced In Project/Scope: server-start:webapps
cxf-rt-security-saml-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-security-saml High
Vendor gradle artifactid cxf-rt-security-saml Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name rt Highest
Vendor jar package name security Highest
Vendor Manifest automatic-module-name org.apache.cxf.security.saml Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-security-saml Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-security-saml Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime SAML Security functionality High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-security-saml High
Product gradle artifactid cxf-rt-security-saml Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name rt Highest
Product jar package name security Highest
Product Manifest automatic-module-name org.apache.cxf.security.saml Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime SAML Security functionality Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-security-saml Medium
Product pom artifactid cxf-rt-security-saml Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime SAML Security functionality High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-transports-http-4.1.3.jar
Description:
Apache CXF Runtime HTTP Transport
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-transports-http/4.1.3/47f921952b12c608a50f04e6c73d3ef0781fc866/cxf-rt-transports-http-4.1.3.jar
MD5: 5a6661f7e727001c58303b72c1d3d213
SHA1: 47f921952b12c608a50f04e6c73d3ef0781fc866
SHA256: 05cd069ffb19e33580378b53a4f03215d3a7fbd9630ab92d5564ae2220cf756c
Referenced In Project/Scope: server-start:webapps
cxf-rt-transports-http-4.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-transports-http High
Vendor gradle artifactid cxf-rt-transports-http Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name http Highest
Vendor jar package name transport Highest
Vendor jar package name transports Highest
Vendor Manifest automatic-module-name org.apache.cxf.transport.http Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-transports-http Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-transports-http Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime HTTP Transport High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-transports-http High
Product gradle artifactid cxf-rt-transports-http Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name http Highest
Product jar package name transport Highest
Product jar package name transports Highest
Product Manifest automatic-module-name org.apache.cxf.transport.http Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime HTTP Transport Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-transports-http Medium
Product pom artifactid cxf-rt-transports-http Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime HTTP Transport High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-ws-addr-4.1.3.jar
Description:
Apache CXF Runtime WS Addressing
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-ws-addr/4.1.3/7f1cf08c77ebf602bbc2218f6a5eb1984c6de9f7/cxf-rt-ws-addr-4.1.3.jar
MD5: cf06486f52bdf026c5175b677c460c15
SHA1: 7f1cf08c77ebf602bbc2218f6a5eb1984c6de9f7
SHA256: d6c768e309b8cb24a2cb1f1087d502b0de41e4a21dd8db27a6361f2fe95b9592
Referenced In Project/Scope: server-start:webapps
cxf-rt-ws-addr-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-ws-addr High
Vendor gradle artifactid cxf-rt-ws-addr Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name addressing Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name ws Highest
Vendor Manifest automatic-module-name org.apache.cxf.ws.addr Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-addr Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-ws-addr Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime WS Addressing High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-ws-addr High
Product gradle artifactid cxf-rt-ws-addr Highest
Product hint analyzer product web services Medium
Product jar package name addressing Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name ws Highest
Product Manifest automatic-module-name org.apache.cxf.ws.addr Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime WS Addressing Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-addr Medium
Product pom artifactid cxf-rt-ws-addr Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime WS Addressing High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-ws-policy-4.1.3.jar
Description:
Apache CXF Runtime WS Policy
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-ws-policy/4.1.3/99d23773eab4a13c7e9ed778588fcf7eeac638f6/cxf-rt-ws-policy-4.1.3.jar
MD5: ba4cb0b7669225a508d68faed81b62fb
SHA1: 99d23773eab4a13c7e9ed778588fcf7eeac638f6
SHA256: b5e9812d08f1c91d92c6150275f617f34c56be6eab18f0b97c2b3be3f9dae334
Referenced In Project/Scope: server-start:webapps
cxf-rt-ws-policy-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-ws-policy High
Vendor gradle artifactid cxf-rt-ws-policy Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name policy Highest
Vendor jar package name ws Highest
Vendor Manifest automatic-module-name org.apache.cxf.ws.policy Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-policy Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-ws-policy Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime WS Policy High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-ws-policy High
Product gradle artifactid cxf-rt-ws-policy Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name policy Highest
Product jar package name ws Highest
Product Manifest automatic-module-name org.apache.cxf.ws.policy Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime WS Policy Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-policy Medium
Product pom artifactid cxf-rt-ws-policy Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime WS Policy High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-ws-security-4.1.3.jar
Description:
Apache CXF Runtime WS Security
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-ws-security/4.1.3/7d8acaf3d215cc191f43d14af1eb559eb8c2bf93/cxf-rt-ws-security-4.1.3.jar
MD5: 49570fd714a24458ba1f25b693bce61c
SHA1: 7d8acaf3d215cc191f43d14af1eb559eb8c2bf93
SHA256: 4ae344e740aa8fb005594ccbcdc190d592631da32f5c010a30116e9e8090b950
Referenced In Project/Scope: server-start:webapps
cxf-rt-ws-security-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-ws-security High
Vendor gradle artifactid cxf-rt-ws-security Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name security Highest
Vendor jar package name ws Highest
Vendor Manifest automatic-module-name org.apache.cxf.ws.security Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-security Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-ws-security Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime WS Security High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-ws-security High
Product gradle artifactid cxf-rt-ws-security Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name security Highest
Product jar package name ws Highest
Product Manifest automatic-module-name org.apache.cxf.ws.security Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime WS Security Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-ws-security Medium
Product pom artifactid cxf-rt-ws-security Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime WS Security High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
cxf-rt-wsdl-4.1.3.jar
Description:
Apache CXF Runtime Core for WSDL Based Technologies
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.cxf/cxf-rt-wsdl/4.1.3/641cea3a5acd7be473d017357a4493d7cb7cdbc4/cxf-rt-wsdl-4.1.3.jar
MD5: c5a96c67da9ba4ddb412300fdad0d0d6
SHA1: 641cea3a5acd7be473d017357a4493d7cb7cdbc4
SHA256: dac11d871afea9c60b88b76f0d214f318d47ed1604cb17446d2b1da9bbaab60d
Referenced In Project/Scope: server-start:webapps
cxf-rt-wsdl-4.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name cxf-rt-wsdl High
Vendor gradle artifactid cxf-rt-wsdl Highest
Vendor gradle groupid org.apache.cxf Highest
Vendor jar package name apache Highest
Vendor jar package name cxf Highest
Vendor jar package name wsdl Highest
Vendor Manifest automatic-module-name org.apache.cxf.wsdl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl http://cxf.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.cxf.cxf-rt-wsdl Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid cxf-rt-wsdl Low
Vendor pom groupid org.apache.cxf Highest
Vendor pom name Apache CXF Runtime Core for WSDL High
Vendor pom parent-artifactid cxf-parent Low
Vendor pom url https://cxf.apache.org Highest
Product file name cxf-rt-wsdl High
Product gradle artifactid cxf-rt-wsdl Highest
Product jar package name apache Highest
Product jar package name cxf Highest
Product jar package name wsdl Highest
Product Manifest automatic-module-name org.apache.cxf.wsdl Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl http://cxf.apache.org Low
Product Manifest Bundle-Name Apache CXF Runtime Core for WSDL Medium
Product Manifest bundle-symbolicname org.apache.cxf.cxf-rt-wsdl Medium
Product pom artifactid cxf-rt-wsdl Highest
Product pom groupid org.apache.cxf Highest
Product pom name Apache CXF Runtime Core for WSDL High
Product pom parent-artifactid cxf-parent Medium
Product pom url https://cxf.apache.org Medium
Version file version 4.1.3 High
Version gradle version 4.1.3 Highest
Version Manifest Bundle-Version 4.1.3 High
Version Manifest Implementation-Version 4.1.3 High
Version pom version 4.1.3 Highest
CVE-2026-44930 suppress
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44417 suppress
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44618 suppress
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
dagger-2.20.jar
Description:
A fast dependency injector for Android and Java.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.dagger/dagger/2.20/8898d0aea048250e29b106b95b63f046a6cae1c4/dagger-2.20.jar
MD5: 64217f21b016a9b1fdc18549fefbe58f
SHA1: 8898d0aea048250e29b106b95b63f046a6cae1c4
SHA256: d37a556d8d57e2428c20e222b95346512d11fcf2174d581489a69a1439b886fb
Referenced In Project/Scope: server-start:runtimeClasspath
dagger-2.20.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dagger High
Vendor gradle artifactid dagger Highest
Vendor gradle groupid com.google.dagger Highest
Vendor jar package name dagger Low
Vendor jar package name internal Low
Vendor Manifest target-label //java/dagger:core Low
Vendor pom artifactid dagger Low
Vendor pom groupid com.google.dagger Highest
Vendor pom name Dagger High
Vendor pom organization name Google, Inc. High
Vendor pom organization url http://www.google.com Medium
Vendor pom url google/dagger Highest
Product file name dagger High
Product gradle artifactid dagger Highest
Product jar package name dagger Highest
Product jar package name internal Low
Product Manifest target-label //java/dagger:core Low
Product pom artifactid dagger Highest
Product pom groupid com.google.dagger Highest
Product pom name Dagger High
Product pom organization name Google, Inc. Low
Product pom organization url http://www.google.com Low
Product pom url google/dagger High
Version file version 2.20 High
Version gradle version 2.20 Highest
Version pom version 2.20 Highest
pkg:maven/com.google.dagger/dagger@2.20
(Confidence :High)
dcm4che-core-2.0.26.jar
Description:
dcm4che DICOM toolkit
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/dcm4che/dcm4che-core/2.0.26/bbd6658a415527cb61a3b03aafa2b37584c097a6/dcm4che-core-2.0.26.jar
MD5: f3352ae278b9c6a6f20230ca19bcb98f
SHA1: bbd6658a415527cb61a3b03aafa2b37584c097a6
SHA256: 653df44f2ac70cecbc85750ab5d483406696492ab79b6b8d696c803d6d21cac7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dcm4che-core-2.0.26.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dcm4che-core High
Vendor gradle artifactid dcm4che-core Highest
Vendor gradle groupid dcm4che Highest
Vendor jar package name dcm4che2 Highest
Vendor Manifest bundle-symbolicname org.dcm4che2.dcm4che-core Medium
Vendor pom artifactid dcm4che-core Low
Vendor pom groupid dcm4che Highest
Vendor pom name dcm4che-core High
Vendor pom parent-artifactid dcm4che Low
Product file name dcm4che-core High
Product gradle artifactid dcm4che-core Highest
Product jar package name dcm4che2 Highest
Product Manifest Bundle-Name dcm4che-core Medium
Product Manifest bundle-symbolicname org.dcm4che2.dcm4che-core Medium
Product pom artifactid dcm4che-core Highest
Product pom groupid dcm4che Highest
Product pom name dcm4che-core High
Product pom parent-artifactid dcm4che Medium
Version file version 2.0.26 High
Version gradle version 2.0.26 Highest
Version Manifest Bundle-Version 2.0.26 High
Version pom version 2.0.26 Highest
pkg:maven/dcm4che/dcm4che-core@2.0.26
(Confidence :High)
dcm4che-image-2.0.26.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/dcm4che/dcm4che-image/2.0.26/94268502ce0fb6be596db94625adc1877ab52e4a/dcm4che-image-2.0.26.jar
MD5: bbf37f5446c608ba5e9a60bde8007e22
SHA1: 94268502ce0fb6be596db94625adc1877ab52e4a
SHA256: a4f8d628d92a4d3c6fe5417b4b0f836824b01734c1258a5f44d7d1144b1acf25
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dcm4che-image-2.0.26.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dcm4che-image High
Vendor gradle artifactid dcm4che-image Highest
Vendor gradle groupid dcm4che Highest
Vendor jar package name dcm4che2 Highest
Vendor jar package name image Highest
Vendor Manifest bundle-symbolicname org.dcm4che2.dcm4che-image Medium
Vendor pom artifactid dcm4che-image Low
Vendor pom groupid dcm4che Highest
Vendor pom name dcm4che-image High
Vendor pom parent-artifactid dcm4che Low
Product file name dcm4che-image High
Product gradle artifactid dcm4che-image Highest
Product jar package name dcm4che2 Highest
Product jar package name image Highest
Product Manifest Bundle-Name dcm4che-image Medium
Product Manifest bundle-symbolicname org.dcm4che2.dcm4che-image Medium
Product pom artifactid dcm4che-image Highest
Product pom groupid dcm4che Highest
Product pom name dcm4che-image High
Product pom parent-artifactid dcm4che Medium
Version file version 2.0.26 High
Version gradle version 2.0.26 Highest
Version Manifest Bundle-Version 2.0.26 High
Version pom version 2.0.26 Highest
pkg:maven/dcm4che/dcm4che-image@2.0.26
(Confidence :High)
dcm4che-imageio-2.0.26.jar
Description:
ImageIO module
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/dcm4che/dcm4che-imageio/2.0.26/55a9b1ffde100688be4bb0d0d434c9dbcbad4845/dcm4che-imageio-2.0.26.jar
MD5: 9d47c108dc3c201030e6a16ec3ca07d8
SHA1: 55a9b1ffde100688be4bb0d0d434c9dbcbad4845
SHA256: 95b6558cbe4fe5368ac73f02c75184edde0a461e53b24f33b31cca7cba7370c3
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dcm4che-imageio-2.0.26.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dcm4che-imageio High
Vendor gradle artifactid dcm4che-imageio Highest
Vendor gradle groupid dcm4che Highest
Vendor jar package name dcm4che2 Highest
Vendor jar package name imageio Highest
Vendor Manifest bundle-symbolicname org.dcm4che2.dcm4che-imageio Medium
Vendor pom artifactid dcm4che-imageio Low
Vendor pom groupid dcm4che Highest
Vendor pom name dcm4che-imageio High
Vendor pom parent-artifactid dcm4che Low
Product file name dcm4che-imageio High
Product gradle artifactid dcm4che-imageio Highest
Product jar package name dcm4che2 Highest
Product jar package name imageio Highest
Product Manifest Bundle-Name dcm4che-imageio Medium
Product Manifest bundle-symbolicname org.dcm4che2.dcm4che-imageio Medium
Product pom artifactid dcm4che-imageio Highest
Product pom groupid dcm4che Highest
Product pom name dcm4che-imageio High
Product pom parent-artifactid dcm4che Medium
Version file version 2.0.26 High
Version gradle version 2.0.26 Highest
Version Manifest Bundle-Version 2.0.26 High
Version pom version 2.0.26 Highest
pkg:maven/dcm4che/dcm4che-imageio@2.0.26
(Confidence :High)
dcm4che-net-2.0.26.jar
Description:
DICOM network API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/dcm4che/dcm4che-net/2.0.26/8c904d21356e7f3d63aedbffb09405b000d0fece/dcm4che-net-2.0.26.jar
MD5: 3bc37e44fab1d0135cf4e84eece3ed0d
SHA1: 8c904d21356e7f3d63aedbffb09405b000d0fece
SHA256: d98736eeabc0d7a1918ddf2efdaba2434ea54ac54f08448038b281781c0008e1
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dcm4che-net-2.0.26.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dcm4che-net High
Vendor gradle artifactid dcm4che-net Highest
Vendor gradle groupid dcm4che Highest
Vendor jar package name dcm4che2 Highest
Vendor jar package name net Highest
Vendor Manifest bundle-symbolicname org.dcm4che2.dcm4che-net Medium
Vendor pom artifactid dcm4che-net Low
Vendor pom groupid dcm4che Highest
Vendor pom name dcm4che-net High
Vendor pom parent-artifactid dcm4che Low
Product file name dcm4che-net High
Product gradle artifactid dcm4che-net Highest
Product jar package name dcm4che2 Highest
Product jar package name net Highest
Product Manifest Bundle-Name dcm4che-net Medium
Product Manifest bundle-symbolicname org.dcm4che2.dcm4che-net Medium
Product pom artifactid dcm4che-net Highest
Product pom groupid dcm4che Highest
Product pom name dcm4che-net High
Product pom parent-artifactid dcm4che Medium
Version file version 2.0.26 High
Version gradle version 2.0.26 Highest
Version Manifest Bundle-Version 2.0.26 High
Version pom version 2.0.26 Highest
pkg:maven/dcm4che/dcm4che-net@2.0.26
(Confidence :High)
dom4j-2.1.3.jar
Description:
flexible XML framework for Java
License:
BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.dom4j/dom4j/2.1.3/a75914155a9f5808963170ec20653668a2ffd2fd/dom4j-2.1.3.jar
MD5: 41efcf234c5a05a8c590f9b51d53ca66
SHA1: a75914155a9f5808963170ec20653668a2ffd2fd
SHA256: 549f3007c6290f6a901e57d1d331b4ed0e6bf7384f78bf10316ffceeca834de6
Referenced In Project/Scope: server-start:runtimeClasspath
dom4j-2.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dom4j High
Vendor gradle artifactid dom4j Highest
Vendor gradle groupid org.dom4j Highest
Vendor jar package name dom4j Low
Vendor pom artifactid dom4j Low
Vendor pom developer email filip@jirsak.org Low
Vendor pom developer name Filip Jirsák Medium
Vendor pom groupid org.dom4j Highest
Vendor pom name dom4j High
Vendor pom url http://dom4j.github.io/ Highest
Product file name dom4j High
Product gradle artifactid dom4j Highest
Product pom artifactid dom4j Highest
Product pom developer email filip@jirsak.org Low
Product pom developer name Filip Jirsák Low
Product pom groupid org.dom4j Highest
Product pom name dom4j High
Product pom url http://dom4j.github.io/ Medium
Version file version 2.1.3 High
Version gradle version 2.1.3 Highest
Version pom version 2.1.3 Highest
dtd-parser-1.4.5.jar
Description:
SAX-like API for parsing XML DTDs.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.dtd-parser/dtd-parser/1.4.5/bd01768721835f13a6da58f6edea5f8c57ee7b3c/dtd-parser-1.4.5.jar
MD5: b27b38e842491770c5a1953dc86468d1
SHA1: bd01768721835f13a6da58f6edea5f8c57ee7b3c
SHA256: a4cd6addced42e2f870dcca1716f459da51f06f2fe49430d2d128f147c8e929d
Referenced In Project/Scope: server-start:runtimeClasspath
dtd-parser-1.4.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dtd-parser High
Vendor gradle artifactid dtd-parser Highest
Vendor gradle groupid com.sun.xml.dtd-parser Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.dtd-parser Medium
Vendor Manifest implementation-build-id 1.4.5 - 4bbd8f7 Low
Vendor pom artifactid dtd-parser Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom groupid com.sun.xml.dtd-parser Highest
Vendor pom name DTD Parser High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/jaxb-dtd-parser Highest
Product file name dtd-parser High
Product gradle artifactid dtd-parser Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name DTD Parser Medium
Product Manifest bundle-symbolicname com.sun.xml.dtd-parser Medium
Product Manifest implementation-build-id 1.4.5 - 4bbd8f7 Low
Product pom artifactid dtd-parser Highest
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer name Roman Grigoriadi Low
Product pom groupid com.sun.xml.dtd-parser Highest
Product pom name DTD Parser High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/jaxb-dtd-parser High
Version file version 1.4.5 High
Version gradle version 1.4.5 Highest
Version Manifest Bundle-Version 1.4.5 High
Version Manifest implementation-build-id 1.4.5 Low
Version pom parent-version 1.4.5 Low
Version pom version 1.4.5 Highest
pkg:maven/com.sun.xml.dtd-parser/dtd-parser@1.4.5
(Confidence :High)
dvdv-api-2.18.0.jar
Description:
API der Bibliothek zum Zugriff auf das Deutsche Verwaltungsdiensteverzeichnis
License:
eupl1.2: https://eupl.eu/1.2/de/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.dataport.dvdv2/dvdv-api/2.18.0/ac8abc6b32cdd5e12a4e2f54249eea1336eaed25/dvdv-api-2.18.0.jar
MD5: 8bc7498738d630f70643faf46bbb56ff
SHA1: ac8abc6b32cdd5e12a4e2f54249eea1336eaed25
SHA256: ae40cfa3431e8eb5a8685ecdebc64abd445d60a730a3a9e3ac9e752df7dcce3c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dvdv-api-2.18.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dvdv-api High
Vendor gradle artifactid dvdv-api Highest
Vendor gradle groupid de.dataport.dvdv2 Highest
Vendor jar package name de Highest
Vendor jar package name dvdv2 Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest Implementation-Vendor Dataport AöR High
Vendor Manifest specification-vendor Dataport AöR Low
Vendor pom artifactid dvdv-api Low
Vendor pom groupid de.dataport.dvdv2 Highest
Vendor pom name DVDV-Bibliothek für Java(tm) (API) High
Vendor pom parent-artifactid dvdv-devkit-java-parent Low
Vendor pom url https://git.fitko.de/dvdv/dvdv-bibliothek-java/ Highest
Product file name dvdv-api High
Product gradle artifactid dvdv-api Highest
Product jar package name de Highest
Product jar package name dvdv2 Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title DVDV-Bibliothek für Java(tm) (API) High
Product Manifest specification-title DVDV-Bibliothek für Java(tm) (API) Medium
Product pom artifactid dvdv-api Highest
Product pom groupid de.dataport.dvdv2 Highest
Product pom name DVDV-Bibliothek für Java(tm) (API) High
Product pom parent-artifactid dvdv-devkit-java-parent Medium
Product pom url https://git.fitko.de/dvdv/dvdv-bibliothek-java/ Medium
Version file version 2.18.0 High
Version gradle version 2.18.0 Highest
Version Manifest Implementation-Version 2.18.0 High
Version pom version 2.18.0 Highest
pkg:maven/de.dataport.dvdv2/dvdv-api@2.18.0
(Confidence :High)
dvdv-impl-2.18.0.jar
Description:
Implementierung der Bibliothek zum Zugriff auf das Deutsche Verwaltungsdiensteverzeichnis
License:
eupl1.2: https://eupl.eu/1.2/de/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.dataport.dvdv2/dvdv-impl/2.18.0/dad5f740db7291b6bc89abc18425c456a75c1809/dvdv-impl-2.18.0.jar
MD5: 0457c8391e309a62c3408d245999da57
SHA1: dad5f740db7291b6bc89abc18425c456a75c1809
SHA256: 4bac1f72866071fd37519e43cd5200db1292613f015d44eb178e5eaa7f78f1e2
Referenced In Project/Scope: server-start:runtimeClasspath
dvdv-impl-2.18.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dvdv-impl High
Vendor gradle artifactid dvdv-impl Highest
Vendor gradle groupid de.dataport.dvdv2 Highest
Vendor jar package name dataport Highest
Vendor jar package name de Highest
Vendor jar package name dvdv2 Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest Implementation-Vendor Dataport AöR High
Vendor Manifest specification-vendor Dataport AöR Low
Vendor pom artifactid dvdv-impl Low
Vendor pom groupid de.dataport.dvdv2 Highest
Vendor pom name DVDV-Bibliothek für Java(tm) (Implementierung) High
Vendor pom parent-artifactid dvdv-devkit-java-parent Low
Vendor pom url https://git.fitko.de/dvdv/dvdv-bibliothek-java/ Highest
Product file name dvdv-impl High
Product gradle artifactid dvdv-impl Highest
Product jar package name dataport Highest
Product jar package name de Highest
Product jar package name dvdv2 Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title DVDV-Bibliothek für Java(tm) (Implementierung) High
Product Manifest specification-title DVDV-Bibliothek für Java(tm) (Implementierung) Medium
Product pom artifactid dvdv-impl Highest
Product pom groupid de.dataport.dvdv2 Highest
Product pom name DVDV-Bibliothek für Java(tm) (Implementierung) High
Product pom parent-artifactid dvdv-devkit-java-parent Medium
Product pom url https://git.fitko.de/dvdv/dvdv-bibliothek-java/ Medium
Version file version 2.18.0 High
Version gradle version 2.18.0 Highest
Version Manifest Implementation-Version 2.18.0 High
Version pom version 2.18.0 Highest
pkg:maven/de.dataport.dvdv2/dvdv-impl@2.18.0
(Confidence :High)
dvdv-sdk-1.16.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.dvdv/dvdv-sdk/1.16.0/ac124437231fec74406b77fcfcf14a0c8a6873b6/dvdv-sdk-1.16.0.jar
MD5: 22d647f37fab5c416cf71321ed561326
SHA1: ac124437231fec74406b77fcfcf14a0c8a6873b6
SHA256: 76d9b889f95baf2eb706b564fb01947caad68b750d6baa72762132a25687929b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
dvdv-sdk-1.16.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name dvdv-sdk High
Vendor gradle artifactid dvdv-sdk Highest
Vendor gradle groupid de.dvdv Highest
Vendor jar package name de Low
Vendor jar package name dvdv Highest
Vendor jar package name dvdv Low
Vendor jar package name object Low
Vendor Manifest application-library-allowable-codebase * Low
Vendor Manifest application-name dvdv-sdk-1.16.0 Medium
Vendor Manifest caller-allowable-codebase * Low
Vendor Manifest codebase * Low
Vendor Manifest permissions all-permissions Low
Vendor Manifest trusted-only true Low
Vendor pom artifactid dvdv-sdk Low
Vendor pom groupid de.dvdv Highest
Product file name dvdv-sdk High
Product gradle artifactid dvdv-sdk Highest
Product jar package name dvdv Highest
Product jar package name dvdv Low
Product jar package name object Low
Product Manifest application-library-allowable-codebase * Low
Product Manifest application-name dvdv-sdk-1.16.0 Medium
Product Manifest caller-allowable-codebase * Low
Product Manifest codebase * Low
Product Manifest permissions all-permissions Low
Product Manifest trusted-only true Low
Product pom artifactid dvdv-sdk Highest
Product pom groupid de.dvdv Highest
Version file version 1.16.0 High
Version gradle version 1.16.0 Highest
Version pom version 1.16.0 Highest
pkg:maven/de.dvdv/dvdv-sdk@1.16.0
(Confidence :High)
eddsa-0.3.0.jar
Description:
Implementation of EdDSA in Java
License:
CC0 1.0 Universal: https://creativecommons.org/publicdomain/zero/1.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.i2p.crypto/eddsa/0.3.0/1901c8d4d8bffb7d79027686cfb91e704217c3e1/eddsa-0.3.0.jar
MD5: ee7de3b6f19de76a06e465efc978f669
SHA1: 1901c8d4d8bffb7d79027686cfb91e704217c3e1
SHA256: 4dda1120db856640dbec04140ed23242215a075fe127bdefa0dcfa29fb31267d
Referenced In Project/Scope: server-start:runtimeClasspath
eddsa-0.3.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name eddsa High
Vendor gradle artifactid eddsa Highest
Vendor gradle groupid net.i2p.crypto Highest
Vendor jar package name crypto Highest
Vendor jar package name eddsa Highest
Vendor jar package name i2p Highest
Vendor jar package name net Highest
Vendor Manifest automatic-module-name net.i2p.crypto.eddsa Medium
Vendor Manifest bundle-symbolicname net.i2p.crypto.eddsa Medium
Vendor pom artifactid eddsa Low
Vendor pom developer email str4d@i2pmail.org Low
Vendor pom developer id str4d Medium
Vendor pom developer name str4d Medium
Vendor pom groupid net.i2p.crypto Highest
Vendor pom name EdDSA-Java High
Vendor pom url str4d/ed25519-java Highest
Product file name eddsa High
Product gradle artifactid eddsa Highest
Product jar package name crypto Highest
Product jar package name eddsa Highest
Product jar package name i2p Highest
Product jar package name net Highest
Product Manifest automatic-module-name net.i2p.crypto.eddsa Medium
Product Manifest Bundle-Name EdDSA-Java Medium
Product Manifest bundle-symbolicname net.i2p.crypto.eddsa Medium
Product pom artifactid eddsa Highest
Product pom developer email str4d@i2pmail.org Low
Product pom developer id str4d Low
Product pom developer name str4d Low
Product pom groupid net.i2p.crypto Highest
Product pom name EdDSA-Java High
Product pom url str4d/ed25519-java High
Version file version 0.3.0 High
Version gradle version 0.3.0 Highest
Version Manifest Bundle-Version 0.3.0 High
Version pom version 0.3.0 Highest
pkg:maven/net.i2p.crypto/eddsa@0.3.0
(Confidence :High)
cpe:2.3:a:4d:4d:0.3.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-107:3.10.8)
Description:
The JSR-107 compatibility module of Ehcache 3
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-107/pom.xml
MD5: cbb6582f7bae2d80eba99428ba1fa879
SHA1: 93ece0b8696af1b39d5a59f4ac001ff67ade031b
SHA256: 881431ccba0094c52fde3d05f6800c5fa488f21ce8e0c253b3080868822362cb
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-107 Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 JSR-107 module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-107 Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 JSR-107 module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-107@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-api:3.10.8)
Description:
The API module of Ehcache 3
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-api/pom.xml
MD5: 684f68673f7e1877dd8710c9c20b66a8
SHA1: 5cb0644b5714e1cd3b9ed067db5b74c1d2f90405
SHA256: 8cb81dbe787af826481c2a79ad85bef6e46cf429a982a765581142a823db54e5
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-api Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 API module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-api Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 API module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-api@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-core:3.10.8)
Description:
The Core module of Ehcache 3
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-core/pom.xml
MD5: 81e4d90adf09bff8de32a927f13fa7dd
SHA1: 1603c939dbc836b9a67ba29c8e3f5bde24a35345
SHA256: d26e487336af1baa60250c41d3f30d6f62fed549c8f282ecccdbb9a905f00a3f
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-core Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 Core module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-core Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 Core module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-core@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-impl:3.10.8)
Description:
The implementation module of Ehcache 3
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-impl/pom.xml
MD5: 68666160c19c3a231099a0d5d61f364f
SHA1: 99176e4618d2a09bbef35ab175273edf50b72f3c
SHA256: 9ccbc05db652fe94233c346648fb06d503bfbf27f13aaaec4be87752b14f1d9c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-impl Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 Implementation module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-impl Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 Implementation module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-impl@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-xml-spi:3.10.8)
Description:
This module contains the XML parsing SPI for Ehcache 3. This allows Ehcache extension services to provide XML configuration capabilities.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-xml-spi/pom.xml
MD5: d692ac727407f129dc07ce98a6c309b2
SHA1: 35f69aaa6f9b7b413aa6c12c969f0e91ba1ffb1f
SHA256: aecb4a20f1ce69a777649b65343557329e031641481841a233973d857d2ba32d
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-xml-spi Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 XML Parsing SPI Module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-xml-spi Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 XML Parsing SPI Module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-xml-spi@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache.modules:ehcache-xml:3.10.8)
Description:
The module containing all XML parsing logic Ehcache 3
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache.modules/ehcache-xml/pom.xml
MD5: c0cfdd21ebfc0207a9516d08ab7e2858
SHA1: 0cec45ad454b3eb0d5cd4a5f4fffd71b1e462e31
SHA256: bd6c0ce56beca6eb6b0b6a55fcf3c86a652b8ddc0bb2cf390c8c3f3e660603fe
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-xml Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache.modules Highest
Vendor pom name Ehcache 3 XML Parsing module High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product pom artifactid ehcache-xml Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache.modules Highest
Product pom name Ehcache 3 XML Parsing module High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache.modules/ehcache-xml@3.10.8
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.ehcache:sizeof:0.4.3)
Description:
SizeOf engine, extracted from Ehcache
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.ehcache/sizeof/pom.xml
MD5: c0ad3baef0ef03d4ca849743f1f26b70
SHA1: 8589b7bd18f4b3e12cd222a44bdcbbada5363da8
SHA256: 9c03a981dbff96ff6b7d74dffb5e8a9a46bb66e06ba98d18f6b8ff4472bd0709
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid sizeof Low
Vendor pom groupid org.ehcache Highest
Vendor pom name Ehcache SizeOf Engine High
Vendor pom organization name Terracotta High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url ehcache/sizeof Highest
Product pom artifactid sizeof Highest
Product pom groupid org.ehcache Highest
Product pom name Ehcache SizeOf Engine High
Product pom organization name Terracotta Low
Product pom organization url http://terracotta.org Low
Product pom url ehcache/sizeof High
Version pom version 0.4.3 Highest
pkg:maven/org.ehcache/sizeof@0.4.3
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.terracotta:offheap-store:2.5.3)
Description:
A library that offers data structures allocated off the java heap.
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.terracotta/offheap-store/pom.xml
MD5: f5ad26371f4a3b04c5b8a0a089639d87
SHA1: 1979a0cbe0be10a6d5215bb9cbbb5635b9314924
SHA256: d8ae272530d98560cf81066b0409bcba2648a2528c00bd0147253695bb5f0949
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid offheap-store Low
Vendor pom developer email chris.dennis@terracottatech.com Low
Vendor pom developer name Chris Dennis Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL https://terracotta.org Medium
Vendor pom groupid org.terracotta Highest
Vendor pom name Terracotta Off-Heap Store High
Vendor pom url Terracotta-OSS/offheap-store/ Highest
Product pom artifactid offheap-store Highest
Product pom developer email chris.dennis@terracottatech.com Low
Product pom developer name Chris Dennis Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL https://terracotta.org Low
Product pom groupid org.terracotta Highest
Product pom name Terracotta Off-Heap Store High
Product pom url Terracotta-OSS/offheap-store/ High
Version pom version 2.5.3 Highest
pkg:maven/org.terracotta/offheap-store@2.5.3
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.terracotta:statistics:2.1.2)
Description:
A statistics framework used inside Ehcache and the Terracotta products
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.terracotta/statistics/pom.xml
MD5: 9df3f5a18142de19c1c7f379885a4391
SHA1: 305a0214578ebf1c14e8d78adce1a5af028c8132
SHA256: 25c36806fdcd2ab5e4c1c1c5625bc4f966c10a4a93ab3dd321aa82b3f9e43081
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid statistics Low
Vendor pom developer email chris.dennis@terracottatech.com Low
Vendor pom developer email Chris.Schanck@terracottatech.com Low
Vendor pom developer email ludovic.orban@terracottatech.com Low
Vendor pom developer name Chris Dennis Medium
Vendor pom developer name Chris Schanck Medium
Vendor pom developer name Ludovic Orban Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL https://terracotta.org Medium
Vendor pom groupid org.terracotta Highest
Vendor pom name Terracotta Statistics High
Vendor pom url Terracotta-OSS/statistics Highest
Product pom artifactid statistics Highest
Product pom developer email chris.dennis@terracottatech.com Low
Product pom developer email Chris.Schanck@terracottatech.com Low
Product pom developer email ludovic.orban@terracottatech.com Low
Product pom developer name Chris Dennis Low
Product pom developer name Chris Schanck Low
Product pom developer name Ludovic Orban Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL https://terracotta.org Low
Product pom groupid org.terracotta Highest
Product pom name Terracotta Statistics High
Product pom url Terracotta-OSS/statistics High
Version pom version 2.1.2 Highest
pkg:maven/org.terracotta/statistics@2.1.2
(Confidence :High)
ehcache-3.10.8-jakarta.jar (shaded: org.terracotta:terracotta-utilities-tools:0.0.15)
Description:
Utility classes/methods for common Java tasks
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/META-INF/maven/org.terracotta/terracotta-utilities-tools/pom.xml
MD5: e4749433aaf243a0fbc14ddad08bbe55
SHA1: 9b7960438f39f7be178e17bba391f38c7b38c860
SHA256: 144603b5fb19b5900a9a28a3a5d7a74f4deeddbdc34d1de8a716f79f91854ada
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid terracotta-utilities-tools Low
Vendor pom developer email clifford.johnson@softwareag.com Low
Vendor pom developer name Clifford W Johnson Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL https://terracotta.org Medium
Vendor pom groupid org.terracotta Highest
Vendor pom name Terracotta Utilities Tools High
Vendor pom parent-artifactid terracotta-utilities-parent Low
Vendor pom url Terracotta-OSS/terracotta-utilities/ Highest
Product pom artifactid terracotta-utilities-tools Highest
Product pom developer email clifford.johnson@softwareag.com Low
Product pom developer name Clifford W Johnson Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL https://terracotta.org Low
Product pom groupid org.terracotta Highest
Product pom name Terracotta Utilities Tools High
Product pom parent-artifactid terracotta-utilities-parent Medium
Product pom url Terracotta-OSS/terracotta-utilities/ High
Version pom version 0.0.15 Highest
pkg:maven/org.terracotta/terracotta-utilities-tools@0.0.15
(Confidence :High)
ehcache-3.10.8-jakarta.jar
Description:
Ehcache is an open-source caching library, compliant with the JSR-107 standard.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar
MD5: 6767673b52b5c2157bb6b41daef38963
SHA1: 892b8caf98d188d0bac6ff16db564cae13a6874f
SHA256: 4530ba51c1768f680bffcc5af722f7b65a0abb3874d9f17a731c7085eb2613e7
Referenced In Project/Scope: server-start:webapps
ehcache-3.10.8-jakarta.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ehcache High
Vendor gradle artifactid ehcache Highest
Vendor gradle groupid org.ehcache Highest
Vendor jar package name ehcache Highest
Vendor jar package name ehcache Low
Vendor jar package name org Highest
Vendor Manifest bundle-docurl http://ehcache.org Low
Vendor Manifest bundle-symbolicname org.ehcache Medium
Vendor Manifest implementation-revision e8c3b4a333f3ffc60d5b8d60ac3f64741efc81e9 Low
Vendor Manifest Implementation-Vendor-Id org.ehcache Medium
Vendor Manifest provide-capability osgi.service;objectClass:List="javax.cache.spi.CachingProvider";uses:="javax.cache.spi",osgi.service;objectClass:List="org.ehcache.core.spi.service.ServiceFactory";uses:="org.ehcache.core.spi.service",osgi.service;objectClass:List="org.ehcache.xml.CacheManagerServiceConfigurationParser";uses:="org.ehcache.xml",osgi.service;objectClass:List="org.ehcache.xml.CacheServiceConfigurationParser";uses:="org.ehcache.xml" Low
Vendor Manifest service-component OSGI-INF/*.xml Low
Vendor pom artifactid ehcache Low
Vendor pom developer email tc-oss@softwareag.com Low
Vendor pom developer name Terracotta Engineers Medium
Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium
Vendor pom developer org URL http://ehcache.org Medium
Vendor pom groupid org.ehcache Highest
Vendor pom name Ehcache High
Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High
Vendor pom organization url http://terracotta.org Medium
Vendor pom url http://ehcache.org Highest
Product file name ehcache High
Product gradle artifactid ehcache Highest
Product jar package name cache Highest
Product jar package name cachemanagerserviceconfigurationparser Highest
Product jar package name cacheserviceconfigurationparser Highest
Product jar package name core Highest
Product jar package name ehcache Highest
Product jar package name org Highest
Product jar package name osgi Highest
Product jar package name service Highest
Product jar package name spi Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://ehcache.org Low
Product Manifest Bundle-Name Ehcache 3 Medium
Product Manifest bundle-symbolicname org.ehcache Medium
Product Manifest implementation-revision e8c3b4a333f3ffc60d5b8d60ac3f64741efc81e9 Low
Product Manifest Implementation-Title ehcache High
Product Manifest provide-capability osgi.service;objectClass:List="javax.cache.spi.CachingProvider";uses:="javax.cache.spi",osgi.service;objectClass:List="org.ehcache.core.spi.service.ServiceFactory";uses:="org.ehcache.core.spi.service",osgi.service;objectClass:List="org.ehcache.xml.CacheManagerServiceConfigurationParser";uses:="org.ehcache.xml",osgi.service;objectClass:List="org.ehcache.xml.CacheServiceConfigurationParser";uses:="org.ehcache.xml" Low
Product Manifest service-component OSGI-INF/*.xml Low
Product pom artifactid ehcache Highest
Product pom developer email tc-oss@softwareag.com Low
Product pom developer name Terracotta Engineers Low
Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom developer org URL http://ehcache.org Low
Product pom groupid org.ehcache Highest
Product pom name Ehcache High
Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low
Product pom organization url http://terracotta.org Low
Product pom url http://ehcache.org Medium
Version file version 3.10.8 High
Version gradle version 3.10.8 Highest
Version Manifest Bundle-Version 3.10.8 High
Version Manifest Implementation-Version 3.10.8 High
Version pom version 3.10.8 Highest
pkg:maven/org.ehcache/ehcache@3.10.8
(Confidence :High)
cpe:2.3:a:service_project:service:3.10.8:*:*:*:*:*:*:*
(Confidence :Low)
suppress
ehcache-3.10.8-jakarta.jar: sizeof-agent.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.ehcache/ehcache/3.10.8/892b8caf98d188d0bac6ff16db564cae13a6874f/ehcache-3.10.8-jakarta.jar/org/ehcache/sizeof/impl/sizeof-agent.jar
MD5: 532dbbf741bfb7f531938786bc0bb970
SHA1: 4e5d8c485b09104825c0d8ec635f775ab522be06
SHA256: 60e093acb08d3bc30235ef15941380195cbb85b1ec8b4afd672249f9c530e356
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name sizeof-agent High
Vendor jar package name ehcache Low
Vendor jar package name impl Low
Vendor jar package name sizeof Low
Product file name sizeof-agent High
Product jar package name impl Low
Product jar package name sizeof Low
Product jar package name sizeofagent Low
email-ews-connector-0.9.13.war
Description:
Web application: email-ews-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war
MD5: 37b99728b398cd01ebdfbfba5111b4ec
SHA1: d8a79bf9b348330fb72d81d27832ef340778b2a4
SHA256: d73b1bba5aeecea56e84f519464596ffcb416e8ff6e079375ce1c72cd430a5fb
Referenced In Project/Scope: server-start:webapps
email-ews-connector-0.9.13.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name email-ews-connector High
Vendor gradle artifactid email-ews-connector Highest
Vendor gradle groupid io.transconnect.connector.email Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid email-ews-connector Low
Vendor pom groupid io.transconnect.connector.email Highest
Product file name email-ews-connector High
Product gradle artifactid email-ews-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid email-ews-connector Highest
Product pom groupid io.transconnect.connector.email Highest
Version file version 0.9.13 High
Version gradle version 0.9.13 Highest
Version pom version 0.9.13 Highest
pkg:maven/io.transconnect.connector.email/email-ews-connector@0.9.13
(Confidence :High)
email-ews-connector-0.9.13.war: accessors-smart-2.5.2.jar
Description:
Java reflect give poor performance on getter setter an constructor calls, accessors-smart use ASM to speed up those calls.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/accessors-smart-2.5.2.jar
MD5: 24191e0bb215c72902e89f46dde839e1
SHA1: ce16fd235cfee48e67eda33e684423bba09f7d07
SHA256: 9b8a7bc43861d6156c021166d941fb7dddbe4463e2fa5ee88077e4b01452a836
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name accessors-smart High
Vendor jar package name asm Highest
Vendor jar package name minidev Highest
Vendor jar package name net Highest
Vendor Manifest build-jdk-spec 23 Low
Vendor Manifest bundle-docurl https://urielch.github.io/ Low
Vendor Manifest bundle-symbolicname net.minidev.accessors-smart Medium
Vendor pom artifactid accessors-smart Low
Vendor pom developer email hezhangjian97gmail.com Low
Vendor pom developer email uchemouni@gmail.com Low
Vendor pom developer id hezhangjian Medium
Vendor pom developer id uriel Medium
Vendor pom developer name Uriel Chemouni Medium
Vendor pom developer name Zhangjian He Medium
Vendor pom groupid net.minidev Highest
Vendor pom name ASM based accessors helper used by json-smart High
Vendor pom organization name Chemouni Uriel High
Vendor pom organization url https://urielch.github.io/ Medium
Vendor pom url https://urielch.github.io/ Highest
Product file name accessors-smart High
Product jar package name asm Highest
Product jar package name minidev Highest
Product jar package name net Highest
Product Manifest build-jdk-spec 23 Low
Product Manifest bundle-docurl https://urielch.github.io/ Low
Product Manifest Bundle-Name accessors-smart Medium
Product Manifest bundle-symbolicname net.minidev.accessors-smart Medium
Product pom artifactid accessors-smart Highest
Product pom developer email hezhangjian97gmail.com Low
Product pom developer email uchemouni@gmail.com Low
Product pom developer id hezhangjian Low
Product pom developer id uriel Low
Product pom developer name Uriel Chemouni Low
Product pom developer name Zhangjian He Low
Product pom groupid net.minidev Highest
Product pom name ASM based accessors helper used by json-smart High
Product pom organization name Chemouni Uriel Low
Product pom organization url https://urielch.github.io/ Low
Product pom url https://urielch.github.io/ Medium
Version file version 2.5.2 High
Version Manifest Bundle-Version 2.5.2 High
Version pom version 2.5.2 Highest
pkg:maven/net.minidev/accessors-smart@2.5.2
(Confidence :High)
email-ews-connector-0.9.13.war: asm-9.7.1.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/asm-9.7.1.jar
MD5: e2cdd32d198ad31427d298eee9d39d8d
SHA1: f0ed132a49244b042cd0e15702ab9f2ce3cc8436
SHA256: 8cadd43ac5eb6d09de05faecca38b917a040bb9139c7edeb4cc81c740b713281
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.7.1 High
Version Manifest Implementation-Version 9.7.1 High
email-ews-connector-0.9.13.war: azure-json-1.4.0.jar
Description:
This package provides interfaces for reading and writing JSON.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/azure-json-1.4.0.jar
MD5: 2d77c261ef8a9812efc15fcca22af984
SHA1: fcc1d354dbc3e0300e5276b1bf124d0247799cd8
SHA256: c50bc998cd1a6c689f8644b51c206217bf2da09d5b949e777490a60290cc3a0d
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-json High
Vendor jar package name azure Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-json Low
Vendor pom developer id microsoft Medium
Vendor pom developer name Microsoft Medium
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure Java JSON Library High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-json High
Product jar package name azure Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure Java JSON Library High
Product pom artifactid azure-json Highest
Product pom developer id microsoft Low
Product pom developer name Microsoft Low
Product pom groupid com.azure Highest
Product pom name Microsoft Azure Java JSON Library High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.4.0 High
Version Manifest Implementation-Version 1.4.0 High
Version pom parent-version 1.4.0 Low
Version pom version 1.4.0 Highest
pkg:maven/com.azure/azure-json@1.4.0
(Confidence :High)
cpe:2.3:a:microsoft:azure_sdk_for_java:1.4.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-33117 suppress
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
CWE-347 Improper Verification of Cryptographic Signature, CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
email-ews-connector-0.9.13.war: checker-qual-3.33.0.jar
License:
MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/checker-qual-3.33.0.jar
MD5: fc9418b779d9d57dcd52197006cbdb9b
SHA1: de2b60b62da487644fc11f734e73c8b0b431238f
SHA256: e316255bbfcd9fe50d165314b85abb2b33cb2a66a93c491db648e498a82c2de1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Highest
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest automatic-module-name org.checkerframework.checker.qual Medium
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Version file version 3.33.0 High
Version Manifest Implementation-Version 3.33.0 High
email-ews-connector-0.9.13.war: commons-codec-1.9.jar
Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/commons-codec-1.9.jar
MD5: 75615356605c8128013da9e3ac62a249
SHA1: 9ce04e34240f674bc72680f8b843b1457383161a
SHA256: ad19d2601c3abf0b946b5c3a4113e226a8c1e3305e395b90013b78dd94a723ce
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name commons-codec High
Vendor jar package name apache Highest
Vendor jar package name codec Highest
Vendor jar package name commons Highest
Vendor jar package name encoder Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium
Vendor Manifest implementation-build tags/1.9-RC1@r1552874; 2013-12-20 22:56:50-0500 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-codec Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email dgraham@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory@apache.org Low
Vendor pom developer email jon@collab.net Low
Vendor pom developer email julius@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@totalsync.com Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer email tobrien@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id dgraham Medium
Vendor pom developer id dlr Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jon Medium
Vendor pom developer id julius Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id tn Medium
Vendor pom developer id tobrien Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name David Graham Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jon S. Stevens Medium
Vendor pom developer name Julius Davies Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer name Tim OBrien Medium
Vendor pom developer org URL http://juliusdavies.ca/ Medium
Vendor pom groupid commons-codec Highest
Vendor pom name Apache Commons Codec High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest
Product file name commons-codec High
Product jar package name apache Highest
Product jar package name codec Highest
Product jar package name commons Highest
Product jar package name encoder Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest bundle-symbolicname org.apache.commons.codec Medium
Product Manifest implementation-build tags/1.9-RC1@r1552874; 2013-12-20 22:56:50-0500 Low
Product Manifest Implementation-Title Apache Commons Codec High
Product Manifest specification-title Apache Commons Codec Medium
Product pom artifactid commons-codec Highest
Product pom developer email bayard@apache.org Low
Product pom developer email dgraham@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory@apache.org Low
Product pom developer email jon@collab.net Low
Product pom developer email julius@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@totalsync.com Low
Product pom developer email tn@apache.org Low
Product pom developer email tobrien@apache.org Low
Product pom developer id bayard Low
Product pom developer id dgraham Low
Product pom developer id dlr Low
Product pom developer id ggregory Low
Product pom developer id jon Low
Product pom developer id julius Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id tn Low
Product pom developer id tobrien Low
Product pom developer name Daniel Rall Low
Product pom developer name David Graham Low
Product pom developer name Gary Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name Jon S. Stevens Low
Product pom developer name Julius Davies Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Thomas Neidhart Low
Product pom developer name Tim OBrien Low
Product pom developer org URL http://juliusdavies.ca/ Low
Product pom groupid commons-codec Highest
Product pom name Apache Commons Codec High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url http://commons.apache.org/proper/commons-codec/ Medium
Version file version 1.9 High
Version Manifest Implementation-Version 1.9 High
Version pom parent-version 1.9 Low
Version pom version 1.9 Highest
pkg:maven/commons-codec/commons-codec@1.9
(Confidence :High)
email-ews-connector-0.9.13.war: commons-lang3-3.4.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/commons-lang3-3.4.jar
MD5: 8667a442ee77e509fbe8176b94726eb2
SHA1: 5fe28b9518e58819180a43a850fbc0dd24b7c050
SHA256: 734c8356420cc8e30c795d64fd1fcd5d44ea9d90342a2cc3262c5158fbc6d98b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang3 High
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name lang3 Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest implementation-build tags/LANG_3_4_RC2@r1671054; 2015-04-03 12:30:21+0000 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-lang3 Low
Vendor pom developer email bayard@apache.org Low
Vendor pom developer email britter@apache.org Low
Vendor pom developer email djones@apache.org Low
Vendor pom developer email dlr@finemaltcoding.com Low
Vendor pom developer email ggregory@apache.org Low
Vendor pom developer email jcarman@apache.org Low
Vendor pom developer email joerg.schaible@gmx.de Low
Vendor pom developer email oheger@apache.org Low
Vendor pom developer email pbenedict@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email scolebourne@joda.org Low
Vendor pom developer email stevencaswell@apache.org Low
Vendor pom developer id bayard Medium
Vendor pom developer id britter Medium
Vendor pom developer id djones Medium
Vendor pom developer id dlr Medium
Vendor pom developer id fredrik Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id jcarman Medium
Vendor pom developer id joehni Medium
Vendor pom developer id mbenson Medium
Vendor pom developer id niallp Medium
Vendor pom developer id oheger Medium
Vendor pom developer id pbenedict Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id scaswell Medium
Vendor pom developer id scolebourne Medium
Vendor pom developer name Benedikt Ritter Medium
Vendor pom developer name Daniel Rall Medium
Vendor pom developer name Duncan Jones Medium
Vendor pom developer name Fredrik Westermarck Medium
Vendor pom developer name Gary D. Gregory Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name James Carman Medium
Vendor pom developer name Joerg Schaible Medium
Vendor pom developer name Matt Benson Medium
Vendor pom developer name Niall Pemberton Medium
Vendor pom developer name Oliver Heger Medium
Vendor pom developer name Paul Benedict Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom developer name Steven Caswell Medium
Vendor pom developer org Carman Consulting, Inc. Medium
Vendor pom developer org CollabNet, Inc. Medium
Vendor pom developer org SITA ATS Ltd Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom name Apache Commons Lang High
Vendor pom parent-artifactid commons-parent Low
Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest
Product file name commons-lang3 High
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name lang3 Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product Manifest implementation-build tags/LANG_3_4_RC2@r1671054; 2015-04-03 12:30:21+0000 Low
Product Manifest Implementation-Title Apache Commons Lang High
Product Manifest specification-title Apache Commons Lang Medium
Product pom artifactid commons-lang3 Highest
Product pom developer email bayard@apache.org Low
Product pom developer email britter@apache.org Low
Product pom developer email djones@apache.org Low
Product pom developer email dlr@finemaltcoding.com Low
Product pom developer email ggregory@apache.org Low
Product pom developer email jcarman@apache.org Low
Product pom developer email joerg.schaible@gmx.de Low
Product pom developer email oheger@apache.org Low
Product pom developer email pbenedict@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email scolebourne@joda.org Low
Product pom developer email stevencaswell@apache.org Low
Product pom developer id bayard Low
Product pom developer id britter Low
Product pom developer id djones Low
Product pom developer id dlr Low
Product pom developer id fredrik Low
Product pom developer id ggregory Low
Product pom developer id jcarman Low
Product pom developer id joehni Low
Product pom developer id mbenson Low
Product pom developer id niallp Low
Product pom developer id oheger Low
Product pom developer id pbenedict Low
Product pom developer id rdonkin Low
Product pom developer id scaswell Low
Product pom developer id scolebourne Low
Product pom developer name Benedikt Ritter Low
Product pom developer name Daniel Rall Low
Product pom developer name Duncan Jones Low
Product pom developer name Fredrik Westermarck Low
Product pom developer name Gary D. Gregory Low
Product pom developer name Henri Yandell Low
Product pom developer name James Carman Low
Product pom developer name Joerg Schaible Low
Product pom developer name Matt Benson Low
Product pom developer name Niall Pemberton Low
Product pom developer name Oliver Heger Low
Product pom developer name Paul Benedict Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Stephen Colebourne Low
Product pom developer name Steven Caswell Low
Product pom developer org Carman Consulting, Inc. Low
Product pom developer org CollabNet, Inc. Low
Product pom developer org SITA ATS Ltd Low
Product pom groupid org.apache.commons Highest
Product pom name Apache Commons Lang High
Product pom parent-artifactid commons-parent Medium
Product pom url http://commons.apache.org/proper/commons-lang/ Medium
Version file version 3.4 High
Version Manifest Implementation-Version 3.4 High
Version pom parent-version 3.4 Low
Version pom version 3.4 Highest
CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
email-ews-connector-0.9.13.war: content-type-2.3.jar
Description:
Java library for Content (Media) Type representation
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/content-type-2.3.jar
MD5: f0fc0d6be73e838863e2197c03a27c3f
SHA1: e3aa0be212d7a42839a8f3f506f5b990bcce0222
SHA256: 60349793e006fba96b532cb0c21e10e969fe0db8d87f91c3b9eaf82ba2998895
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name content-type High
Vendor jar package name nimbusds Highest
Vendor Manifest build-date ${timestamp} Low
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest build-number ${buildNumber} Low
Vendor Manifest build-tag 2.3 Low
Vendor Manifest bundle-docurl https://connect2id.com Low
Vendor Manifest bundle-symbolicname com.nimbusds.content-type Medium
Vendor Manifest implementation-url https://bitbucket.org/connect2id/nimbus-content-type Low
Vendor Manifest Implementation-Vendor Connect2id Ltd. High
Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium
Vendor Manifest specification-vendor Connect2id Ltd. Low
Vendor pom artifactid content-type Low
Vendor pom developer email vladimir@dzhuvinov.com Low
Vendor pom developer id vdzhuvinov Medium
Vendor pom developer name Vladimir Dzhuvinov Medium
Vendor pom groupid com.nimbusds Highest
Vendor pom name Nimbus Content Type High
Vendor pom organization name Connect2id Ltd. High
Vendor pom organization url https://connect2id.com Medium
Vendor pom url https://bitbucket.org/connect2id/nimbus-content-type Highest
Product file name content-type High
Product jar package name nimbusds Highest
Product Manifest build-date ${timestamp} Low
Product Manifest build-jdk-spec 11 Low
Product Manifest build-number ${buildNumber} Low
Product Manifest build-tag 2.3 Low
Product Manifest bundle-docurl https://connect2id.com Low
Product Manifest Bundle-Name Nimbus Content Type Medium
Product Manifest bundle-symbolicname com.nimbusds.content-type Medium
Product Manifest Implementation-Title Nimbus Content Type High
Product Manifest implementation-url https://bitbucket.org/connect2id/nimbus-content-type Low
Product Manifest specification-title Nimbus Content Type Medium
Product pom artifactid content-type Highest
Product pom developer email vladimir@dzhuvinov.com Low
Product pom developer id vdzhuvinov Low
Product pom developer name Vladimir Dzhuvinov Low
Product pom groupid com.nimbusds Highest
Product pom name Nimbus Content Type High
Product pom organization name Connect2id Ltd. Low
Product pom organization url https://connect2id.com Low
Product pom url https://bitbucket.org/connect2id/nimbus-content-type Medium
Version file version 2.3 High
Version Manifest build-tag 2.3 Low
Version Manifest Implementation-Version 2.3 High
Version pom version 2.3 Highest
pkg:maven/com.nimbusds/content-type@2.3
(Confidence :High)
email-ews-connector-0.9.13.war: error_prone_annotations-2.18.0.jar
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/error_prone_annotations-2.18.0.jar
MD5: 64145d0e7fee5a69ed7b84cf402de998
SHA1: 89b684257096f548fa39a7df9fdaa409d4d4df91
SHA256: 9e6814cb71816988a4fd1b07a993a8f21bb7058d522c162b1de849e19bea54ae
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.errorprone.annotations Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.errorprone.annotations Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.18.0 High
Version pom version 2.18.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.18.0
(Confidence :High)
email-ews-connector-0.9.13.war: ews-java-api-2.0.jar
Description:
Exchange Web Services (EWS) Java API
License:
MIT License: http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/ews-java-api-2.0.jar
MD5: bddb4f7875a4d3371c7bb9318436284c
SHA1: 6f76a4ad706b5aa6534a48ea098b257de6b47627
SHA256: 1319c01f9899c3174b4b49849bb92ce8db3e629786c56f733ffb62e1cd729415
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name ews-java-api High
Vendor jar package name exchange Highest
Vendor jar package name exchange Low
Vendor jar package name microsoft Highest
Vendor jar package name microsoft Low
Vendor jar package name webservices Low
Vendor pom artifactid ews-java-api Low
Vendor pom developer email vboctor@users.noreply.github.com Low
Vendor pom developer id vboctor Medium
Vendor pom developer name Victor Boctor Medium
Vendor pom developer org Microsoft Medium
Vendor pom developer org URL http://www.microsoft.com Medium
Vendor pom groupid com.microsoft.ews-java-api Highest
Vendor pom name Exchange Web Services Java API High
Vendor pom organization name Microsoft High
Vendor pom organization url http://www.microsoft.com/ Medium
Vendor pom url http://www.microsoft.com/ Highest
Product file name ews-java-api High
Product jar package name data Low
Product jar package name exchange Highest
Product jar package name exchange Low
Product jar package name microsoft Highest
Product jar package name webservices Low
Product pom artifactid ews-java-api Highest
Product pom developer email vboctor@users.noreply.github.com Low
Product pom developer id vboctor Low
Product pom developer name Victor Boctor Low
Product pom developer org Microsoft Low
Product pom developer org URL http://www.microsoft.com Low
Product pom groupid com.microsoft.ews-java-api Highest
Product pom name Exchange Web Services Java API High
Product pom organization name Microsoft Low
Product pom organization url http://www.microsoft.com/ Low
Product pom url http://www.microsoft.com/ Medium
Version file version 2.0 High
Version pom version 2.0 Highest
pkg:maven/com.microsoft.ews-java-api/ews-java-api@2.0
(Confidence :High)
cpe:2.3:a:microsoft:exchange:2.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
email-ews-connector-0.9.13.war: failureaccess-1.0.1.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes is conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.1 High
Version Manifest Bundle-Version 1.0.1 High
Version pom parent-version 1.0.1 Low
Version pom version 1.0.1 Highest
pkg:maven/com.google.guava/failureaccess@1.0.1
(Confidence :High)
email-ews-connector-0.9.13.war: guava-32.1.1-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/guava-32.1.1-jre.jar
MD5: 55870c9a31bf9ba2815f252a93ab0850
SHA1: ad575652d84153075dd41ec6177ccb15251262b2
SHA256: 91fbba37f1c8b251cf9ea9e7d3a369eb79eb1e6a5df1d4bbf483dd0380740281
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version pom version 32.1.1-jre Highest
email-ews-connector-0.9.13.war: httpclient-4.4.1.jar
Description:
Apache HttpComponents Client
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/httpclient-4.4.1.jar
MD5: 38f9399922142fc9538d690dbaae7e2e
SHA1: 016d0bc512222f1253ee6b64d389c84e22f697f0
SHA256: b2958ffb74f691e108abe69af0002ccff90ba326420596b1aab5bb0f63c31ef9
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name httpclient High
Vendor jar package name apache Highest
Vendor jar package name client Highest
Vendor jar package name httpclient Highest
Vendor Manifest implementation-build tags/4.4.1-RC1/httpclient@r1668921; 2015-03-24 16:41:37+0100 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest url http://hc.apache.org/httpcomponents-client Low
Vendor pom artifactid httpclient Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpClient High
Vendor pom parent-artifactid httpcomponents-client Low
Vendor pom url http://hc.apache.org/httpcomponents-client Highest
Product file name httpclient High
Product jar package name apache Highest
Product jar package name client Highest
Product jar package name http Highest
Product jar package name httpclient Highest
Product Manifest implementation-build tags/4.4.1-RC1/httpclient@r1668921; 2015-03-24 16:41:37+0100 Low
Product Manifest Implementation-Title HttpComponents Apache HttpClient High
Product Manifest specification-title HttpComponents Apache HttpClient Medium
Product Manifest url http://hc.apache.org/httpcomponents-client Low
Product pom artifactid httpclient Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpClient High
Product pom parent-artifactid httpcomponents-client Medium
Product pom url http://hc.apache.org/httpcomponents-client Medium
Version file version 4.4.1 High
Version Manifest Implementation-Version 4.4.1 High
Version pom version 4.4.1 Highest
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9%40%3Cdev.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457%40%3Cdev.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303%40%3Cgitbox.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89%40%3Cdev.jackrabbit.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d%40%3Ccommits.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381%40%3Ccommits.turbine.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8%40%3Csolr-user.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17%40%3Cdev.jackrabbit.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587%40%3Cissues.maven.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4%40%3Cgitbox.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3%40%3Cissues.lucene.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1%40%3Ccommits.creadur.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624%40%3Cissues.solr.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3%40%3Cissues.hive.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://priyankn.github.io/2021-02-26-CVE-2020-13956/
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security@apache.org - https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9%40%3Cdev.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457%40%3Cdev.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303%40%3Cgitbox.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89%40%3Cdev.jackrabbit.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90%40%3Cissues.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d%40%3Ccommits.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec%40%3Cissues.bookkeeper.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381%40%3Ccommits.turbine.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8%40%3Csolr-user.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17%40%3Cdev.jackrabbit.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587%40%3Cissues.maven.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4%40%3Cgitbox.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858%40%3Cissues.hive.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625%40%3Cissues.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917%40%3Cdev.drill.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca%40%3Cissues.bookkeeper.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3%40%3Cissues.lucene.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f%40%3Cdev.ranger.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1%40%3Ccommits.creadur.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624%40%3Cissues.solr.apache.org%3E
security@apache.org - https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3%40%3Cissues.hive.apache.org%3E
security@apache.org - MAILING_LIST,VENDOR_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - PATCH,THIRD_PARTY_ADVISORY
security@apache.org - THIRD_PARTY_ADVISORY
security@apache.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
email-ews-connector-0.9.13.war: httpcore-4.4.1.jar
Description:
Apache HttpComponents Core (blocking I/O)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/httpcore-4.4.1.jar
MD5: 27bf6d5323a86a6115b607ce82512d6c
SHA1: f5aa318bda4c6c8d688c9d00b90681dcd82ce636
SHA256: dd1390c17d40f760f7e51bb20523a8d63deb69e94babeaf567eb76ecd2cad422
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name httpcore High
Vendor jar package name apache Highest
Vendor Manifest implementation-build tags/4.4.1-RC1/httpcore@r1666708; 2015-03-14 17:26:58+0100 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Vendor pom artifactid httpcore Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpCore High
Vendor pom parent-artifactid httpcomponents-core Low
Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest
Product file name httpcore High
Product jar package name apache Highest
Product jar package name http Highest
Product Manifest implementation-build tags/4.4.1-RC1/httpcore@r1666708; 2015-03-14 17:26:58+0100 Low
Product Manifest Implementation-Title HttpComponents Apache HttpCore High
Product Manifest specification-title HttpComponents Apache HttpCore Medium
Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Product pom artifactid httpcore Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpCore High
Product pom parent-artifactid httpcomponents-core Medium
Product pom url http://hc.apache.org/httpcomponents-core-ga Medium
Version file version 4.4.1 High
Version Manifest Implementation-Version 4.4.1 High
Version pom version 4.4.1 Highest
pkg:maven/org.apache.httpcomponents/httpcore@4.4.1
(Confidence :High)
email-ews-connector-0.9.13.war: jackson-core-2.18.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jackson-core-2.18.1.jar
MD5: 74983885c7bd1f9aaa3935115fd1dd3f
SHA1: 9e2284c539e2dedd2aa1487c781e20a0f575d695
SHA256: ebe19596ad19f7a0514c8bb8f7b0acf85239a4eff5ae03229e9760d268d29c22
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.18.1 High
Version Manifest Bundle-Version 2.18.1 High
Version Manifest Implementation-Version 2.18.1 High
Version pom version 2.18.1 Highest
Related Dependencies
email-ews-connector-0.9.13.war: jackson-annotations-2.18.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jackson-annotations-2.18.1.jar
MD5: 0e6e6d0e87b374c710d29188c9c0c512
SHA1: 8f9aa97e7fb44d4bea829061625472b0f6199923
SHA256: b7f9df5dac9a85f47fdb2769455ee8ba9cf2fe9b7c4cf636e0aec83479d7882f
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.18.1
email-ews-connector-0.9.13.war: jackson-databind-2.18.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jackson-databind-2.18.1.jar
MD5: 4d5e91d0c1171c388cb87ee034e08c1c
SHA1: 66547d0c6c2f9e022019499308f09bebbf30ab2e
SHA256: 711bc3bf86d31d02968b9279efb07a6ad60adfc0baa0e9fe66d71a0ac2556234
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.18.1 High
Version Manifest Bundle-Version 2.18.1 High
Version Manifest Implementation-Version 2.18.1 High
Version pom version 2.18.1 Highest
email-ews-connector-0.9.13.war: jackson-dataformat-yaml-2.18.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jackson-dataformat-yaml-2.18.1.jar
MD5: eb5387d4d9c396cfefe693d8972c2dde
SHA1: 71bf4432cc97bb989b3d5356a96aa2efdaa26d74
SHA256: b764452d6cdd644666bba2da35ef8e6dfb86b7a59d24d1d98ea2fcf1e6bb08b2
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.18.1 High
Version Manifest Bundle-Version 2.18.1 High
Version Manifest Implementation-Version 2.18.1 High
Version pom version 2.18.1 Highest
email-ews-connector-0.9.13.war: jackson-datatype-jsr310-2.18.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jackson-datatype-jsr310-2.18.1.jar
MD5: 79baf26e20f83f63153459cc4fb89a7b
SHA1: 36e49c07197395164d50df4b8ed17f5fc05430f0
SHA256: 6f79c87613bd00b1ffdebc78d235cb9f3dcd761977fbf87c1b77017828ae895f
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.18.1 High
Version Manifest Bundle-Version 2.18.1 High
Version Manifest Implementation-Version 2.18.1 High
Version pom version 2.18.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.18.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
email-ews-connector-0.9.13.war: jakarta.activation-api-2.1.0.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jakarta.activation-api-2.1.0.jar
MD5: 7c79641566f97305e17c5f7b9bb33fc3
SHA1: a58861b5deac5e151140511cf57d6b80a83f2d20
SHA256: 56e8d994095fe49c28138c60291482f66f18d12ac2b720e938697dce6a3135c7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 0766560 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/jaf Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 0766560 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/jaf High
Version file version 2.1.0 High
Version Manifest Bundle-Version 2.1.0 High
Version pom parent-version 2.1.0 Low
Version pom version 2.1.0 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.0
(Confidence :High)
email-ews-connector-0.9.13.war: jakarta.xml.bind-api-4.0.0.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.0.jar
MD5: b5132a66e2d3a60904f8035a1f8a34a8
SHA1: bbb399208d288b15ec101fa4fcfc4bd77cedc97a
SHA256: 57e3796ad5753640088f5f9d3c53c183f2c250b7dad90529ea3e19a5515aa122
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id 7e887b2 Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id 7e887b2 Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.0 High
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.0
(Confidence :High)
email-ews-connector-0.9.13.war: javax.activation-api-1.2.0.jar
Description:
JavaBeans Activation Framework API jar
License:
https://github.com/javaee/activation/blob/master/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/javax.activation-api-1.2.0.jar
MD5: 5e50e56bcf4a3ef3bc758f69f7643c3b
SHA1: 85262acf3ca9816f9537ca47d5adeabaead7cb16
SHA256: 43fdef0b5b6ceb31b0424b208b930c74ab58fac2ceeb7b3f6fd3aeb8b5ca4393
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name javax.activation-api High
Vendor jar package name activation Highest
Vendor jar package name javax Highest
Vendor Manifest automatic-module-name java.activation Medium
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname javax.activation-api Medium
Vendor Manifest extension-name javax.activation Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low
Vendor Manifest specification-vendor Oracle Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor Manifest (hint) specification-vendor sun Low
Vendor pom artifactid javax.activation-api Low
Vendor pom groupid javax.activation Highest
Vendor pom name JavaBeans Activation Framework API jar High
Vendor pom parent-artifactid all Low
Vendor pom parent-groupid com.sun.activation Medium
Product file name javax.activation-api High
Product jar package name activation Highest
Product jar package name javax Highest
Product Manifest automatic-module-name java.activation Medium
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name JavaBeans Activation Framework API jar Medium
Product Manifest bundle-symbolicname javax.activation-api Medium
Product Manifest extension-name javax.activation Medium
Product Manifest Implementation-Title javax.activation.javax.activation-api High
Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low
Product Manifest specification-title javax.activation.javax.activation-api Medium
Product pom artifactid javax.activation-api Highest
Product pom groupid javax.activation Highest
Product pom name JavaBeans Activation Framework API jar High
Product pom parent-artifactid all Medium
Product pom parent-groupid com.sun.activation Medium
Version file version 1.2.0 High
Version Manifest Bundle-Version 1.2.0 High
Version Manifest Implementation-Version 1.2.0 High
Version pom version 1.2.0 Highest
pkg:maven/javax.activation/javax.activation-api@1.2.0
(Confidence :High)
email-ews-connector-0.9.13.war: javax.annotation-api-1.3.2.jar
Description:
Common Annotations for the JavaTM Platform API
License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.annotation/blob/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/javax.annotation-api-1.3.2.jar
MD5: 2ab1973eefffaa2aeec47d50b9e40b9d
SHA1: 934c04d3cfef185a8008e7bf34331b79730a9d43
SHA256: e04ba5195bcd555dc95650f7cc614d151e4bcd52d29a10b8aa2197f3ab89ab9b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name javax.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name javax Highest
Vendor Manifest automatic-module-name java.annotation Medium
Vendor Manifest bundle-docurl https://javaee.github.io/glassfish Low
Vendor Manifest bundle-symbolicname javax.annotation-api Medium
Vendor Manifest extension-name javax.annotation Medium
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid javax.annotation-api Low
Vendor pom developer id ldemichiel Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid javax.annotation Highest
Vendor pom name API High
Vendor pom organization name GlassFish Community High
Vendor pom organization url https://javaee.github.io/glassfish Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest
Product file name javax.annotation-api High
Product jar package name annotation Highest
Product jar package name javax Highest
Product Manifest automatic-module-name java.annotation Medium
Product Manifest bundle-docurl https://javaee.github.io/glassfish Low
Product Manifest Bundle-Name javax.annotation API Medium
Product Manifest bundle-symbolicname javax.annotation-api Medium
Product Manifest extension-name javax.annotation Medium
Product pom artifactid javax.annotation-api Highest
Product pom developer id ldemichiel Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid javax.annotation Highest
Product pom name API High
Product pom organization name GlassFish Community Low
Product pom organization url https://javaee.github.io/glassfish Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url http://jcp.org/en/jsr/detail?id=250 Medium
Version file version 1.3.2 High
Version Manifest Bundle-Version 1.3.2 High
Version Manifest Implementation-Version 1.3.2 High
Version pom parent-version 1.3.2 Low
Version pom version 1.3.2 Highest
pkg:maven/javax.annotation/javax.annotation-api@1.3.2
(Confidence :High)
email-ews-connector-0.9.13.war: javax.xml.soap-api-1.4.0.jar
Description:
SAAJ API
License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.xml.soap/blob/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/javax.xml.soap-api-1.4.0.jar
MD5: fb8bbe2cdda8ff7bd945fcb9f0f6b61c
SHA1: 667ef2eee594ca7e05a1cbe0b37a428f7b57778f
SHA256: 141374e33be99768611a2d42b9d33571a0c5b9763beca9c2dc90900d8cc8f767
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name javax.xml.soap-api High
Vendor jar package name javax Highest
Vendor jar package name soap Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname javax.xml.soap-api Medium
Vendor Manifest extension-name javax.xml.soap Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom artifactid javax.xml.soap-api Low
Vendor pom developer id jungicz Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer org Oracle, Inc. Medium
Vendor pom groupid javax.xml.soap Highest
Vendor pom name API High
Vendor pom organization name Oracle High
Vendor pom organization url http://www.oracle.com Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url https://javaee.github.io/javaee-spec/ Highest
Vendor pom (hint) organization name sun High
Product file name javax.xml.soap-api High
Product jar package name javax Highest
Product jar package name soap Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name javax.xml.soap API Medium
Product Manifest bundle-symbolicname javax.xml.soap-api Medium
Product Manifest extension-name javax.xml.soap Medium
Product pom artifactid javax.xml.soap-api Highest
Product pom developer id jungicz Low
Product pom developer name Lukas Jungmann Low
Product pom developer org Oracle, Inc. Low
Product pom groupid javax.xml.soap Highest
Product pom name API High
Product pom organization name Oracle Low
Product pom organization url http://www.oracle.com Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url https://javaee.github.io/javaee-spec/ Medium
Version file version 1.4.0 High
Version Manifest Bundle-Version 1.4.0 High
Version Manifest Implementation-Version 1.4.0 High
Version pom parent-version 1.4.0 Low
Version pom version 1.4.0 Highest
pkg:maven/javax.xml.soap/javax.xml.soap-api@1.4.0
(Confidence :High)
email-ews-connector-0.9.13.war: jaxb-api-2.3.1.jar
Description:
JAXB (JSR 222) API
License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256: 88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-api High
Vendor jar package name bind Highest
Vendor jar package name javax Highest
Vendor jar package name jaxb Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://www.oracle.com/ Low
Vendor Manifest bundle-symbolicname jaxb-api Medium
Vendor Manifest extension-name javax.xml.bind Medium
Vendor Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jaxb-api Low
Vendor pom groupid javax.xml.bind Highest
Vendor pom parent-artifactid jaxb-api-parent Low
Product file name jaxb-api High
Product jar package name bind Highest
Product jar package name javax Highest
Product jar package name jaxb Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://www.oracle.com/ Low
Product Manifest Bundle-Name jaxb-api Medium
Product Manifest bundle-symbolicname jaxb-api Medium
Product Manifest extension-name javax.xml.bind Medium
Product Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low
Product Manifest multi-release true Low
Product Manifest specification-title jaxb-api Medium
Product pom artifactid jaxb-api Highest
Product pom groupid javax.xml.bind Highest
Product pom parent-artifactid jaxb-api-parent Medium
Version file version 2.3.1 High
Version Manifest Bundle-Version 2.3.1 High
Version pom version 2.3.1 Highest
pkg:maven/javax.xml.bind/jaxb-api@2.3.1
(Confidence :High)
email-ews-connector-0.9.13.war: jaxws-api-2.3.1.jar
Description:
JAX-WS (JSR 224) API
License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/jax-ws-spec/blob/master/LICENSE.md
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jaxws-api-2.3.1.jar
MD5: 5a6f94e95cc2054bc840cc2f2fedc5d8
SHA1: 15e46dba25b1f767a3f517721badf6cce8dbb13d
SHA256: a447f84f95658ea68b347acffe156f7700c62a37ede15d81e5298fb8e5fe6dcf
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxws-api High
Vendor hint analyzer vendor web services Medium
Vendor jar package name javax Highest
Vendor jar package name ws Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom artifactid jaxws-api Low
Vendor pom developer email jitendra.kotamraju@oracle.com Low
Vendor pom developer email lukas.jungmann@oracle.com Low
Vendor pom developer email martin.grebac@oracle.com Low
Vendor pom developer name Jitendra Kotamraju Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer name Martin Grebac Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom groupid javax.xml.ws Highest
Vendor pom name JAX-WS API High
Vendor pom organization name Oracle High
Vendor pom organization url http://www.oracle.com Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url javaee/jax-ws-spec Highest
Vendor pom (hint) organization name sun High
Product file name jaxws-api High
Product hint analyzer product web services Medium
Product jar package name http Highest
Product jar package name javax Highest
Product jar package name ws Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name JAX-WS API Medium
Product Manifest bundle-symbolicname Medium
Product pom artifactid jaxws-api Highest
Product pom developer email jitendra.kotamraju@oracle.com Low
Product pom developer email lukas.jungmann@oracle.com Low
Product pom developer email martin.grebac@oracle.com Low
Product pom developer name Jitendra Kotamraju Low
Product pom developer name Lukas Jungmann Low
Product pom developer name Martin Grebac Low
Product pom developer org Oracle Corporation Low
Product pom groupid javax.xml.ws Highest
Product pom name JAX-WS API High
Product pom organization name Oracle Low
Product pom organization url http://www.oracle.com Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url javaee/jax-ws-spec High
Version file version 2.3.1 High
Version pom parent-version 2.3.1 Low
Version pom version 2.3.1 Highest
pkg:maven/javax.xml.ws/jaxws-api@2.3.1
(Confidence :High)
cpe:2.3:a:oracle:web_services:2.3.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
email-ews-connector-0.9.13.war: jcip-annotations-1.0-1.jar
Description:
A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256: 4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jcip-annotations High
Vendor jar package name annotations Highest
Vendor jar package name annotations Low
Vendor jar package name jcip Highest
Vendor jar package name jcip Low
Vendor jar package name net Low
Vendor pom artifactid jcip-annotations Low
Vendor pom developer id stephenc Medium
Vendor pom developer name Stephen Connolly Medium
Vendor pom groupid com.github.stephenc.jcip Highest
Vendor pom name JCIP Annotations under Apache License High
Vendor pom url http://stephenc.github.com/jcip-annotations Highest
Product file name jcip-annotations High
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name jcip Highest
Product jar package name jcip Low
Product pom artifactid jcip-annotations Highest
Product pom developer id stephenc Low
Product pom developer name Stephen Connolly Low
Product pom groupid com.github.stephenc.jcip Highest
Product pom name JCIP Annotations under Apache License High
Product pom url http://stephenc.github.com/jcip-annotations Medium
Version pom version 1.0-1 Highest
pkg:maven/com.github.stephenc.jcip/jcip-annotations@1.0-1
(Confidence :High)
email-ews-connector-0.9.13.war: joda-time-2.8.jar
Description:
Date and time library to replace JDK date handling
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/joda-time-2.8.jar
MD5: 4c17df2ad20161112283dbe6475e70d2
SHA1: 9f2785d7184b97d005a44241ccaf980f43b9ccdb
SHA256: 55ae8d6baf406ccfec88cc444de4a452c5725859b70a076ba50a7a7b75f68ed1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name joda-time High
Vendor jar package name joda Highest
Vendor jar package name time Highest
Vendor Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Vendor Manifest bundle-symbolicname joda-time Medium
Vendor Manifest extension-name joda-time Medium
Vendor Manifest implementation-url http://www.joda.org/joda-time/ Low
Vendor Manifest Implementation-Vendor Joda.org High
Vendor Manifest Implementation-Vendor-Id org.joda Medium
Vendor Manifest specification-vendor Joda.org Low
Vendor pom artifactid joda-time Low
Vendor pom developer id broneill Medium
Vendor pom developer id jodastephen Medium
Vendor pom developer name Brian S O'Neill Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom groupid joda-time Highest
Vendor pom name Joda-Time High
Vendor pom organization name Joda.org High
Vendor pom organization url http://www.joda.org Medium
Vendor pom url http://www.joda.org/joda-time/ Highest
Product file name joda-time High
Product jar package name joda Highest
Product jar package name time Highest
Product Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Product Manifest Bundle-Name Joda-Time Medium
Product Manifest bundle-symbolicname joda-time Medium
Product Manifest extension-name joda-time Medium
Product Manifest Implementation-Title org.joda.time High
Product Manifest implementation-url http://www.joda.org/joda-time/ Low
Product Manifest specification-title Joda-Time Medium
Product pom artifactid joda-time Highest
Product pom developer id broneill Low
Product pom developer id jodastephen Low
Product pom developer name Brian S O'Neill Low
Product pom developer name Stephen Colebourne Low
Product pom groupid joda-time Highest
Product pom name Joda-Time High
Product pom organization name Joda.org Low
Product pom organization url http://www.joda.org Low
Product pom url http://www.joda.org/joda-time/ Medium
Version file version 2.8 High
Version Manifest Bundle-Version 2.8 High
Version Manifest Implementation-Version 2.8 High
Version pom version 2.8 Highest
pkg:maven/joda-time/joda-time@2.8
(Confidence :High)
email-ews-connector-0.9.13.war: json-smart-2.5.2.jar
Description:
JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but uses conventions that are familiar to programmers of the C-family of languages, including C, C++, C#, Java, JavaScript, Perl, Python, and many others. These properties make JSON an ideal data-interchange language.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/json-smart-2.5.2.jar
MD5: e3ad34c55c0d2627255f79f4411c6bdd
SHA1: 95d166b18f95907be0f46cdb9e1c0695eed03387
SHA256: 4fbdedb0105cedc7f766b95c297d2e88fb6a560da48f3bbaa0cc538ea8b7bf71
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name json-smart High
Vendor jar package name json Highest
Vendor jar package name minidev Highest
Vendor jar package name net Highest
Vendor jar package name parser Highest
Vendor Manifest build-jdk-spec 23 Low
Vendor Manifest bundle-docurl https://urielch.github.io/ Low
Vendor Manifest bundle-symbolicname net.minidev.json-smart Medium
Vendor pom artifactid json-smart Low
Vendor pom developer email adoneitan@gmail.com Low
Vendor pom developer email hezhangjian97gmail.com Low
Vendor pom developer email uchemouni@gmail.com Low
Vendor pom developer id erav Medium
Vendor pom developer id hezhangjian Medium
Vendor pom developer id uriel Medium
Vendor pom developer name Eitan Raviv Medium
Vendor pom developer name Uriel Chemouni Medium
Vendor pom developer name Zhangjian He Medium
Vendor pom groupid net.minidev Highest
Vendor pom name JSON Small and Fast Parser High
Vendor pom organization name Chemouni Uriel High
Vendor pom organization url https://urielch.github.io/ Medium
Vendor pom url https://urielch.github.io/ Highest
Product file name json-smart High
Product jar package name json Highest
Product jar package name minidev Highest
Product jar package name net Highest
Product jar package name parser Highest
Product Manifest build-jdk-spec 23 Low
Product Manifest bundle-docurl https://urielch.github.io/ Low
Product Manifest Bundle-Name json-smart Medium
Product Manifest bundle-symbolicname net.minidev.json-smart Medium
Product pom artifactid json-smart Highest
Product pom developer email adoneitan@gmail.com Low
Product pom developer email hezhangjian97gmail.com Low
Product pom developer email uchemouni@gmail.com Low
Product pom developer id erav Low
Product pom developer id hezhangjian Low
Product pom developer id uriel Low
Product pom developer name Eitan Raviv Low
Product pom developer name Uriel Chemouni Low
Product pom developer name Zhangjian He Low
Product pom groupid net.minidev Highest
Product pom name JSON Small and Fast Parser High
Product pom organization name Chemouni Uriel Low
Product pom organization url https://urielch.github.io/ Low
Product pom url https://urielch.github.io/ Medium
Version file version 2.5.2 High
Version Manifest Bundle-Version 2.5.2 High
Version pom version 2.5.2 Highest
email-ews-connector-0.9.13.war: jsoup-1.18.1.jar
Description:
jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers.
License:
The MIT License: https://jsoup.org/license
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jsoup-1.18.1.jar
MD5: d39a0c88a28969d13707b95e035d9442
SHA1: cb7cd991d47b44101cbe4655dec611cdc01f8a02
SHA256: 3bb5b0ec02998abe45a51f37d7ce67c3068b4ccd4ab63c965929ec5074d64e91
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsoup High
Vendor jar package name jsoup Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://jsoup.org/ Low
Vendor Manifest bundle-symbolicname org.jsoup Medium
Vendor Manifest Implementation-Vendor Jonathan Hedley High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor pom artifactid jsoup Low
Vendor pom developer email jonathan@hedley.net Low
Vendor pom developer id jhy Medium
Vendor pom developer name Jonathan Hedley Medium
Vendor pom groupid org.jsoup Highest
Vendor pom name jsoup Java HTML Parser High
Vendor pom organization name Jonathan Hedley High
Vendor pom organization url https://jhy.io/ Medium
Vendor pom url https://jsoup.org/ Highest
Product file name jsoup High
Product jar package name 9 Highest
Product jar package name jsoup Highest
Product jar package name org Highest
Product jar package name parser Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://jsoup.org/ Low
Product Manifest Bundle-Name jsoup Java HTML Parser Medium
Product Manifest bundle-symbolicname org.jsoup Medium
Product Manifest Implementation-Title jsoup Java HTML Parser High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product pom artifactid jsoup Highest
Product pom developer email jonathan@hedley.net Low
Product pom developer id jhy Low
Product pom developer name Jonathan Hedley Low
Product pom groupid org.jsoup Highest
Product pom name jsoup Java HTML Parser High
Product pom organization name Jonathan Hedley Low
Product pom organization url https://jhy.io/ Low
Product pom url https://jsoup.org/ Medium
Version file version 1.18.1 High
Version Manifest Bundle-Version 1.18.1 High
Version Manifest Implementation-Version 1.18.1 High
Version pom version 1.18.1 Highest
email-ews-connector-0.9.13.war: jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
email-ews-connector-0.9.13.war: lang-tag-1.7.jar
Description:
Java implementation of "Tags for Identifying Languages" (RFC 5646)
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/lang-tag-1.7.jar
MD5: 31b8a4f76fdbf21f1d667f9d6618e0b2
SHA1: 97c73ecd70bc7e8eefb26c5eea84f251a63f1031
SHA256: e8c1c594e2425bdbea2d860de55c69b69fc5d59454452449a0f0913c2a5b8a31
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name lang-tag High
Vendor jar package name langtag Highest
Vendor jar package name nimbusds Highest
Vendor Manifest build-date ${timestamp} Low
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest build-number ${buildNumber} Low
Vendor Manifest build-tag 1.7 Low
Vendor Manifest bundle-docurl https://connect2id.com/ Low
Vendor Manifest bundle-symbolicname lang-tag Medium
Vendor Manifest Implementation-Vendor Connect2id Ltd. High
Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium
Vendor Manifest specification-vendor Connect2id Ltd. Low
Vendor pom artifactid lang-tag Low
Vendor pom developer email vladimir@dzhuvinov.com Low
Vendor pom developer id vdzhuvinov Medium
Vendor pom developer name Vladimir Dzhuvinov Medium
Vendor pom groupid com.nimbusds Highest
Vendor pom name Nimbus LangTag High
Vendor pom organization name Connect2id Ltd. High
Vendor pom organization url https://connect2id.com/ Medium
Vendor pom url https://bitbucket.org/connect2id/nimbus-language-tags Highest
Product file name lang-tag High
Product jar package name langtag Highest
Product jar package name nimbusds Highest
Product Manifest build-date ${timestamp} Low
Product Manifest build-jdk-spec 11 Low
Product Manifest build-number ${buildNumber} Low
Product Manifest build-tag 1.7 Low
Product Manifest bundle-docurl https://connect2id.com/ Low
Product Manifest Bundle-Name Nimbus LangTag Medium
Product Manifest bundle-symbolicname lang-tag Medium
Product Manifest Implementation-Title Nimbus LangTag High
Product Manifest specification-title Nimbus LangTag Medium
Product pom artifactid lang-tag Highest
Product pom developer email vladimir@dzhuvinov.com Low
Product pom developer id vdzhuvinov Low
Product pom developer name Vladimir Dzhuvinov Low
Product pom groupid com.nimbusds Highest
Product pom name Nimbus LangTag High
Product pom organization name Connect2id Ltd. Low
Product pom organization url https://connect2id.com/ Low
Product pom url https://bitbucket.org/connect2id/nimbus-language-tags Medium
Version file version 1.7 High
Version Manifest build-tag 1.7 Low
Version Manifest Implementation-Version 1.7 High
Version pom version 1.7 Highest
pkg:maven/com.nimbusds/lang-tag@1.7
(Confidence :High)
email-ews-connector-0.9.13.war: ms-oauth2-token-provider-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/ms-oauth2-token-provider-0.9.5.jar
MD5: 44d9d66ff794d9bd93026ebea325b4f9
SHA1: 7b04c17bb6bd8a63885f0b7cadac77023be5d8fe
SHA256: 745075c3a8cf33ecac3e3d2b746656fb062725016561d617595f7e06cce6c4ad
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name ms-oauth2-token-provider High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name ms-oauth2-token-provider High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name ms-oauth2-token-provider Medium
Version file version 0.9.5 High
email-ews-connector-0.9.13.war: msal4j-1.22.0.jar
Description:
Microsoft Authentication Library for Java gives you the ability to obtain tokens from Microsoft Entra (work and
school accounts, MSA) and Azure AD B2C, gaining access to Microsoft Cloud API and any other API secured by Microsoft
identities
License:
MIT License
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/msal4j-1.22.0.jar
MD5: fa330912b0df54a12095370a2c3d9cc8
SHA1: f8ae704ee28af7678e3f4ea21fc55660c1f116ab
SHA256: c70f36d6342c8914de95a63268f6789d88d8f6697e57e2e79a767041288af9d3
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name msal4j High
Vendor jar package name aad Highest
Vendor jar package name microsoft Highest
Vendor jar package name msal4j Highest
Vendor Manifest automatic-module-name com.microsoft.aad.msal4j Medium
Vendor Manifest bundle-developers msopentech;name="Microsoft Open Technologies, Inc." Low
Vendor Manifest bundle-docurl https://github.com/AzureAD/microsoft-authentication-library-for-java Low
Vendor Manifest bundle-symbolicname msal4j Medium
Vendor Manifest Implementation-Vendor-Id com.microsoft.azure Medium
Vendor pom artifactid msal4j Low
Vendor pom developer id msopentech Medium
Vendor pom developer name Microsoft Open Technologies, Inc. Medium
Vendor pom groupid com.microsoft.azure Highest
Vendor pom name msal4j High
Vendor pom url AzureAD/microsoft-authentication-library-for-java Highest
Product file name msal4j High
Product jar package name aad Highest
Product jar package name microsoft Highest
Product jar package name msal4j Highest
Product Manifest automatic-module-name com.microsoft.aad.msal4j Medium
Product Manifest bundle-developers msopentech;name="Microsoft Open Technologies, Inc." Low
Product Manifest bundle-docurl https://github.com/AzureAD/microsoft-authentication-library-for-java Low
Product Manifest Bundle-Name msal4j Medium
Product Manifest bundle-symbolicname msal4j Medium
Product Manifest Implementation-Title msal4j High
Product Manifest specification-title msal4j Medium
Product pom artifactid msal4j Highest
Product pom developer id msopentech Low
Product pom developer name Microsoft Open Technologies, Inc. Low
Product pom groupid com.microsoft.azure Highest
Product pom name msal4j High
Product pom url AzureAD/microsoft-authentication-library-for-java High
Version file version 1.22.0 High
Version Manifest Bundle-Version 1.22.0 High
Version Manifest Implementation-Version 1.22.0 High
Version pom version 1.22.0 Highest
pkg:maven/com.microsoft.azure/msal4j@1.22.0
(Confidence :High)
cpe:2.3:a:microsoft:authentication_library:1.22.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2024-35255 suppress
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
email-ews-connector-0.9.13.war: nimbus-jose-jwt-10.0.2.jar (shaded: com.google.code.gson:gson:2.12.1)
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/nimbus-jose-jwt-10.0.2.jar/META-INF/maven/com.google.code.gson/gson/pom.xml
MD5: 54205b633e8a676f5bb25c188631c854
SHA1: d2c3993ff96e5da39a57e5e0b695eda560949b57
SHA256: 0b5735ec85f45282f1e2c769779800427b150a8163f405093a9280b71cab1978
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid gson Low
Vendor pom groupid com.google.code.gson Highest
Vendor pom name Gson High
Vendor pom parent-artifactid gson-parent Low
Product pom artifactid gson Highest
Product pom groupid com.google.code.gson Highest
Product pom name Gson High
Product pom parent-artifactid gson-parent Medium
Version pom version 2.12.1 Highest
email-ews-connector-0.9.13.war: nimbus-jose-jwt-10.0.2.jar
Description:
Java library for Javascript Object Signing and Encryption (JOSE) and
JSON Web Tokens (JWT)
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/nimbus-jose-jwt-10.0.2.jar
MD5: 98ebb498f6bbcee1049de8a64ff7c52c
SHA1: 93347ea9247ae09e095575e10f9cae79c195fbb8
SHA256: 960b978a6cd6cbc3319648adc73959789f6742a2bf1e8dd0c843dbc91624218a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name nimbus-jose-jwt High
Vendor jar package name jose Highest
Vendor jar package name jwt Highest
Vendor jar package name nimbusds Highest
Vendor Manifest automatic-module-name com.nimbusds.jose.jwt Medium
Vendor Manifest build-date ${timestamp} Low
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest build-number ${buildNumber} Low
Vendor Manifest build-tag 10.0.2 Low
Vendor Manifest bundle-docurl https://connect2id.com Low
Vendor Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium
Vendor Manifest Implementation-Vendor Connect2id Ltd. High
Vendor Manifest specification-vendor Connect2id Ltd. Low
Vendor pom artifactid nimbus-jose-jwt Low
Vendor pom developer email vladimir@dzhuvinov.com Low
Vendor pom developer id vdzhuvinov Medium
Vendor pom developer name Vladimir Dzhuvinov Medium
Vendor pom groupid com.nimbusds Highest
Vendor pom name Nimbus JOSE+JWT High
Vendor pom organization name Connect2id Ltd. High
Vendor pom organization url https://connect2id.com Medium
Vendor pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Highest
Product file name nimbus-jose-jwt High
Product jar package name jose Highest
Product jar package name jwt Highest
Product jar package name nimbusds Highest
Product Manifest automatic-module-name com.nimbusds.jose.jwt Medium
Product Manifest build-date ${timestamp} Low
Product Manifest build-jdk-spec 17 Low
Product Manifest build-number ${buildNumber} Low
Product Manifest build-tag 10.0.2 Low
Product Manifest bundle-docurl https://connect2id.com Low
Product Manifest Bundle-Name Nimbus JOSE+JWT Medium
Product Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium
Product Manifest Implementation-Title Nimbus JOSE+JWT High
Product Manifest specification-title Nimbus JOSE+JWT Medium
Product pom artifactid nimbus-jose-jwt Highest
Product pom developer email vladimir@dzhuvinov.com Low
Product pom developer id vdzhuvinov Low
Product pom developer name Vladimir Dzhuvinov Low
Product pom groupid com.nimbusds Highest
Product pom name Nimbus JOSE+JWT High
Product pom organization name Connect2id Ltd. Low
Product pom organization url https://connect2id.com Low
Product pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Medium
Version file version 10.0.2 High
Version Manifest build-tag 10.0.2 Low
Version Manifest Bundle-Version 10.0.2 High
Version Manifest Implementation-Version 10.0.2 High
Version pom version 10.0.2 Highest
email-ews-connector-0.9.13.war: oauth2-oidc-sdk-11.23.1.jar
Description:
OAuth 2.0 SDK with OpenID Connection extensions for developing client
and server applications.
License:
Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/oauth2-oidc-sdk-11.23.1.jar
MD5: 23640d70aa30f448060c229f6344d8e2
SHA1: 17facb3e3fa9e048f87b34c706e1163cad660e6d
SHA256: 170303aec2fd3974a14f1edc940e40d334b33fa2a9c3e206b9d2aa12d23d5428
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name oauth2-oidc-sdk High
Vendor jar package name client Highest
Vendor jar package name connect Highest
Vendor jar package name nimbusds Highest
Vendor jar package name oauth2 Highest
Vendor jar package name openid Highest
Vendor jar package name sdk Highest
Vendor Manifest build-date 20250226.102144.957 Low
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest build-number e47b0caef2f607e6620537077360f8e382dccb3b Low
Vendor Manifest build-tag 11.23.1 Low
Vendor Manifest bundle-developers vdzhuvinov;email="vd@connect2id.com";name="Vladimir Dzhuvinov" Low
Vendor Manifest bundle-docurl https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Low
Vendor Manifest bundle-symbolicname oauth2-oidc-sdk Medium
Vendor Manifest Implementation-Vendor Connect2id Ltd. High
Vendor Manifest specification-vendor Connect2id Ltd. Low
Vendor pom artifactid oauth2-oidc-sdk Low
Vendor pom developer email vd@connect2id.com Low
Vendor pom developer id vdzhuvinov Medium
Vendor pom developer name Vladimir Dzhuvinov Medium
Vendor pom groupid com.nimbusds Highest
Vendor pom name OAuth 2.0 SDK with OpenID Connect extensions High
Vendor pom organization name Connect2id Ltd. High
Vendor pom organization url https://connect2id.com Medium
Vendor pom url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Highest
Product file name oauth2-oidc-sdk High
Product jar package name client Highest
Product jar package name connect Highest
Product jar package name nimbusds Highest
Product jar package name oauth2 Highest
Product jar package name openid Highest
Product jar package name sdk Highest
Product Manifest build-date 20250226.102144.957 Low
Product Manifest build-jdk-spec 17 Low
Product Manifest build-number e47b0caef2f607e6620537077360f8e382dccb3b Low
Product Manifest build-tag 11.23.1 Low
Product Manifest bundle-developers vdzhuvinov;email="vd@connect2id.com";name="Vladimir Dzhuvinov" Low
Product Manifest bundle-docurl https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Low
Product Manifest Bundle-Name OAuth 2.0 SDK with OpenID Connect extensions Medium
Product Manifest bundle-symbolicname oauth2-oidc-sdk Medium
Product Manifest Implementation-Title OAuth 2.0 SDK with OpenID Connect extensions High
Product Manifest specification-title OAuth 2.0 SDK with OpenID Connect extensions Medium
Product pom artifactid oauth2-oidc-sdk Highest
Product pom developer email vd@connect2id.com Low
Product pom developer id vdzhuvinov Low
Product pom developer name Vladimir Dzhuvinov Low
Product pom groupid com.nimbusds Highest
Product pom name OAuth 2.0 SDK with OpenID Connect extensions High
Product pom organization name Connect2id Ltd. Low
Product pom organization url https://connect2id.com Low
Product pom url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Medium
Version file version 11.23.1 High
Version Manifest build-tag 11.23.1 Low
Version Manifest Bundle-Version 11.23.1 High
Version Manifest Implementation-Version 11.23.1 High
Version pom version 11.23.1 Highest
pkg:maven/com.nimbusds/oauth2-oidc-sdk@11.23.1
(Confidence :High)
email-ews-connector-0.9.13.war: oauth2-properties-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/oauth2-properties-0.9.5.jar
MD5: e7dc71b4dcd375374a88d866a320eb21
SHA1: 0ada609c6c589e7463cec6e8be2088ef8422488e
SHA256: dbe2f7155a72b16b365481537b207c27a64174e077f03f93b6ae17afcc41839d
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name oauth2-properties High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name oauth2-properties High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name oauth2-properties Medium
Version file version 0.9.5 High
email-ews-connector-0.9.13.war: snakeyaml-2.3.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/snakeyaml-2.3.jar
MD5: 2a1c2ee8923dcd6bd6d025751af5df37
SHA1: 936b36210e27320f920536f695cf1af210c44586
SHA256: 63a76fe66b652360bd4c2c107e6f0258daa7d4bb492008ba8c26fcd230ff9146
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.3 High
Version pom version 2.3 Highest
email-ews-connector-0.9.13.war: war-connector-bridge-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/war-connector-bridge-0.9.5.jar
MD5: d30d230b69cd912e0a5b520226115414
SHA1: f87d602579133c6c538e341a3891458f176c5666
SHA256: 9bc5dafd561bc7a99979f603ac5331eacd3d3c8f21f717b24fed1ff8045ec421
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 0.9.5 High
email-ews-connector-0.9.13.war: yaml-descriptor-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector.email/email-ews-connector/0.9.13/d8a79bf9b348330fb72d81d27832ef340778b2a4/email-ews-connector-0.9.13.war/WEB-INF/lib/yaml-descriptor-0.9.5.jar
MD5: 139586d6d73e3a49bd3e7fba273f0199
SHA1: 0484c4ecddab80a4c8b1a4d12667750af151e8bd
SHA256: ff7826a7641fb90aca304878bc97d505da06d971d2df3f0b272f621aeaa3abff
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 0.9.5 High
endpoints-spi-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/endpoints-spi/2.26.30/78ff72714167fc1664ab985d270b0ba3b557449b/endpoints-spi-2.26.30.jar
MD5: 9e1fa5947c6e59cfc7f386f7488df6ff
SHA1: 78ff72714167fc1664ab985d270b0ba3b557449b
SHA256: 2b9229dd34ca2bbeb1c24cb1946946a8180dc66fa379fec5e3b0ee50940d624c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
endpoints-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name endpoints-spi High
Vendor gradle artifactid endpoints-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name endpoints Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.endpoints Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid endpoints-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Endpoints SPI High
Vendor pom parent-artifactid core Low
Product file name endpoints-spi High
Product gradle artifactid endpoints-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name endpoints Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.endpoints Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid endpoints-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Endpoints SPI High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
error_prone_annotations-2.36.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.errorprone/error_prone_annotations/2.36.0/227d4d4957ccc3dc5761bd897e3a0ee587e750a7/error_prone_annotations-2.36.0.jar
MD5: 0e48e5ba2cd0a8d8d09bad849b99f6a6
SHA1: 227d4d4957ccc3dc5761bd897e3a0ee587e750a7
SHA256: 77440e270b0bc9a249903c5a076c36a722c4886ca4f42675f2903a1c53ed61a5
Referenced In Project/Scope: server-start:webapps
error_prone_annotations-2.36.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor gradle artifactid error_prone_annotations Highest
Vendor gradle groupid com.google.errorprone Highest
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product gradle artifactid error_prone_annotations Highest
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.36.0 High
Version gradle version 2.36.0 Highest
Version Manifest Bundle-Version 2.36.0 High
Version pom version 2.36.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0
(Confidence :High)
error_prone_annotations-2.40.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.errorprone/error_prone_annotations/2.40.0/81bd85ecc769f008241fa841159c3e1caa08deab/error_prone_annotations-2.40.0.jar
MD5: 636aeb43b0cda7272a924a430bad206e
SHA1: 81bd85ecc769f008241fa841159c3e1caa08deab
SHA256: bfa77e49226e9bd2ac7ac1bc4a3c70430078f2e6cd30c8e0615d6c25d8ae818d
Referenced In Project/Scope: server-start:compileClasspath
error_prone_annotations-2.40.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor gradle artifactid error_prone_annotations Highest
Vendor gradle groupid com.google.errorprone Highest
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product gradle artifactid error_prone_annotations Highest
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.40.0 High
Version gradle version 2.40.0 Highest
Version Manifest Bundle-Version 2.40.0 High
Version pom version 2.40.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.40.0
(Confidence :High)
error_prone_annotations-2.41.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.errorprone/error_prone_annotations/2.41.0/4381275efdef6ddfae38f002c31e84cd001c97f0/error_prone_annotations-2.41.0.jar
MD5: 75e3b25da8b8a2136463c4674f5e49bf
SHA1: 4381275efdef6ddfae38f002c31e84cd001c97f0
SHA256: a56e782b5b50811ac204073a355a21d915a2107fce13ec711331ad036f660fcc
Referenced In Project/Scope: server-start:runtimeClasspath
error_prone_annotations-2.41.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor gradle artifactid error_prone_annotations Highest
Vendor gradle groupid com.google.errorprone Highest
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product gradle artifactid error_prone_annotations Highest
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.41.0 High
Version gradle version 2.41.0 Highest
Version Manifest Bundle-Version 2.41.0 High
Version pom version 2.41.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.41.0
(Confidence :High)
eventstream-1.0.1.jar
Description:
The AWS Event Stream decoder library.
License:
Apache License, Version 2.0: https://aws.amazon.com/apache2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.eventstream/eventstream/1.0.1/6ff8649dffc5190366ada897ba8525a836297784/eventstream-1.0.1.jar
MD5: 864488626f50477cfd786d1c80e3b39e
SHA1: 6ff8649dffc5190366ada897ba8525a836297784
SHA256: 0c37d8e696117f02c302191b8110b0d0eb20fa412fce34c3a269ec73c16ce822
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
eventstream-1.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name eventstream High
Vendor gradle artifactid eventstream Highest
Vendor gradle groupid software.amazon.eventstream Highest
Vendor jar package name amazon Highest
Vendor jar package name eventstream Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.eventstream Medium
Vendor pom artifactid eventstream Low
Vendor pom developer id amazonwebservices Medium
Vendor pom developer org Amazon Web Services Medium
Vendor pom developer org URL https://aws.amazon.com Medium
Vendor pom groupid software.amazon.eventstream Highest
Vendor pom name AWS Event Stream High
Vendor pom url awslabs/aws-eventstream-java Highest
Product file name eventstream High
Product gradle artifactid eventstream Highest
Product jar package name amazon Highest
Product jar package name eventstream Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.eventstream Medium
Product pom artifactid eventstream Highest
Product pom developer id amazonwebservices Low
Product pom developer org Amazon Web Services Low
Product pom developer org URL https://aws.amazon.com Low
Product pom groupid software.amazon.eventstream Highest
Product pom name AWS Event Stream High
Product pom url awslabs/aws-eventstream-java High
Version file version 1.0.1 High
Version gradle version 1.0.1 Highest
Version pom version 1.0.1 Highest
pkg:maven/software.amazon.eventstream/eventstream@1.0.1
(Confidence :High)
cpe:2.3:a:amazon:amazon_web_services:1.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
ews-java-api-2.0.jar
Description:
Exchange Web Services (EWS) Java API
License:
MIT License: http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.microsoft.ews-java-api/ews-java-api/2.0/6f76a4ad706b5aa6534a48ea098b257de6b47627/ews-java-api-2.0.jar
MD5: bddb4f7875a4d3371c7bb9318436284c
SHA1: 6f76a4ad706b5aa6534a48ea098b257de6b47627
SHA256: 1319c01f9899c3174b4b49849bb92ce8db3e629786c56f733ffb62e1cd729415
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ews-java-api-2.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ews-java-api High
Vendor gradle artifactid ews-java-api Highest
Vendor gradle groupid com.microsoft.ews-java-api Highest
Vendor jar package name exchange Highest
Vendor jar package name exchange Low
Vendor jar package name microsoft Highest
Vendor jar package name microsoft Low
Vendor jar package name webservices Low
Vendor pom artifactid ews-java-api Low
Vendor pom developer email vboctor@users.noreply.github.com Low
Vendor pom developer id vboctor Medium
Vendor pom developer name Victor Boctor Medium
Vendor pom developer org Microsoft Medium
Vendor pom developer org URL http://www.microsoft.com Medium
Vendor pom groupid com.microsoft.ews-java-api Highest
Vendor pom name Exchange Web Services Java API High
Vendor pom organization name Microsoft High
Vendor pom organization url http://www.microsoft.com/ Medium
Vendor pom url http://www.microsoft.com/ Highest
Product file name ews-java-api High
Product gradle artifactid ews-java-api Highest
Product jar package name data Low
Product jar package name exchange Highest
Product jar package name exchange Low
Product jar package name microsoft Highest
Product jar package name webservices Low
Product pom artifactid ews-java-api Highest
Product pom developer email vboctor@users.noreply.github.com Low
Product pom developer id vboctor Low
Product pom developer name Victor Boctor Low
Product pom developer org Microsoft Low
Product pom developer org URL http://www.microsoft.com Low
Product pom groupid com.microsoft.ews-java-api Highest
Product pom name Exchange Web Services Java API High
Product pom organization name Microsoft Low
Product pom organization url http://www.microsoft.com/ Low
Product pom url http://www.microsoft.com/ Medium
Version file version 2.0 High
Version gradle version 2.0 Highest
Version pom version 2.0 Highest
pkg:maven/com.microsoft.ews-java-api/ews-java-api@2.0
(Confidence :High)
cpe:2.3:a:microsoft:exchange:2.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
failureaccess-1.0.1.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes is conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.guava/failureaccess/1.0.1/1dcf1de382a0bf95a3d8b0849546c88bac1292c9/failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
failureaccess-1.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor gradle artifactid failureaccess Highest
Vendor gradle groupid com.google.guava Highest
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product gradle artifactid failureaccess Highest
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.1 High
Version gradle version 1.0.1 Highest
Version Manifest Bundle-Version 1.0.1 High
Version pom parent-version 1.0.1 Low
Version pom version 1.0.1 Highest
pkg:maven/com.google.guava/failureaccess@1.0.1
(Confidence :High)
failureaccess-1.0.2.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes are conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.guava/failureaccess/1.0.2/c4a06a64e650562f30b7bf9aaec1bfed43aca12b/failureaccess-1.0.2.jar
MD5: 3f75955b49b6758fd6d1e1bd9bf777b3
SHA1: c4a06a64e650562f30b7bf9aaec1bfed43aca12b
SHA256: 8a8f81cf9b359e3f6dfa691a1e776985c061ef2f223c9b2c80753e1b458e8064
Referenced In Project/Scope: server-start:webapps
failureaccess-1.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor gradle artifactid failureaccess Highest
Vendor gradle groupid com.google.guava Highest
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest automatic-module-name com.google.common.util.concurrent.internal Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product gradle artifactid failureaccess Highest
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest automatic-module-name com.google.common.util.concurrent.internal Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.2 High
Version gradle version 1.0.2 Highest
Version Manifest Bundle-Version 1.0.2 High
Version pom parent-version 1.0.2 Low
Version pom version 1.0.2 Highest
pkg:maven/com.google.guava/failureaccess@1.0.2
(Confidence :High)
fontbox-2.0.27.jar
Description:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.pdfbox/fontbox/2.0.27/d08c064d18b2b149da937d15c0d1708cba03f29d/fontbox-2.0.27.jar
MD5: 587744efe2a82d3584c2f3969fa4dca0
SHA1: d08c064d18b2b149da937d15c0d1708cba03f29d
SHA256: dc7429868aaf3d313c524b9aab846a405e89ca4927f35762ca4d1a60bce1d7f4
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
fontbox-2.0.27.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name fontbox High
Vendor gradle artifactid fontbox Highest
Vendor gradle groupid org.apache.pdfbox Highest
Vendor jar package name apache Highest
Vendor jar package name fontbox Highest
Vendor Manifest automatic-module-name org.apache.fontbox Medium
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Vendor Manifest implementation-url http://pdfbox.apache.org/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid fontbox Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor pom name Apache FontBox High
Vendor pom parent-artifactid pdfbox-parent Low
Vendor pom url http://pdfbox.apache.org/ Highest
Product file name fontbox High
Product gradle artifactid fontbox Highest
Product jar package name apache Highest
Product jar package name fontbox Highest
Product Manifest automatic-module-name org.apache.fontbox Medium
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product Manifest Bundle-Name Apache FontBox Medium
Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Product Manifest Implementation-Title Apache FontBox High
Product Manifest implementation-url http://pdfbox.apache.org/ Low
Product Manifest specification-title Apache FontBox Medium
Product pom artifactid fontbox Highest
Product pom groupid org.apache.pdfbox Highest
Product pom name Apache FontBox High
Product pom parent-artifactid pdfbox-parent Medium
Product pom url http://pdfbox.apache.org/ Medium
Version file version 2.0.27 High
Version gradle version 2.0.27 Highest
Version Manifest Bundle-Version 2.0.27 High
Version Manifest Implementation-Version 2.0.27 High
Version pom version 2.0.27 Highest
pkg:maven/org.apache.pdfbox/fontbox@2.0.27
(Confidence :High)
geronimo-annotation_1.0_spec-1.1.1.jar
Description:
Provides open-source implementations of Sun specifications.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.geronimo.specs/geronimo-annotation_1.0_spec/1.1.1/47caa799389f69d297b86bf90523d431599c3796/geronimo-annotation_1.0_spec-1.1.1.jar
MD5: 4bcea8aa3540b81b66de5e9893a2b5d7
SHA1: 47caa799389f69d297b86bf90523d431599c3796
SHA256: 41a3705fadf44c27cc4e1045b8c4775a10b23d7fbe2e8285ad2e08d809bd6d7e
Referenced In Project/Scope: server-start:runtimeClasspath
geronimo-annotation_1.0_spec-1.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name geronimo-annotation_1.0_spec-1.1.1 High
Vendor gradle artifactid geronimo-annotation_1.0_spec Highest
Vendor gradle groupid org.apache.geronimo.specs Highest
Vendor jar package name annotation Highest
Vendor Manifest bundle-docurl http://www.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-annotation_1.0_spec Medium
Vendor pom artifactid geronimo-annotation_1.0_spec Low
Vendor pom groupid org.apache.geronimo.specs Highest
Vendor pom name Annotation 1.0 High
Vendor pom parent-artifactid specs Low
Product file name geronimo-annotation_1.0_spec-1.1.1 High
Product gradle artifactid geronimo-annotation_1.0_spec Highest
Product jar package name annotation Highest
Product Manifest bundle-docurl http://www.apache.org Low
Product Manifest Bundle-Name geronimo-annotation_1.0_spec Medium
Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-annotation_1.0_spec Medium
Product Manifest Implementation-Title Apache Geronimo High
Product pom artifactid geronimo-annotation_1.0_spec Highest
Product pom groupid org.apache.geronimo.specs Highest
Product pom name Annotation 1.0 High
Product pom parent-artifactid specs Medium
Version gradle version 1.1.1 Highest
Version Manifest Bundle-Version 1.1.1 High
Version Manifest Implementation-Version 1.1.1 High
Version pom parent-version 1.1.1 Low
Version pom version 1.1.1 Highest
pkg:maven/org.apache.geronimo.specs/geronimo-annotation_1.0_spec@1.1.1
(Confidence :High)
geronimo-jaxws_2.2_spec-1.2.jar
Description:
Java API for XML Web Services 2.2
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.geronimo.specs/geronimo-jaxws_2.2_spec/1.2/c5ece362fcac7f92b16120399d8b0911260b3271/geronimo-jaxws_2.2_spec-1.2.jar
MD5: 41c53e6e0a33ac903776e3d0a2a659fe
SHA1: c5ece362fcac7f92b16120399d8b0911260b3271
SHA256: f82650e7c27e2763822cc9efc67c645f91a8328aaeb201e909c9747a985f16af
Referenced In Project/Scope: server-start:runtimeClasspath
geronimo-jaxws_2.2_spec-1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name geronimo-jaxws_2.2_spec-1.2 High
Vendor gradle artifactid geronimo-jaxws_2.2_spec Highest
Vendor gradle groupid org.apache.geronimo.specs Highest
Vendor jar package name apache Highest
Vendor jar package name geronimo Highest
Vendor jar package name ws Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-jaxws_2.2_spec/1.2 Low
Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-jaxws_2.2_spec;singleton=true Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid geronimo-jaxws_2.2_spec Low
Vendor pom groupid org.apache.geronimo.specs Highest
Vendor pom name Apache Geronimo JAX-WS Spec 2.2 High
Vendor pom parent-artifactid genesis-java5-flava Low
Vendor pom parent-groupid org.apache.geronimo.genesis Medium
Vendor pom url http://geronimo.apache.org/maven/${siteId}/${version} Highest
Vendor pom url http://geronimo.apache.org/maven//1.2 Highest
Product file name geronimo-jaxws_2.2_spec-1.2 High
Product gradle artifactid geronimo-jaxws_2.2_spec Highest
Product jar package name apache Highest
Product jar package name geronimo Highest
Product jar package name http Highest
Product jar package name ws Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-jaxws_2.2_spec/1.2 Low
Product Manifest Bundle-Name Apache Geronimo JAX-WS Spec 2.2 Medium
Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-jaxws_2.2_spec;singleton=true Medium
Product Manifest Implementation-Title Apache Geronimo JAX-WS Spec 2.2 High
Product Manifest specification-title JSR-224 Java API for XML based Web Services 2.2 Medium
Product pom artifactid geronimo-jaxws_2.2_spec Highest
Product pom groupid org.apache.geronimo.specs Highest
Product pom name Apache Geronimo JAX-WS Spec 2.2 High
Product pom parent-artifactid genesis-java5-flava Medium
Product pom parent-groupid org.apache.geronimo.genesis Medium
Product pom url http://geronimo.apache.org/maven/${siteId}/${version} Medium
Product pom url http://geronimo.apache.org/maven//1.2 Medium
Version gradle version 1.2 Highest
Version Manifest Bundle-Version 1.2 High
Version Manifest Implementation-Version 1.2 High
Version pom parent-version 1.2 Low
Version pom version 1.2 Highest
pkg:maven/org.apache.geronimo.specs/geronimo-jaxws_2.2_spec@1.2
(Confidence :High)
geronimo-jms_1.1_spec-1.1.1.jar
Description:
Provides open-source implementations of Sun specifications.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.geronimo.specs/geronimo-jms_1.1_spec/1.1.1/c872b46c601d8dc03633288b81269f9e42762cea/geronimo-jms_1.1_spec-1.1.1.jar
MD5: d80ce71285696d36c1add1989b94f084
SHA1: c872b46c601d8dc03633288b81269f9e42762cea
SHA256: 18d9ff7b9066aa99cf89843f5055d2fe58b1abe4346ee9df0daf4ac18ca232d7
Referenced In Project/Scope: server-start:runtimeClasspath
geronimo-jms_1.1_spec-1.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name geronimo-jms_1.1_spec-1.1.1 High
Vendor gradle artifactid geronimo-jms_1.1_spec Highest
Vendor gradle groupid org.apache.geronimo.specs Highest
Vendor jar package name jms Highest
Vendor Manifest bundle-docurl http://www.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-jms_1.1_spec Medium
Vendor pom artifactid geronimo-jms_1.1_spec Low
Vendor pom groupid org.apache.geronimo.specs Highest
Vendor pom name JMS 1.1 High
Vendor pom parent-artifactid specs Low
Product file name geronimo-jms_1.1_spec-1.1.1 High
Product gradle artifactid geronimo-jms_1.1_spec Highest
Product jar package name jms Highest
Product Manifest bundle-docurl http://www.apache.org Low
Product Manifest Bundle-Name geronimo-jms_1.1_spec Medium
Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-jms_1.1_spec Medium
Product Manifest Implementation-Title Apache Geronimo High
Product pom artifactid geronimo-jms_1.1_spec Highest
Product pom groupid org.apache.geronimo.specs Highest
Product pom name JMS 1.1 High
Product pom parent-artifactid specs Medium
Version gradle version 1.1.1 Highest
Version Manifest Bundle-Version 1.1.1 High
Version Manifest Implementation-Version 1.1.1 High
Version pom parent-version 1.1.1 Low
Version pom version 1.1.1 Highest
pkg:maven/org.apache.geronimo.specs/geronimo-jms_1.1_spec@1.1.1
(Confidence :High)
geronimo-ws-metadata_2.0_spec-1.1.3.jar
Description:
Web Services Metadata 2.0 API
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.geronimo.specs/geronimo-ws-metadata_2.0_spec/1.1.3/5b6aa041a37145d6deedd92c66b3a266d4a601a1/geronimo-ws-metadata_2.0_spec-1.1.3.jar
MD5: 7b87d27ff907a4ed84fe8a0a209b7257
SHA1: 5b6aa041a37145d6deedd92c66b3a266d4a601a1
SHA256: 905806340528726b2d1a53a82024442ab31b95a6f730750f0720ded806f888a5
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
geronimo-ws-metadata_2.0_spec-1.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name geronimo-ws-metadata_2.0_spec-1.1.3 High
Vendor gradle artifactid geronimo-ws-metadata_2.0_spec Highest
Vendor gradle groupid org.apache.geronimo.specs Highest
Vendor hint analyzer vendor web services Medium
Vendor Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-ws-metadata_2.0_spec/1.1.3 Low
Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-ws-metadata_2.0_spec Medium
Vendor pom artifactid geronimo-ws-metadata_2.0_spec Low
Vendor pom groupid org.apache.geronimo.specs Highest
Vendor pom name Web Services Metadata 2.0 High
Vendor pom parent-artifactid genesis-java5-flava Low
Vendor pom parent-groupid org.apache.geronimo.genesis Medium
Vendor pom url http://geronimo.apache.org/maven/${siteId}/${version} Highest
Vendor pom url http://geronimo.apache.org/maven//1.1.3 Highest
Product file name geronimo-ws-metadata_2.0_spec-1.1.3 High
Product gradle artifactid geronimo-ws-metadata_2.0_spec Highest
Product hint analyzer product web services Medium
Product Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-ws-metadata_2.0_spec/1.1.3 Low
Product Manifest Bundle-Name Web Services Metadata 2.0 Medium
Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-ws-metadata_2.0_spec Medium
Product Manifest Implementation-Title Web Services Metadata 2.0 High
Product pom artifactid geronimo-ws-metadata_2.0_spec Highest
Product pom groupid org.apache.geronimo.specs Highest
Product pom name Web Services Metadata 2.0 High
Product pom parent-artifactid genesis-java5-flava Medium
Product pom parent-groupid org.apache.geronimo.genesis Medium
Product pom url http://geronimo.apache.org/maven/${siteId}/${version} Medium
Product pom url http://geronimo.apache.org/maven//1.1.3 Medium
Version gradle version 1.1.3 Highest
Version Manifest Bundle-Version 1.1.3 High
Version Manifest Implementation-Version 1.1.3 High
Version pom parent-version 1.1.3 Low
Version pom version 1.1.3 Highest
pkg:maven/org.apache.geronimo.specs/geronimo-ws-metadata_2.0_spec@1.1.3
(Confidence :High)
google-java-format-1.7.jar
Description:
A Java source code formatter that follows Google Java Style.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.googlejavaformat/google-java-format/1.7/97cb6afc835d65682edc248e19170a8e4ecfe4c4/google-java-format-1.7.jar
MD5: 983a6ef09e410ebc9113ed09a1341a52
SHA1: 97cb6afc835d65682edc248e19170a8e4ecfe4c4
SHA256: 0e13edfb91fc373075790beb1dc1f36e0b7ddd11865696f928ef63e328781cc2
Referenced In Project/Scope: server-start:runtimeClasspath
google-java-format-1.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name google-java-format High
Vendor gradle artifactid google-java-format Highest
Vendor gradle groupid com.google.googlejavaformat Highest
Vendor jar package name formatter Highest
Vendor jar package name google Highest
Vendor jar package name googlejavaformat Highest
Vendor jar package name java Highest
Vendor Manifest automatic-module-name com.google.googlejavaformat Medium
Vendor Manifest implementation-url https://github.com/google/google-java-format/google-java-format Low
Vendor Manifest Implementation-Vendor Google Inc. High
Vendor Manifest Implementation-Vendor-Id com.google.googlejavaformat Medium
Vendor pom artifactid google-java-format Low
Vendor pom groupid com.google.googlejavaformat Highest
Vendor pom name Google Java Format High
Vendor pom parent-artifactid google-java-format-parent Low
Product file name google-java-format High
Product gradle artifactid google-java-format Highest
Product jar package name formatter Highest
Product jar package name google Highest
Product jar package name googlejavaformat Highest
Product jar package name java Highest
Product Manifest automatic-module-name com.google.googlejavaformat Medium
Product Manifest Implementation-Title Google Java Format High
Product Manifest implementation-url https://github.com/google/google-java-format/google-java-format Low
Product pom artifactid google-java-format Highest
Product pom groupid com.google.googlejavaformat Highest
Product pom name Google Java Format High
Product pom parent-artifactid google-java-format-parent Medium
Version file version 1.7 High
Version gradle version 1.7 Highest
Version Manifest Implementation-Version 1.7 High
Version pom version 1.7 Highest
pkg:maven/com.google.googlejavaformat/google-java-format@1.7
(Confidence :High)
gson-2.13.2.jar
Description:
Gson JSON library
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.code.gson/gson/2.13.2/48b8230771e573b54ce6e867a9001e75977fe78e/gson-2.13.2.jar
MD5: a2c47e14ce5e956105458fe455f5d542
SHA1: 48b8230771e573b54ce6e867a9001e75977fe78e
SHA256: dd0ce1b55a3ed2080cb70f9c655850cda86c206862310009dcb5e5c95265a5e0
Referenced In Project/Scope: server-start:runtimeClasspath
gson-2.13.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name gson High
Vendor gradle artifactid gson Highest
Vendor gradle groupid com.google.code.gson Highest
Vendor jar package name google Highest
Vendor jar package name gson Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-contactaddress https://github.com/google/gson Low
Vendor Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low
Vendor Manifest bundle-docurl https://github.com/google/gson Low
Vendor Manifest bundle-symbolicname com.google.gson Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid gson Low
Vendor pom groupid com.google.code.gson Highest
Vendor pom name Gson High
Vendor pom parent-artifactid gson-parent Low
Product file name gson High
Product gradle artifactid gson Highest
Product jar package name google Highest
Product jar package name gson Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-contactaddress https://github.com/google/gson Low
Product Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low
Product Manifest bundle-docurl https://github.com/google/gson Low
Product Manifest Bundle-Name Gson Medium
Product Manifest bundle-symbolicname com.google.gson Medium
Product Manifest multi-release true Low
Product pom artifactid gson Highest
Product pom groupid com.google.code.gson Highest
Product pom name Gson High
Product pom parent-artifactid gson-parent Medium
Version file version 2.13.2 High
Version gradle version 2.13.2 Highest
Version Manifest Bundle-Version 2.13.2 High
Version pom version 2.13.2 Highest
guava-32.1.1-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.guava/guava/32.1.1-jre/ad575652d84153075dd41ec6177ccb15251262b2/guava-32.1.1-jre.jar
MD5: 55870c9a31bf9ba2815f252a93ab0850
SHA1: ad575652d84153075dd41ec6177ccb15251262b2
SHA256: 91fbba37f1c8b251cf9ea9e7d3a369eb79eb1e6a5df1d4bbf483dd0380740281
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
guava-32.1.1-jre.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor gradle artifactid guava Highest
Vendor gradle groupid com.google.guava Highest
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product gradle artifactid guava Highest
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version gradle version 32.1.1-jre Highest
Version pom version 32.1.1-jre Highest
guava-33.4.0-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.guava/guava/33.4.0-jre/3fcc0a259f724c7de54a6a55ea7e26d3d5c0cac/guava-33.4.0-jre.jar
MD5: 5732af16367192820c7bf177e9b29512
SHA1: 03fcc0a259f724c7de54a6a55ea7e26d3d5c0cac
SHA256: b918c98a7e44dbe94ebd9fe3e40cddaadb5a93e6a78eb6008b42df237241e538
Referenced In Project/Scope: server-start:webapps
guava-33.4.0-jre.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor gradle artifactid guava Highest
Vendor gradle groupid com.google.guava Highest
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product gradle artifactid guava Highest
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version gradle version 33.4.0-jre Highest
Version pom version 33.4.0-jre Highest
hamcrest-core-1.3.jar
Description:
This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.hamcrest/hamcrest-core/1.3/42a25dc3219429f0e5d060061f71acb49bf010a0/hamcrest-core-1.3.jar
MD5: 6393363b47ddcbba82321110c3e07519
SHA1: 42a25dc3219429f0e5d060061f71acb49bf010a0
SHA256: 66fdef91e9739348df7a096aa384a5685f4e875584cce89386a7a47251c4d8e9
Referenced In Project/Scope: server-start:runtimeClasspath
hamcrest-core-1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name hamcrest-core High
Vendor gradle artifactid hamcrest-core Highest
Vendor gradle groupid org.hamcrest Highest
Vendor jar package name hamcrest Highest
Vendor jar package name hamcrest Low
Vendor Manifest built-date 2012-07-09 19:49:34 Low
Vendor Manifest Implementation-Vendor hamcrest.org High
Vendor pom artifactid hamcrest-core Low
Vendor pom groupid org.hamcrest Highest
Vendor pom name Hamcrest Core High
Vendor pom parent-artifactid hamcrest-parent Low
Product file name hamcrest-core High
Product gradle artifactid hamcrest-core Highest
Product jar package name core Highest
Product jar package name hamcrest Highest
Product Manifest built-date 2012-07-09 19:49:34 Low
Product Manifest Implementation-Title hamcrest-core High
Product pom artifactid hamcrest-core Highest
Product pom groupid org.hamcrest Highest
Product pom name Hamcrest Core High
Product pom parent-artifactid hamcrest-parent Medium
Version file version 1.3 High
Version gradle version 1.3 Highest
Version Manifest Implementation-Version 1.3 High
Version pom version 1.3 Highest
pkg:maven/org.hamcrest/hamcrest-core@1.3
(Confidence :High)
hivemq-mqtt-client-1.1.4.jar
Description:
HiveMQ MQTT Client is a MQTT 5.0 and MQTT 3.1.1 compatible and feature-rich high-performance Java client library with different API flavours and backpressure support
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
Apache-2.0;description="The Apache License, Version 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.hivemq/hivemq-mqtt-client/1.1.4/253131e45a4456ea063ead22bf2000de4b4a8fe/hivemq-mqtt-client-1.1.4.jar
MD5: f703cdcc68ad1c45ac25f6cb4d91cfa3
SHA1: 0253131e45a4456ea063ead22bf2000de4b4a8fe
SHA256: c9e56557410f3baad15fa3e3bb9c4711b0735025143b7ac4ffe2b50c0d5db95a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
hivemq-mqtt-client-1.1.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name hivemq-mqtt-client High
Vendor gradle artifactid hivemq-mqtt-client Highest
Vendor gradle groupid com.hivemq Highest
Vendor jar package name client Highest
Vendor jar package name client Low
Vendor jar package name hivemq Highest
Vendor jar package name hivemq Low
Vendor jar package name internal Low
Vendor jar package name mqtt Highest
Vendor Manifest automatic-module-name com.hivemq.client.mqtt Medium
Vendor Manifest bundle-docurl https://hivemq.github.io/hivemq-mqtt-client/ Low
Vendor Manifest bundle-symbolicname com.hivemq.client.mqtt Medium
Vendor pom artifactid hivemq-mqtt-client Low
Vendor pom developer email silvio.giebl@hivemq.com Low
Vendor pom developer id SG Medium
Vendor pom developer name Silvio Giebl Medium
Vendor pom groupid com.hivemq Highest
Vendor pom name HiveMQ MQTT Client High
Vendor pom url hivemq/hivemq-mqtt-client Highest
Product file name hivemq-mqtt-client High
Product gradle artifactid hivemq-mqtt-client Highest
Product jar package name client Highest
Product jar package name client Low
Product jar package name hivemq Highest
Product jar package name internal Low
Product jar package name mqtt Highest
Product jar package name mqtt Low
Product Manifest automatic-module-name com.hivemq.client.mqtt Medium
Product Manifest bundle-docurl https://hivemq.github.io/hivemq-mqtt-client/ Low
Product Manifest Bundle-Name hivemq-mqtt-client Medium
Product Manifest bundle-symbolicname com.hivemq.client.mqtt Medium
Product pom artifactid hivemq-mqtt-client Highest
Product pom developer email silvio.giebl@hivemq.com Low
Product pom developer id SG Low
Product pom developer name Silvio Giebl Low
Product pom groupid com.hivemq Highest
Product pom name HiveMQ MQTT Client High
Product pom url hivemq/hivemq-mqtt-client High
Version file version 1.1.4 High
Version gradle version 1.1.4 Highest
Version Manifest Bundle-Version 1.1.4 High
Version pom version 1.1.4 Highest
hk2-api-3.0.6.jar
Description:
HK2 API module
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.hk2/hk2-api/3.0.6/5a5152dea2c43384f5c07985eb27140134074ecb/hk2-api-3.0.6.jar
MD5: 37d753cad17273560c48b745f024cbaa
SHA1: 5a5152dea2c43384f5c07985eb27140134074ecb
SHA256: c049a21a9fd9316c7e291a2bc28835f70d25affb623dc1599a83b6b84ec83a4f
Referenced In Project/Scope: server-start:webapps
hk2-api-3.0.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name hk2-api High
Vendor gradle artifactid hk2-api Highest
Vendor gradle groupid org.glassfish.hk2 Highest
Vendor jar package name api Highest
Vendor jar package name glassfish Highest
Vendor jar package name hk2 Highest
Vendor Manifest automatic-module-name org.glassfish.hk2.api Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname org.glassfish.hk2.api Medium
Vendor pom artifactid hk2-api Low
Vendor pom groupid org.glassfish.hk2 Highest
Vendor pom name HK2 API module High
Vendor pom parent-artifactid hk2-parent Low
Product file name hk2-api High
Product gradle artifactid hk2-api Highest
Product jar package name api Highest
Product jar package name glassfish Highest
Product jar package name hk2 Highest
Product Manifest automatic-module-name org.glassfish.hk2.api Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name HK2 API module Medium
Product Manifest bundle-symbolicname org.glassfish.hk2.api Medium
Product pom artifactid hk2-api Highest
Product pom groupid org.glassfish.hk2 Highest
Product pom name HK2 API module High
Product pom parent-artifactid hk2-parent Medium
Version file version 3.0.6 High
Version gradle version 3.0.6 Highest
Version Manifest Bundle-Version 3.0.6 High
Version pom version 3.0.6 Highest
pkg:maven/org.glassfish.hk2/hk2-api@3.0.6
(Confidence :High)
hk2-locator-3.0.6.jar
Description:
ServiceLocator Default Implementation
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.hk2/hk2-locator/3.0.6/92d5c92c9f23bea4b8681c6f8d6ba3d708619f81/hk2-locator-3.0.6.jar
MD5: e976aff53fb156b02317d2b8bc40660d
SHA1: 92d5c92c9f23bea4b8681c6f8d6ba3d708619f81
SHA256: e2664d21b017c3aa1518b913264602bea604edc54d356103c10afba99abd04fc
Referenced In Project/Scope: server-start:webapps
hk2-locator-3.0.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name hk2-locator High
Vendor gradle artifactid hk2-locator Highest
Vendor gradle groupid org.glassfish.hk2 Highest
Vendor jar package name hk2 Highest
Vendor Manifest automatic-module-name org.glassfish.hk2.locator Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname org.glassfish.hk2.locator Medium
Vendor pom artifactid hk2-locator Low
Vendor pom groupid org.glassfish.hk2 Highest
Vendor pom name ServiceLocator Default Implementation High
Vendor pom parent-artifactid hk2-parent Low
Product file name hk2-locator High
Product gradle artifactid hk2-locator Highest
Product jar package name hk2 Highest
Product Manifest automatic-module-name org.glassfish.hk2.locator Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name ServiceLocator Default Implementation Medium
Product Manifest bundle-symbolicname org.glassfish.hk2.locator Medium
Product pom artifactid hk2-locator Highest
Product pom groupid org.glassfish.hk2 Highest
Product pom name ServiceLocator Default Implementation High
Product pom parent-artifactid hk2-parent Medium
Version file version 3.0.6 High
Version gradle version 3.0.6 Highest
Version Manifest Bundle-Version 3.0.6 High
Version pom version 3.0.6 Highest
pkg:maven/org.glassfish.hk2/hk2-locator@3.0.6
(Confidence :High)
cpe:2.3:a:service_project:service:3.0.6:*:*:*:*:*:*:*
(Confidence :Low)
suppress
hk2-utils-3.0.6.jar
Description:
HK2 Implementation Utilities
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.hk2/hk2-utils/3.0.6/b3187d0673c0fd52de197e52c62545c34d4eda29/hk2-utils-3.0.6.jar
MD5: 4f0469e8a5957c5912639f92244a9662
SHA1: b3187d0673c0fd52de197e52c62545c34d4eda29
SHA256: fc84d85a0744b576d9ec7db5845eeb998ed532a9450dd19c8c922c3ee6926206
Referenced In Project/Scope: server-start:webapps
hk2-utils-3.0.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name hk2-utils High
Vendor gradle artifactid hk2-utils Highest
Vendor gradle groupid org.glassfish.hk2 Highest
Vendor jar package name glassfish Highest
Vendor jar package name hk2 Highest
Vendor jar package name utilities Highest
Vendor Manifest automatic-module-name org.glassfish.hk2.utilities Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname org.glassfish.hk2.utils Medium
Vendor Manifest service foo Low
Vendor pom artifactid hk2-utils Low
Vendor pom groupid org.glassfish.hk2 Highest
Vendor pom name HK2 Implementation Utilities High
Vendor pom parent-artifactid hk2-parent Low
Product file name hk2-utils High
Product gradle artifactid hk2-utils Highest
Product jar package name glassfish Highest
Product jar package name hk2 Highest
Product jar package name utilities Highest
Product Manifest automatic-module-name org.glassfish.hk2.utilities Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name HK2 Implementation Utilities Medium
Product Manifest bundle-symbolicname org.glassfish.hk2.utils Medium
Product Manifest service foo Low
Product pom artifactid hk2-utils Highest
Product pom groupid org.glassfish.hk2 Highest
Product pom name HK2 Implementation Utilities High
Product pom parent-artifactid hk2-parent Medium
Version file version 3.0.6 High
Version gradle version 3.0.6 Highest
Version Manifest Bundle-Version 3.0.6 High
Version pom version 3.0.6 Highest
http-auth-2.26.30.jar
Description:
The AWS SDK for Java - HTTP Auth module contains interfaces and implementations
for generic HTTP authentication
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/http-auth/2.26.30/34d9476cfc1daf5364dfc2e361ba438bb74ac2b1/http-auth-2.26.30.jar
MD5: 73acc7ccf672a076d32063742e646c66
SHA1: 34d9476cfc1daf5364dfc2e361ba438bb74ac2b1
SHA256: 145b190191cb76c07d5ee3f57800b21e2db21734cd967d66c05a8d001e7a2ed6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
http-auth-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name http-auth High
Vendor gradle artifactid http-auth Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.auth Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid http-auth Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Auth High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name http-auth High
Product gradle artifactid http-auth Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.auth Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid http-auth Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Auth High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
http-auth-aws-2.26.30.jar
Description:
The AWS SDK for Java - HTTP Auth AWS module contains interfaces and implementations for HTTP
authentication specific to AWS.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/http-auth-aws/2.26.30/ae2ad1d5cca5ddfda89afe44e4f55ad41534f15/http-auth-aws-2.26.30.jar
MD5: 1a8fa9ef36dff1dd5969e8dea245c1b7
SHA1: 0ae2ad1d5cca5ddfda89afe44e4f55ad41534f15
SHA256: fee71a49d9051f6c96cfe57bb9ae92b7014189058b10daab5d0b43dcd8da9f30
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
http-auth-aws-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name http-auth-aws High
Vendor gradle artifactid http-auth-aws Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.auth.aws Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid http-auth-aws Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Auth AWS High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name http-auth-aws High
Product gradle artifactid http-auth-aws Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.auth.aws Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid http-auth-aws Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Auth AWS High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
http-auth-aws-eventstream-2.26.30.jar
Description:
The AWS SDK for Java - HTTP Auth AWS Event Stream module contains interfaces and implementations for AWS
specific authentication of event streams in HTTP services.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/http-auth-aws-eventstream/2.26.30/63eafebadedc3e0ed2c6dbb56128463bbf1f0339/http-auth-aws-eventstream-2.26.30.jar
MD5: 94d20710ce380e3b3f0b4b05125e35f8
SHA1: 63eafebadedc3e0ed2c6dbb56128463bbf1f0339
SHA256: 58f7fbac6775e1790a107aff8ac20b5f4213a2538f2c974514659761dc9488af
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
http-auth-aws-eventstream-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name http-auth-aws-eventstream High
Vendor gradle artifactid http-auth-aws-eventstream Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.auth.aws.eventstream Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid http-auth-aws-eventstream Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Auth Event Stream High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name http-auth-aws-eventstream High
Product gradle artifactid http-auth-aws-eventstream Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.auth.aws.eventstream Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid http-auth-aws-eventstream Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Auth Event Stream High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
http-auth-spi-2.26.30.jar
Description:
The AWS SDK for Java - HTTP Auth SPI module contains the interfaces for authentication that are used by other
modules in the library.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/http-auth-spi/2.26.30/230bd0f71c0a65c4635d552a0e689c99a75b8754/http-auth-spi-2.26.30.jar
MD5: 246c042389cf532a1ee65978ef4441a9
SHA1: 230bd0f71c0a65c4635d552a0e689c99a75b8754
SHA256: 03805a97da68f70246d7c0830b4f84cb9beb3e840f8d33eca2ce57fbcff19082
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
http-auth-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name http-auth-spi High
Vendor gradle artifactid http-auth-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.auth.spi Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid http-auth-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Auth SPI High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name http-auth-spi High
Product gradle artifactid http-auth-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.auth.spi Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid http-auth-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Auth SPI High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
http-client-spi-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/http-client-spi/2.26.30/17b4be4434c7ed3d68653698f32d9cfa0bac64fb/http-client-spi-2.26.30.jar
MD5: a13328581a3201811c985fec2c931618
SHA1: 17b4be4434c7ed3d68653698f32d9cfa0bac64fb
SHA256: 0e049ab69207d26c191a176df620f5a24df92db7b51264682867ff85bdc2efb5
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
http-client-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name http-client-spi High
Vendor gradle artifactid http-client-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid http-client-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Client Interface High
Vendor pom parent-artifactid aws-sdk-java-pom Low
Product file name http-client-spi High
Product gradle artifactid http-client-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid http-client-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Client Interface High
Product pom parent-artifactid aws-sdk-java-pom Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
httpclient-4.5.13.jar
Description:
Apache HttpComponents Client
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpclient/4.5.13/e5f6cae5ca7ecaac1ec2827a9e2d65ae2869cada/httpclient-4.5.13.jar
MD5: 40d6b9075fbd28fa10292a45a0db9457
SHA1: e5f6cae5ca7ecaac1ec2827a9e2d65ae2869cada
SHA256: 6fe9026a566c6a5001608cf3fc32196641f6c1e5e1986d1037ccdbd5f31ef743
Referenced In Project/Scope: server-start:compileClasspath
httpclient-4.5.13.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpclient High
Vendor gradle artifactid httpclient Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor jar package name client Highest
Vendor jar package name httpclient Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpclient Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpClient High
Vendor pom parent-artifactid httpcomponents-client Low
Vendor pom url http://hc.apache.org/httpcomponents-client Highest
Product file name httpclient High
Product gradle artifactid httpclient Highest
Product jar package name apache Highest
Product jar package name client Highest
Product jar package name http Highest
Product jar package name httpclient Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium
Product Manifest Implementation-Title Apache HttpClient High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low
Product Manifest specification-title Apache HttpClient Medium
Product pom artifactid httpclient Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpClient High
Product pom parent-artifactid httpcomponents-client Medium
Product pom url http://hc.apache.org/httpcomponents-client Medium
Version file version 4.5.13 High
Version gradle version 4.5.13 Highest
Version Manifest Implementation-Version 4.5.13 High
Version pom version 4.5.13 Highest
httpclient-4.5.14.jar
Description:
Apache HttpComponents Client
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpclient/4.5.14/1194890e6f56ec29177673f2f12d0b8e627dec98/httpclient-4.5.14.jar
MD5: 2cb357c4b763f47e58af6cad47df6ba3
SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98
SHA256: c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Referenced In Project/Scope: server-start:runtimeClasspath
httpclient-4.5.14.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpclient High
Vendor gradle artifactid httpclient Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor jar package name client Highest
Vendor jar package name httpclient Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpclient Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpClient High
Vendor pom parent-artifactid httpcomponents-client Low
Vendor pom url http://hc.apache.org/httpcomponents-client-ga Highest
Product file name httpclient High
Product gradle artifactid httpclient Highest
Product jar package name apache Highest
Product jar package name client Highest
Product jar package name http Highest
Product jar package name httpclient Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium
Product Manifest Implementation-Title Apache HttpClient High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low
Product Manifest specification-title Apache HttpClient Medium
Product pom artifactid httpclient Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpClient High
Product pom parent-artifactid httpcomponents-client Medium
Product pom url http://hc.apache.org/httpcomponents-client-ga Medium
Version file version 4.5.14 High
Version gradle version 4.5.14 Highest
Version Manifest Implementation-Version 4.5.14 High
Version pom version 4.5.14 Highest
httpclient5-5.3.1.jar
Description:
Apache HttpComponents Client
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents.client5/httpclient5/5.3.1/56b53c8f4bcdaada801d311cf2ff8a24d6d96883/httpclient5-5.3.1.jar
MD5: de1810a606b27192cbf5bbad9c25a648
SHA1: 56b53c8f4bcdaada801d311cf2ff8a24d6d96883
SHA256: 08346a757c617f6ecc66af9f099260adde1f3a1351fa81cb22fc17482b31f823
Referenced In Project/Scope: server-start:webapps
httpclient5-5.3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpclient5 High
Vendor gradle artifactid httpclient5 Highest
Vendor gradle groupid org.apache.httpcomponents.client5 Highest
Vendor jar package name apache Highest
Vendor jar package name client5 Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.3.1/httpclient5/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpclient5 Low
Vendor pom groupid org.apache.httpcomponents.client5 Highest
Vendor pom name Apache HttpClient High
Vendor pom parent-artifactid httpclient5-parent Low
Product file name httpclient5 High
Product gradle artifactid httpclient5 Highest
Product jar package name apache Highest
Product jar package name client5 Highest
Product jar package name hc Highest
Product Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Implementation-Title Apache HttpClient High
Product Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.3.1/httpclient5/ Low
Product Manifest specification-title Apache HttpClient Medium
Product pom artifactid httpclient5 Highest
Product pom groupid org.apache.httpcomponents.client5 Highest
Product pom name Apache HttpClient High
Product pom parent-artifactid httpclient5-parent Medium
Version file version 5.3.1 High
Version gradle version 5.3.1 Highest
Version Manifest Implementation-Version 5.3.1 High
Version pom version 5.3.1 Highest
httpclient5-cache-5.3.1.jar
Description:
Apache HttpComponents HttpClient Cache
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents.client5/httpclient5-cache/5.3.1/3d3bea8e0b3dd4964225ad8abe4eed5b6ccd6db9/httpclient5-cache-5.3.1.jar
MD5: ef035c64709044723191e430b7919890
SHA1: 3d3bea8e0b3dd4964225ad8abe4eed5b6ccd6db9
SHA256: bb1852942dcb40566f53bb99f11b5175fd913229ab35b9fa54a33d4644924b10
Referenced In Project/Scope: server-start:webapps
httpclient5-cache-5.3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpclient5-cache High
Vendor gradle artifactid httpclient5-cache Highest
Vendor gradle groupid org.apache.httpcomponents.client5 Highest
Vendor jar package name apache Highest
Vendor jar package name client5 Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5.cache Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.3.1/httpclient5-cache/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpclient5-cache Low
Vendor pom groupid org.apache.httpcomponents.client5 Highest
Vendor pom name Apache HttpClient Cache High
Vendor pom parent-artifactid httpclient5-parent Low
Product file name httpclient5-cache High
Product gradle artifactid httpclient5-cache Highest
Product jar package name apache Highest
Product jar package name client5 Highest
Product jar package name hc Highest
Product Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5.cache Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Implementation-Title Apache HttpClient Cache High
Product Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.3.1/httpclient5-cache/ Low
Product Manifest specification-title Apache HttpClient Cache Medium
Product pom artifactid httpclient5-cache Highest
Product pom groupid org.apache.httpcomponents.client5 Highest
Product pom name Apache HttpClient Cache High
Product pom parent-artifactid httpclient5-parent Medium
Version file version 5.3.1 High
Version gradle version 5.3.1 Highest
Version Manifest Implementation-Version 5.3.1 High
Version pom version 5.3.1 Highest
httpcore-4.4.13.jar
Description:
Apache HttpComponents Core (blocking I/O)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpcore/4.4.13/853b96d3afbb7bf8cc303fe27ee96836a10c1834/httpcore-4.4.13.jar
MD5: e07a248f61c52776a2366c075dcd4963
SHA1: 853b96d3afbb7bf8cc303fe27ee96836a10c1834
SHA256: e06e89d40943245fcfa39ec537cdbfce3762aecde8f9c597780d2b00c2b43424
Referenced In Project/Scope: server-start:compileClasspath
httpcore-4.4.13.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpcore High
Vendor gradle artifactid httpcore Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium
Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-01-09 12:56:55+0000 Low
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Vendor pom artifactid httpcore Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpCore High
Vendor pom parent-artifactid httpcomponents-core Low
Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest
Product file name httpcore High
Product gradle artifactid httpcore Highest
Product jar package name apache Highest
Product jar package name http Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium
Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-01-09 12:56:55+0000 Low
Product Manifest Implementation-Title HttpComponents Apache HttpCore High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Product Manifest specification-title HttpComponents Apache HttpCore Medium
Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Product pom artifactid httpcore Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpCore High
Product pom parent-artifactid httpcomponents-core Medium
Product pom url http://hc.apache.org/httpcomponents-core-ga Medium
Version file version 4.4.13 High
Version gradle version 4.4.13 Highest
Version Manifest Implementation-Version 4.4.13 High
Version pom version 4.4.13 Highest
pkg:maven/org.apache.httpcomponents/httpcore@4.4.13
(Confidence :High)
httpcore-4.4.16.jar
Description:
Apache HttpComponents Core (blocking I/O)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpcore/4.4.16/51cf043c87253c9f58b539c9f7e44c8894223850/httpcore-4.4.16.jar
MD5: 28d2cd9bf8789fd2ec774fb88436ebd1
SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850
SHA256: 6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Referenced In Project/Scope: server-start:runtimeClasspath
httpcore-4.4.16.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpcore High
Vendor gradle artifactid httpcore Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium
Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Vendor pom artifactid httpcore Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpCore High
Vendor pom parent-artifactid httpcomponents-core Low
Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest
Product file name httpcore High
Product gradle artifactid httpcore Highest
Product jar package name apache Highest
Product jar package name http Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium
Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low
Product Manifest Implementation-Title HttpComponents Apache HttpCore High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Product Manifest specification-title HttpComponents Apache HttpCore Medium
Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Product pom artifactid httpcore Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpCore High
Product pom parent-artifactid httpcomponents-core Medium
Product pom url http://hc.apache.org/httpcomponents-core-ga Medium
Version file version 4.4.16 High
Version gradle version 4.4.16 Highest
Version Manifest Implementation-Version 4.4.16 High
Version pom version 4.4.16 Highest
pkg:maven/org.apache.httpcomponents/httpcore@4.4.16
(Confidence :High)
httpcore-nio-4.4.12.jar
Description:
Apache HttpComponents Core (non-blocking I/O)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpcore-nio/4.4.12/84cd29eca842f31db02987cfedea245af020198b/httpcore-nio-4.4.12.jar
MD5: 6b623c5cce9d2333cfdf220749cdab03
SHA1: 84cd29eca842f31db02987cfedea245af020198b
SHA256: 11448f4b5c7f13d9396a67b33aa938d05f660665e0f14fd08e25acfd3c20ae80
Referenced In Project/Scope: server-start:runtimeClasspath
httpcore-nio-4.4.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpcore-nio High
Vendor gradle artifactid httpcore-nio Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor jar package name nio Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore.nio Medium
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpcore-nio Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpCore NIO High
Vendor pom parent-artifactid httpcomponents-core Low
Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest
Product file name httpcore-nio High
Product gradle artifactid httpcore-nio Highest
Product jar package name apache Highest
Product jar package name http Highest
Product jar package name nio Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpcore.nio Medium
Product Manifest Implementation-Title Apache HttpCore NIO High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low
Product Manifest specification-title Apache HttpCore NIO Medium
Product pom artifactid httpcore-nio Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpCore NIO High
Product pom parent-artifactid httpcomponents-core Medium
Product pom url http://hc.apache.org/httpcomponents-core-ga Medium
Version file version 4.4.12 High
Version gradle version 4.4.12 Highest
Version Manifest Implementation-Version 4.4.12 High
Version pom version 4.4.12 Highest
pkg:maven/org.apache.httpcomponents/httpcore-nio@4.4.12
(Confidence :High)
httpcore5-5.2.5.jar
Description:
Apache HttpComponents HTTP/1.1 core components
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents.core5/httpcore5/5.2.5/dab1e18842971a45ca8942491ce005ab86a028d7/httpcore5-5.2.5.jar
MD5: 419f7b3172ebee12dd64af978feb4351
SHA1: dab1e18842971a45ca8942491ce005ab86a028d7
SHA256: 9552b9e06cef3170e37046092de115c33a7cb48ee7ef0d87f1d5650dee7e1b0d
Referenced In Project/Scope: server-start:webapps
httpcore5-5.2.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpcore5 High
Vendor gradle artifactid httpcore5 Highest
Vendor gradle groupid org.apache.httpcomponents.core5 Highest
Vendor jar package name apache Highest
Vendor jar package name core5 Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.2.x/5.2.5/httpcore5/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpcore5 Low
Vendor pom groupid org.apache.httpcomponents.core5 Highest
Vendor pom name Apache HttpComponents Core HTTP/1.1 High
Vendor pom parent-artifactid httpcore5-parent Low
Product file name httpcore5 High
Product gradle artifactid httpcore5 Highest
Product jar package name apache Highest
Product jar package name core5 Highest
Product jar package name hc Highest
Product Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Implementation-Title Apache HttpComponents Core HTTP/1.1 High
Product Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.2.x/5.2.5/httpcore5/ Low
Product Manifest specification-title Apache HttpComponents Core HTTP/1.1 Medium
Product pom artifactid httpcore5 Highest
Product pom groupid org.apache.httpcomponents.core5 Highest
Product pom name Apache HttpComponents Core HTTP/1.1 High
Product pom parent-artifactid httpcore5-parent Medium
Version file version 5.2.5 High
Version gradle version 5.2.5 Highest
Version Manifest Implementation-Version 5.2.5 High
Version pom version 5.2.5 Highest
pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.2.5
(Confidence :High)
httpcore5-h2-5.2.4.jar
Description:
Apache HttpComponents HTTP/2 Core Components
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents.core5/httpcore5-h2/5.2.4/2872764df7b4857549e2880dd32a6f9009166289/httpcore5-h2-5.2.4.jar
MD5: d407b8144029db656ac5ba3d54ef801f
SHA1: 2872764df7b4857549e2880dd32a6f9009166289
SHA256: dc1a95e73eb04db93451533d390ce02c53b301a10dc343d08c862f2934b3d30e
Referenced In Project/Scope: server-start:webapps
httpcore5-h2-5.2.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpcore5-h2 High
Vendor gradle artifactid httpcore5-h2 Highest
Vendor gradle groupid org.apache.httpcomponents.core5 Highest
Vendor jar package name apache Highest
Vendor jar package name core5 Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5.h2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.2.x/5.2.4/httpcore5-h2/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpcore5-h2 Low
Vendor pom groupid org.apache.httpcomponents.core5 Highest
Vendor pom name Apache HttpComponents Core HTTP/2 High
Vendor pom parent-artifactid httpcore5-parent Low
Product file name httpcore5-h2 High
Product gradle artifactid httpcore5-h2 Highest
Product jar package name apache Highest
Product jar package name core5 Highest
Product jar package name hc Highest
Product Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5.h2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Implementation-Title Apache HttpComponents Core HTTP/2 High
Product Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.2.x/5.2.4/httpcore5-h2/ Low
Product Manifest specification-title Apache HttpComponents Core HTTP/2 Medium
Product pom artifactid httpcore5-h2 Highest
Product pom groupid org.apache.httpcomponents.core5 Highest
Product pom name Apache HttpComponents Core HTTP/2 High
Product pom parent-artifactid httpcore5-parent Medium
Version file version 5.2.4 High
Version gradle version 5.2.4 Highest
Version Manifest Implementation-Version 5.2.4 High
Version pom version 5.2.4 Highest
pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.2.4
(Confidence :High)
httpmime-4.5.13.jar
Description:
Apache HttpComponents HttpClient - MIME coded entities
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.httpcomponents/httpmime/4.5.13/efc110bad4a0d45cda7858e6beee1d8a8313da5a/httpmime-4.5.13.jar
MD5: 3f0c1ef2c9dc47b62b780192f54b0c18
SHA1: efc110bad4a0d45cda7858e6beee1d8a8313da5a
SHA256: 06e754d99245b98dcc2860dcb43d20e737d650da2bf2077a105f68accbd5c5cc
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
httpmime-4.5.13.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name httpmime High
Vendor gradle artifactid httpmime Highest
Vendor gradle groupid org.apache.httpcomponents Highest
Vendor jar package name apache Highest
Vendor jar package name mime Highest
Vendor Manifest automatic-module-name org.apache.httpcomponents.httpmime Medium
Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid httpmime Low
Vendor pom groupid org.apache.httpcomponents Highest
Vendor pom name Apache HttpClient Mime High
Vendor pom parent-artifactid httpcomponents-client Low
Vendor pom url http://hc.apache.org/httpcomponents-client Highest
Product file name httpmime High
Product gradle artifactid httpmime Highest
Product jar package name apache Highest
Product jar package name http Highest
Product jar package name mime Highest
Product Manifest automatic-module-name org.apache.httpcomponents.httpmime Medium
Product Manifest Implementation-Title Apache HttpClient Mime High
Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low
Product Manifest specification-title Apache HttpClient Mime Medium
Product pom artifactid httpmime Highest
Product pom groupid org.apache.httpcomponents Highest
Product pom name Apache HttpClient Mime High
Product pom parent-artifactid httpcomponents-client Medium
Product pom url http://hc.apache.org/httpcomponents-client Medium
Version file version 4.5.13 High
Version gradle version 4.5.13 Highest
Version Manifest Implementation-Version 4.5.13 High
Version pom version 4.5.13 Highest
pkg:maven/org.apache.httpcomponents/httpmime@4.5.13
(Confidence :High)
identity-spi-2.26.30.jar
Description:
The AWS SDK for Java - Identity SPI module contains the Identity interfaces that are used by other modules in
the library.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/identity-spi/2.26.30/cc5e5caba4846cb552afdbbfa68ea8a82f322a7f/identity-spi-2.26.30.jar
MD5: 8f44384c6bdb9ac4553d1e61ed398310
SHA1: cc5e5caba4846cb552afdbbfa68ea8a82f322a7f
SHA256: 333636f5bf6b557a4c6faebe2799d546c0c7a9c1a677e5b6b6a12405e6252cff
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
identity-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name identity-spi High
Vendor gradle artifactid identity-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name identity Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.identity.spi Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid identity-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Identity SPI High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name identity-spi High
Product gradle artifactid identity-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name identity Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.identity.spi Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid identity-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Identity SPI High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
istack-commons-runtime-3.0.12.jar
Description:
istack common utility code
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.istack/istack-commons-runtime/3.0.12/cbbe1a62b0cc6c85972e99d52aaee350153dc530/istack-commons-runtime-3.0.12.jar
MD5: 1952bd76321f8580cfaa57e332a68287
SHA1: cbbe1a62b0cc6c85972e99d52aaee350153dc530
SHA256: 27d85fc134c9271d5c79d3300fc4669668f017e72409727c428f54f2417f04cd
Referenced In Project/Scope: server-start:runtimeClasspath
istack-commons-runtime-3.0.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name istack-commons-runtime High
Vendor gradle artifactid istack-commons-runtime Highest
Vendor gradle groupid com.sun.istack Highest
Vendor jar package name com Highest
Vendor jar package name istack Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Vendor Manifest implementation-build-id 3.0.12 - 7ed1368 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid istack-commons-runtime Low
Vendor pom groupid com.sun.istack Highest
Vendor pom name istack common utility code runtime High
Vendor pom parent-artifactid istack-commons Low
Product file name istack-commons-runtime High
Product gradle artifactid istack-commons-runtime Highest
Product jar package name com Highest
Product jar package name istack Highest
Product jar package name sun Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name istack common utility code runtime Medium
Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Product Manifest implementation-build-id 3.0.12 - 7ed1368 Low
Product Manifest multi-release true Low
Product pom artifactid istack-commons-runtime Highest
Product pom groupid com.sun.istack Highest
Product pom name istack common utility code runtime High
Product pom parent-artifactid istack-commons Medium
Version file version 3.0.12 High
Version gradle version 3.0.12 Highest
Version Manifest Bundle-Version 3.0.12 High
Version Manifest implementation-build-id 3.0.12 Low
Version pom version 3.0.12 Highest
pkg:maven/com.sun.istack/istack-commons-runtime@3.0.12
(Confidence :High)
istack-commons-runtime-3.0.8.jar
Description:
istack common utility code
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.istack/istack-commons-runtime/3.0.8/d6a97364045aa6b99bf2d3c566a3f98599c2d296/istack-commons-runtime-3.0.8.jar
MD5: d8555a2f242c55d6727b4d0e82ab8446
SHA1: d6a97364045aa6b99bf2d3c566a3f98599c2d296
SHA256: 4ffabb06be454a05e4398e20c77fa2b6308d4b88dfbef7ca30a76b5b7d5505ef
Referenced In Project/Scope: server-start:compileClasspath
istack-commons-runtime-3.0.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name istack-commons-runtime High
Vendor gradle artifactid istack-commons-runtime Highest
Vendor gradle groupid com.sun.istack Highest
Vendor jar package name istack Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Vendor Manifest implementation-build-id 3.0.8-5384038, 2018-12-27T14:45:41+0000 Low
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium
Vendor pom artifactid istack-commons-runtime Low
Vendor pom groupid com.sun.istack Highest
Vendor pom name istack common utility code runtime High
Vendor pom parent-artifactid istack-commons Low
Product file name istack-commons-runtime High
Product gradle artifactid istack-commons-runtime Highest
Product jar package name istack Highest
Product jar package name sun Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name istack common utility code runtime Medium
Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Product Manifest implementation-build-id 3.0.8-5384038, 2018-12-27T14:45:41+0000 Low
Product pom artifactid istack-commons-runtime Highest
Product pom groupid com.sun.istack Highest
Product pom name istack common utility code runtime High
Product pom parent-artifactid istack-commons Medium
Version file version 3.0.8 High
Version gradle version 3.0.8 Highest
Version Manifest Bundle-Version 3.0.8 High
Version pom version 3.0.8 Highest
pkg:maven/com.sun.istack/istack-commons-runtime@3.0.8
(Confidence :High)
istack-commons-runtime-4.1.2.jar
Description:
istack common utility code
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.istack/istack-commons-runtime/4.1.2/18ec117c85f3ba0ac65409136afa8e42bc74e739/istack-commons-runtime-4.1.2.jar
MD5: 535154ef647af2a52478c4debec93659
SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739
SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee
Referenced In Project/Scope: server-start:webapps
istack-commons-runtime-4.1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name istack-commons-runtime High
Vendor gradle artifactid istack-commons-runtime Highest
Vendor gradle groupid com.sun.istack Highest
Vendor jar package name istack Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Vendor Manifest implementation-build-id 4.1.2 - 343a28e Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium
Vendor pom artifactid istack-commons-runtime Low
Vendor pom groupid com.sun.istack Highest
Vendor pom name istack common utility code runtime High
Vendor pom parent-artifactid istack-commons Low
Product file name istack-commons-runtime High
Product gradle artifactid istack-commons-runtime Highest
Product jar package name istack Highest
Product jar package name sun Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name istack common utility code runtime Medium
Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium
Product Manifest implementation-build-id 4.1.2 - 343a28e Low
Product pom artifactid istack-commons-runtime Highest
Product pom groupid com.sun.istack Highest
Product pom name istack common utility code runtime High
Product pom parent-artifactid istack-commons Medium
Version file version 4.1.2 High
Version gradle version 4.1.2 Highest
Version Manifest Bundle-Version 4.1.2 High
Version Manifest implementation-build-id 4.1.2 Low
Version pom version 4.1.2 Highest
pkg:maven/com.sun.istack/istack-commons-runtime@4.1.2
(Confidence :High)
istack-commons-tools-3.0.12.jar
Description:
istack common utility code
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.istack/istack-commons-tools/3.0.12/7213eee4e9f65972968f03c9dd4df266ce42530b/istack-commons-tools-3.0.12.jar
MD5: 466851283328c997fc3c9008ba71b869
SHA1: 7213eee4e9f65972968f03c9dd4df266ce42530b
SHA256: 88369766d2f7bf7904595d295d759ef553de47f2b9fc7d0c82a42f602ed70af0
Referenced In Project/Scope: server-start:runtimeClasspath
istack-commons-tools-3.0.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name istack-commons-tools High
Vendor gradle artifactid istack-commons-tools Highest
Vendor gradle groupid com.sun.istack Highest
Vendor jar package name com Highest
Vendor jar package name istack Highest
Vendor jar package name sun Highest
Vendor jar package name tools Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.istack.commons-tools Medium
Vendor Manifest implementation-build-id 3.0.12 - 7ed1368 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid istack-commons-tools Low
Vendor pom groupid com.sun.istack Highest
Vendor pom name istack common utility code tools High
Vendor pom parent-artifactid istack-commons Low
Product file name istack-commons-tools High
Product gradle artifactid istack-commons-tools Highest
Product jar package name com Highest
Product jar package name istack Highest
Product jar package name sun Highest
Product jar package name tools Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name istack common utility code tools Medium
Product Manifest bundle-symbolicname com.sun.istack.commons-tools Medium
Product Manifest implementation-build-id 3.0.12 - 7ed1368 Low
Product Manifest multi-release true Low
Product pom artifactid istack-commons-tools Highest
Product pom groupid com.sun.istack Highest
Product pom name istack common utility code tools High
Product pom parent-artifactid istack-commons Medium
Version file version 3.0.12 High
Version gradle version 3.0.12 Highest
Version Manifest Bundle-Version 3.0.12 High
Version Manifest implementation-build-id 3.0.12 Low
Version pom version 3.0.12 Highest
pkg:maven/com.sun.istack/istack-commons-tools@3.0.12
(Confidence :High)
j2objc-annotations-2.8.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.j2objc/j2objc-annotations/2.8/c85270e307e7b822f1086b93689124b89768e273/j2objc-annotations-2.8.jar
MD5: c50af69b704dc91050efb98e0dff66d1
SHA1: c85270e307e7b822f1086b93689124b89768e273
SHA256: f02a95fa1a5e95edb3ed859fd0fb7df709d121a35290eff8b74dce2ab7f4d6ed
Referenced In Project/Scope: server-start:compileClasspath
j2objc-annotations-2.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor gradle artifactid j2objc-annotations Highest
Vendor gradle groupid com.google.j2objc Highest
Vendor jar package name annotations Highest
Vendor jar package name annotations Low
Vendor jar package name google Highest
Vendor jar package name google Low
Vendor jar package name j2objc Highest
Vendor jar package name j2objc Low
Vendor pom artifactid j2objc-annotations Low
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product gradle artifactid j2objc-annotations Highest
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name google Highest
Product jar package name j2objc Highest
Product jar package name j2objc Low
Product pom artifactid j2objc-annotations Highest
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 2.8 High
Version gradle version 2.8 Highest
Version pom version 2.8 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@2.8
(Confidence :High)
j2objc-annotations-3.0.0.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.j2objc/j2objc-annotations/3.0.0/7399e65dd7e9ff3404f4535b2f017093bdb134c7/j2objc-annotations-3.0.0.jar
MD5: f59529b29202a5baf37f491ea5ec8627
SHA1: 7399e65dd7e9ff3404f4535b2f017093bdb134c7
SHA256: 88241573467ddca44ffd4d74aa04c2bbfd11bf7c17e0c342c94c9de7a70a7c64
Referenced In Project/Scope: server-start:webapps
j2objc-annotations-3.0.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor gradle artifactid j2objc-annotations Highest
Vendor gradle groupid com.google.j2objc Highest
Vendor jar package name annotations Highest
Vendor jar package name google Highest
Vendor jar package name j2objc Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest multi-release true Low
Vendor pom artifactid j2objc-annotations Low
Vendor pom developer email tball@google.com Low
Vendor pom developer id tomball Medium
Vendor pom developer name Tom Ball Medium
Vendor pom developer org Google Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product gradle artifactid j2objc-annotations Highest
Product jar package name annotations Highest
Product jar package name google Highest
Product jar package name j2objc Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest multi-release true Low
Product pom artifactid j2objc-annotations Highest
Product pom developer email tball@google.com Low
Product pom developer id tomball Low
Product pom developer name Tom Ball Low
Product pom developer org Google Low
Product pom developer org URL https://www.google.com Low
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 3.0.0 High
Version gradle version 3.0.0 Highest
Version pom version 3.0.0 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0
(Confidence :High)
jackson-annotations-2.20.jar
Description:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-annotations/2.20/6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c/jackson-annotations-2.20.jar
MD5: b901def3c20752817f27130e4b8d6640
SHA1: 6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c
SHA256: 959a2ffb2d591436f51f183c6a521fc89347912f711bf0cae008cdf045d95319
Referenced In Project/Scope: server-start:webapps
jackson-annotations-2.20.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-annotations High
Vendor gradle artifactid jackson-annotations Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-annotations Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-annotations High
Product gradle artifactid jackson-annotations Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest specification-title Jackson-annotations Medium
Product pom artifactid jackson-annotations Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-annotations High
Product pom parent-artifactid jackson-parent Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.20 High
Version gradle version 2.20 Highest
Version Manifest Implementation-Version 2.20 High
Version pom version 2.20 Highest
jackson-annotations-2.21.jar
Description:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-annotations/2.21/b1bc1868bf02dc0bd6c7836257a036a331005309/jackson-annotations-2.21.jar
MD5: e0d0c3e7300954f73e43c67d933aaea4
SHA1: b1bc1868bf02dc0bd6c7836257a036a331005309
SHA256: 53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b
Referenced In Project/Scope: server-start:runtimeClasspath
jackson-annotations-2.21.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-annotations High
Vendor gradle artifactid jackson-annotations Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-annotations Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-annotations High
Product gradle artifactid jackson-annotations Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest specification-title Jackson-annotations Medium
Product pom artifactid jackson-annotations Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-annotations High
Product pom parent-artifactid jackson-parent Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.21 High
Version gradle version 2.21 Highest
Version Manifest Implementation-Version 2.21 High
Version pom version 2.21 Highest
jackson-core-2.19.0.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.19.0/a90640e59ea42632a8e331ff1d6b706cf306050a/jackson-core-2.19.0.jar
MD5: d741d9cff5a56cb6f1307abe947fb7c1
SHA1: a90640e59ea42632a8e331ff1d6b706cf306050a
SHA256: da8e859bac94874528116a25f20c68560e4287acbf27628711b8a4f96b028430
Referenced In Project/Scope: server-start:compileClasspath
jackson-core-2.19.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor gradle artifactid jackson-core Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product gradle artifactid jackson-core Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.19.0 High
Version gradle version 2.19.0 Highest
Version Manifest Bundle-Version 2.19.0 High
Version Manifest Implementation-Version 2.19.0 High
Version pom version 2.19.0 Highest
jackson-core-2.20.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.20.1/5734323adfece72111769b0ae38a6cf803e3d178/jackson-core-2.20.1.jar
MD5: 889b2c417b61c9f4f460b06957147234
SHA1: 5734323adfece72111769b0ae38a6cf803e3d178
SHA256: ffab4d957daa2796cf24cb66d0b78a7090f1bcbe17c3a4578f09affaaf137089
Referenced In Project/Scope: server-start:webapps
jackson-core-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor gradle artifactid jackson-core Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product gradle artifactid jackson-core Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
jackson-core-2.21.0.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.21.0/1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28/jackson-core-2.21.0.jar
MD5: eeaf6f2d71789f1c04ba944aeaa8e18e
SHA1: 1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28
SHA256: e22604bcd9b24e462d5df102007cb06e1ed811e86f1ce6081ca62f385f2db87b
Referenced In Project/Scope: server-start:runtimeClasspath
jackson-core-2.21.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor gradle artifactid jackson-core Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product gradle artifactid jackson-core Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.21.0 High
Version gradle version 2.21.0 Highest
Version Manifest Bundle-Version 2.21.0 High
Version Manifest Implementation-Version 2.21.0 High
Version pom version 2.21.0 Highest
jackson-databind-2.20.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.20.1/9586a7fe0e1775de0e54237fa6a2c8455c93ac06/jackson-databind-2.20.1.jar
MD5: 49d7b7226df5ed4a036e48997a03d066
SHA1: 9586a7fe0e1775de0e54237fa6a2c8455c93ac06
SHA256: 34bbeb4526fff4f8565b12106bf85a6afcbae858966d489b54214ac46b2e26e8
Referenced In Project/Scope: server-start:webapps
jackson-databind-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor gradle artifactid jackson-databind Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product gradle artifactid jackson-databind Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
jackson-databind-2.21.0.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.21.0/a6b96ee168ca8734a293b6dc70acd5d495119521/jackson-databind-2.21.0.jar
MD5: 6da51758193ce8b00c39e742010b6c45
SHA1: a6b96ee168ca8734a293b6dc70acd5d495119521
SHA256: 0057817ee40bc71544072dc2a3ba575ef91dce53a2d87489bde91c05f3a22621
Referenced In Project/Scope: server-start:runtimeClasspath
jackson-databind-2.21.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor gradle artifactid jackson-databind Highest
Vendor gradle groupid com.fasterxml.jackson.core Highest
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product gradle artifactid jackson-databind Highest
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.21.0 High
Version gradle version 2.21.0 Highest
Version Manifest Bundle-Version 2.21.0 High
Version Manifest Implementation-Version 2.21.0 High
Version pom version 2.21.0 Highest
jackson-dataformat-yaml-2.20.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml/2.20.1/e6da043059c9ec631a3429ded461d5d92f240c3f/jackson-dataformat-yaml-2.20.1.jar
MD5: 66dc3c5f31150557109b14182ed7ed8a
SHA1: e6da043059c9ec631a3429ded461d5d92f240c3f
SHA256: 030f1d91f7df278e86e1ba3e129fb520871ac16ce53017c735f708823be970db
Referenced In Project/Scope: server-start:webapps
jackson-dataformat-yaml-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor gradle artifactid jackson-dataformat-yaml Highest
Vendor gradle groupid com.fasterxml.jackson.dataformat Highest
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product gradle artifactid jackson-dataformat-yaml Highest
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
jackson-datatype-jdk8-2.21.0.jar
Description:
Add-on module for Jackson (https://github.com/FasterXML/jackson) to support
JDK 8 data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.datatype/jackson-datatype-jdk8/2.21.0/2ec52647d5af910c27b34991b3127c34ae7319ca/jackson-datatype-jdk8-2.21.0.jar
MD5: c51b64b76723fb0cfb7071404dd15205
SHA1: 2ec52647d5af910c27b34991b3127c34ae7319ca
SHA256: c80ea021476de24903da7a5596989b3b5469aac2a727348878d1079960d26700
Referenced In Project/Scope: server-start:runtimeClasspath
jackson-datatype-jdk8-2.21.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jdk8 High
Vendor gradle artifactid jackson-datatype-jdk8 Highest
Vendor gradle groupid com.fasterxml.jackson.datatype Highest
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jdk8 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jdk8 Low
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: jdk8 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jdk8 High
Product gradle artifactid jackson-datatype-jdk8 Highest
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jdk8 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low
Product Manifest Bundle-Name Jackson datatype: jdk8 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium
Product Manifest Implementation-Title Jackson datatype: jdk8 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: jdk8 Medium
Product pom artifactid jackson-datatype-jdk8 Highest
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: jdk8 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.21.0 High
Version gradle version 2.21.0 Highest
Version Manifest Bundle-Version 2.21.0 High
Version Manifest Implementation-Version 2.21.0 High
Version pom version 2.21.0 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.21.0
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jackson-datatype-jsr310-2.20.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.datatype/jackson-datatype-jsr310/2.20.1/7ad06a455afc4a38412d5dab127191bdc3d90faf/jackson-datatype-jsr310-2.20.1.jar
MD5: 1ebd4e254f641f0cadf0ffdc1f662fea
SHA1: 7ad06a455afc4a38412d5dab127191bdc3d90faf
SHA256: 692be83c7e2eebb53b995c11d813c603a7d716d60c9d2d4fb9486ecb105f9291
Referenced In Project/Scope: server-start:webapps
jackson-datatype-jsr310-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor gradle artifactid jackson-datatype-jsr310 Highest
Vendor gradle groupid com.fasterxml.jackson.datatype Highest
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product gradle artifactid jackson-datatype-jsr310 Highest
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.20.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.20.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jackson-datatype-jsr310-2.21.0.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.datatype/jackson-datatype-jsr310/2.21.0/19aeeb3523112059e0ee7a859d337c0842f10af/jackson-datatype-jsr310-2.21.0.jar
MD5: 87cbf6f62ac03289225809efd6fb6698
SHA1: 019aeeb3523112059e0ee7a859d337c0842f10af
SHA256: b350169a3b2cc53d781541fe1bfbc0f00c978d185884da79b8330be8fb7aefeb
Referenced In Project/Scope: server-start:runtimeClasspath
jackson-datatype-jsr310-2.21.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor gradle artifactid jackson-datatype-jsr310 Highest
Vendor gradle groupid com.fasterxml.jackson.datatype Highest
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product gradle artifactid jackson-datatype-jsr310 Highest
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.21.0 High
Version gradle version 2.21.0 Highest
Version Manifest Bundle-Version 2.21.0 High
Version Manifest Implementation-Version 2.21.0 High
Version pom version 2.21.0 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.0
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jackson-jakarta-rs-base-2.20.1.jar
Description:
Pile of code that is shared by all Jackson-based Jakarta-RS
providers.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base/2.20.1/af3b69315b94fc27943f064e1686232d70ab0435/jackson-jakarta-rs-base-2.20.1.jar
MD5: b3f4d58e89ee7279c07191cb8b6746f1
SHA1: af3b69315b94fc27943f064e1686232d70ab0435
SHA256: 9761eecd67b0c4a831f02d378f2a63d3f4ea8bdde5919c7b9b225a9326026650
Referenced In Project/Scope: server-start:webapps
jackson-jakarta-rs-base-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-jakarta-rs-base High
Vendor gradle artifactid jackson-jakarta-rs-base Highest
Vendor gradle groupid com.fasterxml.jackson.jakarta.rs Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jakarta Highest
Vendor jar package name rs Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-base Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jakarta.rs Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-jakarta-rs-base Low
Vendor pom groupid com.fasterxml.jackson.jakarta.rs Highest
Vendor pom name Jackson Jakarta-RS: base High
Vendor pom parent-artifactid jackson-jakarta-rs-providers Low
Product file name jackson-jakarta-rs-base High
Product gradle artifactid jackson-jakarta-rs-base Highest
Product jar package name 11 Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jakarta Highest
Product jar package name rs Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-base Low
Product Manifest Bundle-Name Jackson Jakarta-RS: base Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base Medium
Product Manifest Implementation-Title Jackson Jakarta-RS: base High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson Jakarta-RS: base Medium
Product pom artifactid jackson-jakarta-rs-base Highest
Product pom groupid com.fasterxml.jackson.jakarta.rs Highest
Product pom name Jackson Jakarta-RS: base High
Product pom parent-artifactid jackson-jakarta-rs-providers Medium
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base@2.20.1
(Confidence :High)
jackson-jakarta-rs-json-provider-2.20.1.jar
Description:
Functionality to handle JSON input/output for Jakarta-RS implementations
(like Jersey and RESTeasy) using standard Jackson data binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider/2.20.1/41b2719b93949427d30b573c3c997459e86bfa94/jackson-jakarta-rs-json-provider-2.20.1.jar
MD5: 2b7062b6587e7b3c8ded16f38dc3eff6
SHA1: 41b2719b93949427d30b573c3c997459e86bfa94
SHA256: 3bc6d1af62588c504160c1155347b1b3a15288e5e3f35156eb1bed4bd940dcdd
Referenced In Project/Scope: server-start:webapps
jackson-jakarta-rs-json-provider-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-jakarta-rs-json-provider High
Vendor gradle artifactid jackson-jakarta-rs-json-provider Highest
Vendor gradle groupid com.fasterxml.jackson.jakarta.rs Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jakarta Highest
Vendor jar package name rs Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-json-provider Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jakarta.rs Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-jakarta-rs-json-provider Low
Vendor pom groupid com.fasterxml.jackson.jakarta.rs Highest
Vendor pom name Jackson Jakarta-RS: JSON High
Vendor pom parent-artifactid jackson-jakarta-rs-providers Low
Product file name jackson-jakarta-rs-json-provider High
Product gradle artifactid jackson-jakarta-rs-json-provider Highest
Product jar package name 11 Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jakarta Highest
Product jar package name rs Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-json-provider Low
Product Manifest Bundle-Name Jackson Jakarta-RS: JSON Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider Medium
Product Manifest Implementation-Title Jackson Jakarta-RS: JSON High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson Jakarta-RS: JSON Medium
Product pom artifactid jackson-jakarta-rs-json-provider Highest
Product pom groupid com.fasterxml.jackson.jakarta.rs Highest
Product pom name Jackson Jakarta-RS: JSON High
Product pom parent-artifactid jackson-jakarta-rs-providers Medium
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.20.1
(Confidence :High)
jackson-jaxrs-base-2.20.1.jar
Description:
Pile of code that is shared by all Jackson-based JAX-RS
providers.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.jaxrs/jackson-jaxrs-base/2.20.1/a78feea452f2c83ce5307d9835c66d55b6160f2f/jackson-jaxrs-base-2.20.1.jar
MD5: 0b51c8ee8c7437553e43d4172ccbef6c
SHA1: a78feea452f2c83ce5307d9835c66d55b6160f2f
SHA256: d34944bd5666bd4db02882185c43551dbde0801286fe7c2c5b43a5b5dcca1d1e
Referenced In Project/Scope: server-start:webapps
jackson-jaxrs-base-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-jaxrs-base High
Vendor gradle artifactid jackson-jaxrs-base Highest
Vendor gradle groupid com.fasterxml.jackson.jaxrs Highest
Vendor jar package name base Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jaxrs Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jaxrs-providers/jackson-jaxrs-base Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jaxrs.jackson-jaxrs-base Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jaxrs Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-jaxrs-base Low
Vendor pom groupid com.fasterxml.jackson.jaxrs Highest
Vendor pom name Jackson-JAXRS: base High
Vendor pom parent-artifactid jackson-jaxrs-providers Low
Product file name jackson-jaxrs-base High
Product gradle artifactid jackson-jaxrs-base Highest
Product jar package name base Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jaxrs Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jaxrs-providers/jackson-jaxrs-base Low
Product Manifest Bundle-Name Jackson-JAXRS: base Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.jaxrs.jackson-jaxrs-base Medium
Product Manifest Implementation-Title Jackson-JAXRS: base High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-JAXRS: base Medium
Product pom artifactid jackson-jaxrs-base Highest
Product pom groupid com.fasterxml.jackson.jaxrs Highest
Product pom name Jackson-JAXRS: base High
Product pom parent-artifactid jackson-jaxrs-providers Medium
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.jaxrs/jackson-jaxrs-base@2.20.1
(Confidence :High)
jackson-jaxrs-json-provider-2.20.1.jar
Description:
Functionality to handle JSON input/output for JAX-RS implementations (like Jersey and RESTeasy) using standard Jackson data binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.jaxrs/jackson-jaxrs-json-provider/2.20.1/83b9ae70d2c10458c76e1871851d477f8ca689e6/jackson-jaxrs-json-provider-2.20.1.jar
MD5: f9ed39b3e5b92d54e8d1c58ba6d0d7f4
SHA1: 83b9ae70d2c10458c76e1871851d477f8ca689e6
SHA256: 74ea814ca7cd6a83a1c474f7c90f4061d5034079deaee0e0e8f9477b219e8871
Referenced In Project/Scope: server-start:webapps
jackson-jaxrs-json-provider-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-jaxrs-json-provider High
Vendor gradle artifactid jackson-jaxrs-json-provider Highest
Vendor gradle groupid com.fasterxml.jackson.jaxrs Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jaxrs Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jaxrs-providers/jackson-jaxrs-json-provider Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jaxrs.jackson-jaxrs-json-provider Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jaxrs Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-jaxrs-json-provider Low
Vendor pom groupid com.fasterxml.jackson.jaxrs Highest
Vendor pom name Jackson-JAXRS: JSON High
Vendor pom parent-artifactid jackson-jaxrs-providers Low
Product file name jackson-jaxrs-json-provider High
Product gradle artifactid jackson-jaxrs-json-provider Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jaxrs Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jaxrs-providers/jackson-jaxrs-json-provider Low
Product Manifest Bundle-Name Jackson-JAXRS: JSON Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.jaxrs.jackson-jaxrs-json-provider Medium
Product Manifest Implementation-Title Jackson-JAXRS: JSON High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-JAXRS: JSON Medium
Product pom artifactid jackson-jaxrs-json-provider Highest
Product pom groupid com.fasterxml.jackson.jaxrs Highest
Product pom name Jackson-JAXRS: JSON High
Product pom parent-artifactid jackson-jaxrs-providers Medium
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.jaxrs/jackson-jaxrs-json-provider@2.20.1
(Confidence :High)
jackson-module-jakarta-xmlbind-annotations-2.20.1.jar
Description:
Support for using Jakarta XML Bind (aka JAXB 3.0) annotations as an alternative
to "native" Jackson annotations, for configuring data-binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations/2.20.1/15e386d9151f5964dc28fd25c28660d1262b8898/jackson-module-jakarta-xmlbind-annotations-2.20.1.jar
MD5: 249a6e812de8ed3f68fd72af918ef2f9
SHA1: 15e386d9151f5964dc28fd25c28660d1262b8898
SHA256: 0d5710d2e38b1567edf4acc0d7b9aeb6610f57b901cec9b42548872d421619d1
Referenced In Project/Scope: server-start:webapps
jackson-module-jakarta-xmlbind-annotations-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-module-jakarta-xmlbind-annotations High
Vendor gradle artifactid jackson-module-jakarta-xmlbind-annotations Highest
Vendor gradle groupid com.fasterxml.jackson.module Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jakarta Highest
Vendor jar package name module Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-module-jakarta-xmlbind-annotations Low
Vendor pom groupid com.fasterxml.jackson.module Highest
Vendor pom name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High
Vendor pom parent-artifactid jackson-modules-base Low
Vendor pom url FasterXML/jackson-modules-base Highest
Product file name jackson-module-jakarta-xmlbind-annotations High
Product gradle artifactid jackson-module-jakarta-xmlbind-annotations Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jakarta Highest
Product jar package name module Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low
Product Manifest Bundle-Name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations Medium
Product Manifest Implementation-Title Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) Medium
Product pom artifactid jackson-module-jakarta-xmlbind-annotations Highest
Product pom groupid com.fasterxml.jackson.module Highest
Product pom name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High
Product pom parent-artifactid jackson-modules-base Medium
Product pom url FasterXML/jackson-modules-base High
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations@2.20.1
(Confidence :High)
jackson-module-jaxb-annotations-2.20.1.jar
Description:
Support for using JAXB annotations as an alternative to "native" Jackson annotations,
for configuring data-binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.jackson.module/jackson-module-jaxb-annotations/2.20.1/6002a78c8a8cdde2f2195daac5591ee424d1d4ac/jackson-module-jaxb-annotations-2.20.1.jar
MD5: a1399afede95b690d650a3a1f721f729
SHA1: 6002a78c8a8cdde2f2195daac5591ee424d1d4ac
SHA256: 0b4c0cf84bb9e5251d29743fc0488d5414b0ac6e20fa4ac87d0754b8d4d78a05
Referenced In Project/Scope: server-start:webapps
jackson-module-jaxb-annotations-2.20.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jackson-module-jaxb-annotations High
Vendor gradle artifactid jackson-module-jaxb-annotations Highest
Vendor gradle groupid com.fasterxml.jackson.module Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jaxb Highest
Vendor jar package name module Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jaxb-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-module-jaxb-annotations Low
Vendor pom groupid com.fasterxml.jackson.module Highest
Vendor pom name Jackson module: Old JAXB Annotations (javax.xml.bind) High
Vendor pom parent-artifactid jackson-modules-base Low
Vendor pom url FasterXML/jackson-modules-base Highest
Product file name jackson-module-jaxb-annotations High
Product gradle artifactid jackson-module-jaxb-annotations Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jaxb Highest
Product jar package name module Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low
Product Manifest Bundle-Name Jackson module: Old JAXB Annotations (javax.xml.bind) Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jaxb-annotations Medium
Product Manifest Implementation-Title Jackson module: Old JAXB Annotations (javax.xml.bind) High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson module: Old JAXB Annotations (javax.xml.bind) Medium
Product pom artifactid jackson-module-jaxb-annotations Highest
Product pom groupid com.fasterxml.jackson.module Highest
Product pom name Jackson module: Old JAXB Annotations (javax.xml.bind) High
Product pom parent-artifactid jackson-modules-base Medium
Product pom url FasterXML/jackson-modules-base High
Version file version 2.20.1 High
Version gradle version 2.20.1 Highest
Version Manifest Bundle-Version 2.20.1 High
Version Manifest Implementation-Version 2.20.1 High
Version pom version 2.20.1 Highest
pkg:maven/com.fasterxml.jackson.module/jackson-module-jaxb-annotations@2.20.1
(Confidence :High)
jai_imageio-1.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.media/jai_imageio/1.1/ce14f7375da96d8300356f2b7cf4e89e523b22cf/jai_imageio-1.1.jar
MD5: de045bb7c4367be74ce7a1e50d400a47
SHA1: ce14f7375da96d8300356f2b7cf4e89e523b22cf
SHA256: 600768eabd63f92e4ba503d956f540c7d3382e4e2425058e60879b9282232e40
Referenced In Project/Scope: server-start:runtimeClasspath
jai_imageio-1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jai_imageio High
Vendor gradle artifactid jai_imageio Highest
Vendor gradle groupid com.sun.media Highest
Vendor jar package name imageio Highest
Vendor jar package name media Highest
Vendor jar package name media Low
Vendor jar package name sun Highest
Vendor jar package name sun Low
Vendor jar (hint) package name oracle Highest
Vendor jar (hint) package name oracle Low
Vendor Manifest extension-name com.sun.media.imageio Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid jai_imageio Low
Vendor pom groupid com.sun.media Highest
Product file name jai_imageio High
Product gradle artifactid jai_imageio Highest
Product jar package name image Highest
Product jar package name imageio Highest
Product jar package name media Highest
Product jar package name media Low
Product jar package name plugins Low
Product jar package name sun Highest
Product Manifest extension-name com.sun.media.imageio Medium
Product Manifest Implementation-Title com.sun.media.imageio High
Product Manifest specification-title Java Advanced Imaging Image I/O Tools Medium
Product pom artifactid jai_imageio Highest
Product pom groupid com.sun.media Highest
Version file version 1.1 High
Version gradle version 1.1 Highest
Version Manifest Implementation-Version 1.1 High
Version pom version 1.1 Highest
pkg:maven/com.sun.media/jai_imageio@1.1
(Confidence :High)
jakarta.activation-1.2.2.jar
Description:
Jakarta Activation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.activation/jakarta.activation/1.2.2/74548703f9851017ce2f556066659438019e7eb5/jakarta.activation-1.2.2.jar
MD5: 0b8bee3bf29b9a015f8b992035581a7c
SHA1: 74548703f9851017ce2f556066659438019e7eb5
SHA256: 02156773e4ae9d048d14a56ad35d644bee9f1052a791d072df3ded3c656e6e1a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.activation-1.2.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation High
Vendor gradle artifactid jakarta.activation Highest
Vendor gradle groupid com.sun.activation Highest
Vendor jar package name activation Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation Low
Vendor pom groupid com.sun.activation Highest
Vendor pom name Jakarta Activation High
Vendor pom parent-artifactid all Low
Product file name jakarta.activation High
Product gradle artifactid jakarta.activation Highest
Product jar package name activation Highest
Product jar package name javax Highest
Product jar package name sun Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation Medium
Product Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest Implementation-Title javax.activation High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation Highest
Product pom groupid com.sun.activation Highest
Product pom name Jakarta Activation High
Product pom parent-artifactid all Medium
Version file version 1.2.2 High
Version gradle version 1.2.2 Highest
Version Manifest Bundle-Version 1.2.2 High
Version Manifest Implementation-Version 1.2.2 High
Version pom version 1.2.2 Highest
pkg:maven/com.sun.activation/jakarta.activation@1.2.2
(Confidence :High)
jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.activation/jakarta.activation-api/2.1.3/fa165bd70cda600368eee31555222776a46b881f/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.activation-api-2.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor gradle artifactid jakarta.activation-api Highest
Vendor gradle groupid jakarta.activation Highest
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product gradle artifactid jakarta.activation-api Highest
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version gradle version 2.1.3 Highest
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
jakarta.activation-api-2.1.4.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.activation/jakarta.activation-api/2.1.4/9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8/jakarta.activation-api-2.1.4.jar
MD5: bc1602eee7bc61a0b86f14bbbb0cc794
SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8
SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004
Referenced In Project/Scope: server-start:webapps
jakarta.activation-api-2.1.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor gradle artifactid jakarta.activation-api Highest
Vendor gradle groupid jakarta.activation Highest
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 3dad341 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product gradle artifactid jakarta.activation-api Highest
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 3dad341 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.4 High
Version gradle version 2.1.4 Highest
Version Manifest Bundle-Version 2.1.4 High
Version pom parent-version 2.1.4 Low
Version pom version 2.1.4 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.4
(Confidence :High)
jakarta.annotation-api-2.1.1.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.annotation/jakarta.annotation-api/2.1.1/48b9bda22b091b1f48b13af03fe36db3be6e1ae3/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
jakarta.annotation-api-2.1.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor gradle artifactid jakarta.annotation-api Highest
Vendor gradle groupid jakarta.annotation Highest
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product gradle artifactid jakarta.annotation-api Highest
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 2.1.1 High
Version gradle version 2.1.1 Highest
Version Manifest Bundle-Version 2.1.1 High
Version Manifest Implementation-Version 2.1.1 High
Version pom parent-version 2.1.1 Low
Version pom version 2.1.1 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1
(Confidence :High)
cpe:2.3:a:oracle:projects:2.1.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.authentication-api-3.1.0.jar
Description:
Jakarta Authentication defines a general low-level SPI for authentication mechanisms, which are controllers
that interact with a caller and a container's environment to obtain the caller's credentials, validate these,
and pass an authenticated identity (such as name and groups) to the container.
Jakarta Authentication consists of several profiles, with each profile telling how a specific container
(such as Jakarta Servlet) can integrate with- and adapt to this SPI.
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.authentication/jakarta.authentication-api/3.1.0/d06859cab1228a7524bf620a0daf120dc979ecae/jakarta.authentication-api-3.1.0.jar
MD5: 38948ed95369103e7ec3eafbbde0e627
SHA1: d06859cab1228a7524bf620a0daf120dc979ecae
SHA256: 07307889ba23d7152b6735a30b660207cc1783807cb7b76ebf15e305a6572e7e
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.authentication-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.authentication-api High
Vendor gradle artifactid jakarta.authentication-api Highest
Vendor gradle groupid jakarta.authentication Highest
Vendor jar package name auth Highest
Vendor jar package name jakarta Highest
Vendor jar package name message Highest
Vendor jar package name security Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/jakartaee/authentication Low
Vendor Manifest bundle-symbolicname jakarta.security.auth.message-api Medium
Vendor Manifest extension-name jakarta.security.auth.message Medium
Vendor Manifest Implementation-Vendor Jakarta Authentication High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jakarta.authentication-api Low
Vendor pom developer email arjan.tijms@gmail.com Low
Vendor pom developer id atijms Medium
Vendor pom developer id yaminikb Medium
Vendor pom developer name Arjan Tijms Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.authentication Highest
Vendor pom name Jakarta Authentication High
Vendor pom url jakartaee/authentication Highest
Product file name jakarta.authentication-api High
Product gradle artifactid jakarta.authentication-api Highest
Product jar package name auth Highest
Product jar package name jakarta Highest
Product jar package name message Highest
Product jar package name security Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/jakartaee/authentication Low
Product Manifest Bundle-Name Jakarta Authentication Medium
Product Manifest bundle-symbolicname jakarta.security.auth.message-api Medium
Product Manifest extension-name jakarta.security.auth.message Medium
Product pom artifactid jakarta.authentication-api Highest
Product pom developer email arjan.tijms@gmail.com Low
Product pom developer id atijms Low
Product pom developer id yaminikb Low
Product pom developer name Arjan Tijms Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.authentication Highest
Product pom name Jakarta Authentication High
Product pom url jakartaee/authentication High
Version file version 3.1.0 High
Version gradle version 3.1.0 Highest
Version Manifest Bundle-Version 3.1.0 High
Version Manifest Implementation-Version 3.1.0 High
Version pom version 3.1.0 Highest
pkg:maven/jakarta.authentication/jakarta.authentication-api@3.1.0
(Confidence :High)
jakarta.enterprise.cdi-api-4.0.1.jar
Description:
APIs for CDI (Contexts and Dependency Injection for Java)
License:
Apache License 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.enterprise/jakarta.enterprise.cdi-api/4.0.1/2012f388c6de83e29101cbf82c3ed2bd37931c64/jakarta.enterprise.cdi-api-4.0.1.jar
MD5: 4ddecd5a6280ef5f222e693ce9d29898
SHA1: 2012f388c6de83e29101cbf82c3ed2bd37931c64
SHA256: beaf74c4f2618189309e3f4a09c43effab633dd96aa1f6dc58a6ba7ee0042717
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.enterprise.cdi-api-4.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.enterprise.cdi-api High
Vendor gradle artifactid jakarta.enterprise.cdi-api Highest
Vendor gradle groupid jakarta.enterprise Highest
Vendor jar package name enterprise Highest
Vendor jar package name jakarta Highest
Vendor Manifest automatic-module-name jakarta.cdi Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://jboss.org Low
Vendor Manifest bundle-symbolicname jakarta.enterprise.cdi-api Medium
Vendor pom artifactid jakarta.enterprise.cdi-api Low
Vendor pom developer email asd[at]redhat[dot]com Low
Vendor pom developer email johndament[at]apache[dot]org Low
Vendor pom developer email manovotn[at]redhat[dot]com Low
Vendor pom developer email mkouba[at]redhat[dot]com Low
Vendor pom developer email mpaluch[at]paluch[dot]biz Low
Vendor pom developer email struberg[at]yahoo[dot]de Low
Vendor pom developer email tremes[at]redhat[dot]com Low
Vendor pom developer id asabotdu Medium
Vendor pom developer id johndament Medium
Vendor pom developer id manovotn Medium
Vendor pom developer id mkouba Medium
Vendor pom developer id mp911de Medium
Vendor pom developer id mstruberg Medium
Vendor pom developer id tremes Medium
Vendor pom developer name Antoine Sabot-Durand Medium
Vendor pom developer name John D. Ament Medium
Vendor pom developer name Mark Paluch Medium
Vendor pom developer name Mark Struberg Medium
Vendor pom developer name Martin Kouba Medium
Vendor pom developer name Matej Novotny Medium
Vendor pom developer name Tomas Remes Medium
Vendor pom developer org Independent Medium
Vendor pom developer org Red Hat Inc. Medium
Vendor pom groupid jakarta.enterprise Highest
Vendor pom name CDI APIs High
Vendor pom organization name JBoss by Red Hat, Inc. High
Vendor pom organization url https://jboss.org Medium
Vendor pom parent-artifactid jakarta.enterprise.cdi-parent Low
Vendor pom url http://cdi-spec.org Highest
Product file name jakarta.enterprise.cdi-api High
Product gradle artifactid jakarta.enterprise.cdi-api Highest
Product jar package name enterprise Highest
Product jar package name jakarta Highest
Product Manifest automatic-module-name jakarta.cdi Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://jboss.org Low
Product Manifest Bundle-Name CDI APIs Medium
Product Manifest bundle-symbolicname jakarta.enterprise.cdi-api Medium
Product pom artifactid jakarta.enterprise.cdi-api Highest
Product pom developer email asd[at]redhat[dot]com Low
Product pom developer email johndament[at]apache[dot]org Low
Product pom developer email manovotn[at]redhat[dot]com Low
Product pom developer email mkouba[at]redhat[dot]com Low
Product pom developer email mpaluch[at]paluch[dot]biz Low
Product pom developer email struberg[at]yahoo[dot]de Low
Product pom developer email tremes[at]redhat[dot]com Low
Product pom developer id asabotdu Low
Product pom developer id johndament Low
Product pom developer id manovotn Low
Product pom developer id mkouba Low
Product pom developer id mp911de Low
Product pom developer id mstruberg Low
Product pom developer id tremes Low
Product pom developer name Antoine Sabot-Durand Low
Product pom developer name John D. Ament Low
Product pom developer name Mark Paluch Low
Product pom developer name Mark Struberg Low
Product pom developer name Martin Kouba Low
Product pom developer name Matej Novotny Low
Product pom developer name Tomas Remes Low
Product pom developer org Independent Low
Product pom developer org Red Hat Inc. Low
Product pom groupid jakarta.enterprise Highest
Product pom name CDI APIs High
Product pom organization name JBoss by Red Hat, Inc. Low
Product pom organization url https://jboss.org Low
Product pom parent-artifactid jakarta.enterprise.cdi-parent Medium
Product pom url http://cdi-spec.org Medium
Version file version 4.0.1 High
Version gradle version 4.0.1 Highest
Version Manifest Bundle-Version 4.0.1 High
Version pom version 4.0.1 Highest
pkg:maven/jakarta.enterprise/jakarta.enterprise.cdi-api@4.0.1
(Confidence :High)
cpe:2.3:a:redhat:enterprise_ipa:4.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.enterprise.lang-model-4.0.1.jar
Description:
Build Compatible (Reflection-Free) Java Language Model for CDI
License:
Apache License 2.0: https://repository.jboss.org/licenses/apache-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.enterprise/jakarta.enterprise.lang-model/4.0.1/2b195781faad31c1724d8122136909c34c3ae79e/jakarta.enterprise.lang-model-4.0.1.jar
MD5: fe02deb673794ba67c5e423bcca3d229
SHA1: 2b195781faad31c1724d8122136909c34c3ae79e
SHA256: 53acafe65b6ef0195fa1b8a0ef2650e5aa024c32cb4059c4df372d6b32089cd3
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.enterprise.lang-model-4.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.enterprise.lang-model High
Vendor gradle artifactid jakarta.enterprise.lang-model Highest
Vendor gradle groupid jakarta.enterprise Highest
Vendor jar package name enterprise Highest
Vendor jar package name jakarta Highest
Vendor jar package name lang Highest
Vendor jar package name model Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.enterprise.lang-model Medium
Vendor pom artifactid jakarta.enterprise.lang-model Low
Vendor pom groupid jakarta.enterprise Highest
Vendor pom name CDI Language Model High
Vendor pom parent-artifactid jakarta.enterprise.cdi-parent Low
Product file name jakarta.enterprise.lang-model High
Product gradle artifactid jakarta.enterprise.lang-model Highest
Product jar package name enterprise Highest
Product jar package name jakarta Highest
Product jar package name lang Highest
Product jar package name model Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name CDI Language Model Medium
Product Manifest bundle-symbolicname jakarta.enterprise.lang-model Medium
Product pom artifactid jakarta.enterprise.lang-model Highest
Product pom groupid jakarta.enterprise Highest
Product pom name CDI Language Model High
Product pom parent-artifactid jakarta.enterprise.cdi-parent Medium
Version file version 4.0.1 High
Version gradle version 4.0.1 Highest
Version Manifest Bundle-Version 4.0.1 High
Version pom version 4.0.1 Highest
pkg:maven/jakarta.enterprise/jakarta.enterprise.lang-model@4.0.1
(Confidence :High)
jakarta.inject-api-2.0.1.jar
Description:
Jakarta Dependency Injection
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.inject/jakarta.inject-api/2.0.1/4c28afe1991a941d7702fe1362c365f0a8641d1e/jakarta.inject-api-2.0.1.jar
MD5: 72003bf6efcc8455d414bbd7da86c11c
SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e
SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
jakarta.inject-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.inject-api High
Vendor gradle artifactid jakarta.inject-api Highest
Vendor gradle groupid jakarta.inject Highest
Vendor jar package name inject Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium
Vendor pom artifactid jakarta.inject-api Low
Vendor pom developer email asd[at]redhat[dot]com Low
Vendor pom developer email manovotn[at]redhat[dot]com Low
Vendor pom developer email mkouba[at]redhat[dot]com Low
Vendor pom developer email tremes[at]redhat[dot]com Low
Vendor pom developer id asabotdu Medium
Vendor pom developer id manovotn Medium
Vendor pom developer id mkouba Medium
Vendor pom developer id tremes Medium
Vendor pom developer name Antoine Sabot-Durand Medium
Vendor pom developer name Martin Kouba Medium
Vendor pom developer name Matej Novotny Medium
Vendor pom developer name Tomas Remes Medium
Vendor pom developer org Red Hat Inc. Medium
Vendor pom groupid jakarta.inject Highest
Vendor pom name Jakarta Dependency Injection High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/injection-api Highest
Product file name jakarta.inject-api High
Product gradle artifactid jakarta.inject-api Highest
Product jar package name inject Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Dependency Injection Medium
Product Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium
Product pom artifactid jakarta.inject-api Highest
Product pom developer email asd[at]redhat[dot]com Low
Product pom developer email manovotn[at]redhat[dot]com Low
Product pom developer email mkouba[at]redhat[dot]com Low
Product pom developer email tremes[at]redhat[dot]com Low
Product pom developer id asabotdu Low
Product pom developer id manovotn Low
Product pom developer id mkouba Low
Product pom developer id tremes Low
Product pom developer name Antoine Sabot-Durand Low
Product pom developer name Martin Kouba Low
Product pom developer name Matej Novotny Low
Product pom developer name Tomas Remes Low
Product pom developer org Red Hat Inc. Low
Product pom groupid jakarta.inject Highest
Product pom name Jakarta Dependency Injection High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/injection-api High
Version file version 2.0.1 High
Version gradle version 2.0.1 Highest
Version Manifest Bundle-Version 2.0.1 High
Version pom parent-version 2.0.1 Low
Version pom version 2.0.1 Highest
pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1
(Confidence :High)
jakarta.interceptor-api-2.1.0.jar
Description:
Jakarta Interceptors defines a means of interposing on business method invocations
and specific events—such as lifecycle events and timeout events—that occur on instances
of Jakarta EE components and other managed classes.
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.interceptor/jakarta.interceptor-api/2.1.0/1d06a662708601400af4556577ee514c4ad01549/jakarta.interceptor-api-2.1.0.jar
MD5: c68f893a96a6ddbcd08c09d508ae0040
SHA1: 1d06a662708601400af4556577ee514c4ad01549
SHA256: ef787d3f713fc6ff4f02cd4b0dbed08f93d8af3400c90cbb43fb4b5c0583710b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.interceptor-api-2.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.interceptor-api High
Vendor gradle artifactid jakarta.interceptor-api Highest
Vendor gradle groupid jakarta.interceptor Highest
Vendor jar package name interceptor Highest
Vendor jar package name interceptors Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.interceptor-api Medium
Vendor Manifest extension-name jakarta.interceptor Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jakarta.interceptor-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.interceptor Highest
Vendor pom name Jakarta Interceptors High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/interceptor-api Highest
Product file name jakarta.interceptor-api High
Product gradle artifactid jakarta.interceptor-api Highest
Product jar package name interceptor Highest
Product jar package name interceptors Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Interceptors Medium
Product Manifest bundle-symbolicname jakarta.interceptor-api Medium
Product Manifest extension-name jakarta.interceptor Medium
Product pom artifactid jakarta.interceptor-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.interceptor Highest
Product pom name Jakarta Interceptors High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/interceptor-api High
Version file version 2.1.0 High
Version gradle version 2.1.0 Highest
Version Manifest Bundle-Version 2.1.0 High
Version Manifest Implementation-Version 2.1.0 High
Version pom parent-version 2.1.0 Low
Version pom version 2.1.0 Highest
pkg:maven/jakarta.interceptor/jakarta.interceptor-api@2.1.0
(Confidence :High)
jakarta.jms-api-2.0.3.jar
Description:
Jakarta Messaging describes a means for Java applications to create, send,
and receive messages via loosely coupled, reliable asynchronous communication services.
License:
Eclipse Public License 2.0: https://projects.eclipse.org/license/epl-2.0
GNU General Public License, version 2 with the GNU Classpath Exception: https://projects.eclipse.org/license/secondary-gpl-2.0-cp
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.jms/jakarta.jms-api/2.0.3/c3267a1a8129ba26e1093e7b51ae296891c5fa17/jakarta.jms-api-2.0.3.jar
MD5: 569d6b710a850e4198e0e56c5a337e3d
SHA1: c3267a1a8129ba26e1093e7b51ae296891c5fa17
SHA256: 5940937cb1095764a0039dae147395e37528a0575e2366f4dd20713b7785044a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.jms-api-2.0.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.jms-api High
Vendor gradle artifactid jakarta.jms-api Highest
Vendor gradle groupid jakarta.jms Highest
Vendor jar package name javax Highest
Vendor jar package name jms Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.jms-api Medium
Vendor Manifest extension-name javax.jms Medium
Vendor Manifest Implementation-Vendor-Id org.eclipse.ee4j.jms Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.jms-api Low
Vendor pom groupid jakarta.jms Highest
Vendor pom name Jakarta Messaging API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jms Highest
Product file name jakarta.jms-api High
Product gradle artifactid jakarta.jms-api Highest
Product jar package name javax Highest
Product jar package name jms Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Messaging API Medium
Product Manifest bundle-symbolicname jakarta.jms-api Medium
Product Manifest extension-name javax.jms Medium
Product pom artifactid jakarta.jms-api Highest
Product pom groupid jakarta.jms Highest
Product pom name Jakarta Messaging API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.jms Medium
Version file version 2.0.3 High
Version gradle version 2.0.3 Highest
Version Manifest Bundle-Version 2.0.3 High
Version Manifest Implementation-Version 2.0.3 High
Version pom parent-version 2.0.3 Low
Version pom version 2.0.3 Highest
pkg:maven/jakarta.jms/jakarta.jms-api@2.0.3
(Confidence :High)
jakarta.jws-api-2.1.0.jar
Description:
Jakarta Web Services Metadata API
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.jws/jakarta.jws-api/2.1.0/7d283ef13e49c1422701e30639371edca788c609/jakarta.jws-api-2.1.0.jar
MD5: 9e3bc505722b1e84535d7edb3d582ca1
SHA1: 7d283ef13e49c1422701e30639371edca788c609
SHA256: d4c321f47a72001977fa11d2df408db23bf5f46e954aeb2c6f1ecda4dfef8fd8
Referenced In Project/Scope: server-start:runtimeClasspath
jakarta.jws-api-2.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.jws-api High
Vendor gradle artifactid jakarta.jws-api Highest
Vendor gradle groupid jakarta.jws Highest
Vendor jar package name jws Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.jws-api Medium
Vendor Manifest extension-name jakarta.jws Medium
Vendor Manifest implementation-build-id 2.1.0-RELEASE-2072849 Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.jws-api Low
Vendor pom developer id lukasj Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.jws Highest
Vendor pom name Jakarta Web Services Metadata API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/jws-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.jws-api High
Product gradle artifactid jakarta.jws-api Highest
Product jar package name jws Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Web Services Metadata API Medium
Product Manifest bundle-symbolicname jakarta.jws-api Medium
Product Manifest extension-name jakarta.jws Medium
Product Manifest implementation-build-id 2.1.0-RELEASE-2072849 Low
Product pom artifactid jakarta.jws-api Highest
Product pom developer id lukasj Low
Product pom developer name Lukas Jungmann Low
Product pom developer org Oracle Low
Product pom groupid jakarta.jws Highest
Product pom name Jakarta Web Services Metadata API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/jws-api High
Version file version 2.1.0 High
Version gradle version 2.1.0 Highest
Version Manifest Bundle-Version 2.1.0 High
Version Manifest Implementation-Version 2.1.0 High
Version pom parent-version 2.1.0 Low
Version pom version 2.1.0 Highest
pkg:maven/jakarta.jws/jakarta.jws-api@2.1.0
(Confidence :High)
cpe:2.3:a:oracle:web_services:2.1.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.mail-1.6.8.jar
Description:
Jakarta Mail API
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.mail/jakarta.mail/1.6.8/ec7e870b0c62734336d464f5cbfb410b2169e3fe/jakarta.mail-1.6.8.jar
MD5: 25b908bfd32b2d6bcf2c14521b5f4286
SHA1: ec7e870b0c62734336d464f5cbfb410b2169e3fe
SHA256: c83f1a1ed580a35878957de7367071be27026d02d34ace6267d0c3da23e193c2
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.mail-1.6.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail High
Vendor gradle artifactid jakarta.mail Highest
Vendor gradle groupid com.sun.mail Highest
Vendor jar package name javax Highest
Vendor jar package name mail Highest
Vendor jar package name provider Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname com.sun.mail.jakarta.mail Medium
Vendor Manifest extension-name javax.mail Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Vendor Manifest specification-vendor Oracle Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor Manifest (hint) specification-vendor sun Low
Vendor pom artifactid jakarta.mail Low
Vendor pom groupid com.sun.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid all Low
Product file name jakarta.mail High
Product gradle artifactid jakarta.mail Highest
Product jar package name javax Highest
Product jar package name mail Highest
Product jar package name provider Highest
Product jar package name sun Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname com.sun.mail.jakarta.mail Medium
Product Manifest extension-name javax.mail Medium
Product Manifest Implementation-Title javax.mail High
Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Product Manifest specification-title Jakarta Mail API Design Specification Medium
Product pom artifactid jakarta.mail Highest
Product pom groupid com.sun.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid all Medium
Version file version 1.6.8 High
Version gradle version 1.6.8 Highest
Version Manifest Bundle-Version 1.6.8 High
Version Manifest Implementation-Version 1.6.8 High
Version pom version 1.6.8 Highest
pkg:maven/com.sun.mail/jakarta.mail@1.6.8
(Confidence :High)
jakarta.mail-api-2.0.1.jar
Description:
Jakarta Mail API jar
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.mail/jakarta.mail-api/2.0.1/715ababc1fe0cf07844e4c97d0a8f27421c4c867/jakarta.mail-api-2.0.1.jar
MD5: 1d95f358e919ce4472daf32b24cea284
SHA1: 715ababc1fe0cf07844e4c97d0a8f27421c4c867
SHA256: 44b1f25896b1ca6d0cd27d97cdd319cf1a7a8cf24fdd7b549b7e9dfccaa0c8d4
Referenced In Project/Scope: server-start:runtimeClasspath
jakarta.mail-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor gradle artifactid jakarta.mail-api Highest
Vendor gradle groupid jakarta.mail Highest
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest probe-provider-xml-file-names Medium
Vendor Manifest specification-vendor Oracle Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor Manifest (hint) specification-vendor sun Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API jar High
Vendor pom parent-artifactid all Low
Vendor pom parent-groupid com.sun.mail Medium
Product file name jakarta.mail-api High
Product gradle artifactid jakarta.mail-api Highest
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl http://www.oracle.com Low
Product Manifest Bundle-Name Jakarta Mail API jar Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest Implementation-Title jakarta.mail.jakarta.mail-api High
Product Manifest probe-provider-xml-file-names Medium
Product Manifest specification-title jakarta.mail.jakarta.mail-api Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API jar High
Product pom parent-artifactid all Medium
Product pom parent-groupid com.sun.mail Medium
Version file version 2.0.1 High
Version gradle version 2.0.1 Highest
Version Manifest Bundle-Version 2.0.1 High
Version Manifest Implementation-Version 2.0.1 High
Version pom version 2.0.1 Highest
pkg:maven/jakarta.mail/jakarta.mail-api@2.0.1
(Confidence :High)
jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.mail/jakarta.mail-api/2.1.3/a327aa5f514ba86e80d54584417d7376ed2bde0e/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
jakarta.mail-api-2.1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor gradle artifactid jakarta.mail-api Highest
Vendor gradle groupid jakarta.mail Highest
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product gradle artifactid jakarta.mail-api Highest
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version gradle version 2.1.3 Highest
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
jakarta.resource-api-2.1.0.jar
Description:
Jakarta Connectors
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.resource/jakarta.resource-api/2.1.0/d98f0ac826cdc85f80061c21bc061841ac6d374c/jakarta.resource-api-2.1.0.jar
MD5: d1bc3f1bcfb4be1a9d810195eba05927
SHA1: d98f0ac826cdc85f80061c21bc061841ac6d374c
SHA256: 4d26ad86a5f72cd2f9c4a31cc4524f7bf3ec0ff74416f081f8642b7ce8041067
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.resource-api-2.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.resource-api High
Vendor gradle artifactid jakarta.resource-api Highest
Vendor gradle groupid jakarta.resource Highest
Vendor jar package name jakarta Highest
Vendor jar package name resource Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.resource-api Medium
Vendor Manifest extension-name jakarta.resource Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Jakarta Connectors Low
Vendor pom artifactid jakarta.resource-api Low
Vendor pom developer id smillidge Medium
Vendor pom developer id yaminikb Medium
Vendor pom developer name Steve Millidge Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org Payara Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom developer org URL http://www.payara.fish/ Medium
Vendor pom groupid jakarta.resource Highest
Vendor pom name API High
Vendor pom name ${extension.name} API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/jca-api Highest
Product file name jakarta.resource-api High
Product gradle artifactid jakarta.resource-api Highest
Product jar package name jakarta Highest
Product jar package name resource Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name jakarta.resource API Medium
Product Manifest bundle-symbolicname jakarta.resource-api Medium
Product Manifest extension-name jakarta.resource Medium
Product pom artifactid jakarta.resource-api Highest
Product pom developer id smillidge Low
Product pom developer id yaminikb Low
Product pom developer name Steve Millidge Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org Payara Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom developer org URL http://www.payara.fish/ Low
Product pom groupid jakarta.resource Highest
Product pom name API High
Product pom name ${extension.name} API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/jca-api High
Version file version 2.1.0 High
Version gradle version 2.1.0 Highest
Version Manifest Bundle-Version 2.1.0 High
Version Manifest Implementation-Version 2.1.0 High
Version pom parent-version 2.1.0 Low
Version pom version 2.1.0 Highest
pkg:maven/jakarta.resource/jakarta.resource-api@2.1.0
(Confidence :High)
jakarta.servlet-api-6.0.0.jar
Description:
Jakarta Servlet 6.0
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.servlet/jakarta.servlet-api/6.0.0/abecc699286e65035ebba9844c03931357a6a963/jakarta.servlet-api-6.0.0.jar
MD5: 4bcb3175ed9b7aa3f038d082879ec2a8
SHA1: abecc699286e65035ebba9844c03931357a6a963
SHA256: c034eb1afb158987dbb53a5fea0cadf611c8dae8daadd59c44d9d5ab70129cef
Referenced In Project/Scope: server-start:compileClasspath
jakarta.servlet-api-6.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet-api High
Vendor gradle artifactid jakarta.servlet-api Highest
Vendor gradle groupid jakarta.servlet Highest
Vendor jar package name jakarta Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet-api Medium
Vendor Manifest extension-name jakarta.servlet Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.servlet Highest
Vendor pom name Jakarta Servlet High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.servlet Highest
Product file name jakarta.servlet-api High
Product gradle artifactid jakarta.servlet-api Highest
Product jar package name jakarta Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Servlet Medium
Product Manifest bundle-symbolicname jakarta.servlet-api Medium
Product Manifest extension-name jakarta.servlet Medium
Product pom artifactid jakarta.servlet-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.servlet Highest
Product pom name Jakarta Servlet High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.servlet Medium
Version file version 6.0.0 High
Version gradle version 6.0.0 Highest
Version Manifest Bundle-Version 6.0.0 High
Version Manifest Implementation-Version 6.0.0 High
Version pom parent-version 6.0.0 Low
Version pom version 6.0.0 Highest
pkg:maven/jakarta.servlet/jakarta.servlet-api@6.0.0
(Confidence :High)
cpe:2.3:a:oracle:projects:6.0.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.servlet-api-6.1.0.jar
Description:
Jakarta Servlet 6.1
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.servlet/jakarta.servlet-api/6.1.0/1169a246913fe3823782af7943e7a103634867c5/jakarta.servlet-api-6.1.0.jar
MD5: 314c930b3e40ac1abc3529c7c9942f09
SHA1: 1169a246913fe3823782af7943e7a103634867c5
SHA256: 8a31f465f3593bf2351531a5c952014eb839da96a605b5825b93dd54714c48c4
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
jakarta.servlet-api-6.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet-api High
Vendor gradle artifactid jakarta.servlet-api Highest
Vendor gradle groupid jakarta.servlet Highest
Vendor jar package name jakarta Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet-api Medium
Vendor Manifest extension-name jakarta.servlet Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.servlet Highest
Vendor pom name Jakarta Servlet High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.servlet Highest
Product file name jakarta.servlet-api High
Product gradle artifactid jakarta.servlet-api Highest
Product jar package name jakarta Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Servlet Medium
Product Manifest bundle-symbolicname jakarta.servlet-api Medium
Product Manifest extension-name jakarta.servlet Medium
Product pom artifactid jakarta.servlet-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.servlet Highest
Product pom name Jakarta Servlet High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.servlet Medium
Version file version 6.1.0 High
Version gradle version 6.1.0 Highest
Version Manifest Bundle-Version 6.1.0 High
Version Manifest Implementation-Version 6.1.0 High
Version pom parent-version 6.1.0 Low
Version pom version 6.1.0 Highest
pkg:maven/jakarta.servlet/jakarta.servlet-api@6.1.0
(Confidence :High)
cpe:2.3:a:oracle:projects:6.1.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.transaction-api-2.0.1.jar
Description:
Jakarta Transactions
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.transaction/jakarta.transaction-api/2.0.1/51a520e3fae406abb84e2e1148e6746ce3f80a1a/jakarta.transaction-api-2.0.1.jar
MD5: 5315974a3935e342b40849478e1c9966
SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a
SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.transaction-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.transaction-api High
Vendor gradle artifactid jakarta.transaction-api Highest
Vendor gradle groupid jakarta.transaction Highest
Vendor jar package name jakarta Highest
Vendor jar package name transaction Highest
Vendor Manifest automatic-module-name jakarta.transaction Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/eclipse-ee4j Low
Vendor Manifest bundle-symbolicname jakarta.transaction-api Medium
Vendor Manifest extension-name jakarta.transaction Medium
Vendor Manifest Implementation-Vendor EE4J Community High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jakarta.transaction-api Low
Vendor pom developer id stephen_felts Medium
Vendor pom developer name Stephen Felts Medium
Vendor pom developer org Oracle, Inc. Medium
Vendor pom groupid jakarta.transaction Highest
Vendor pom name API High
Vendor pom name ${extension.name} API High
Vendor pom organization name EE4J Community High
Vendor pom organization url eclipse-ee4j Medium
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.jta Highest
Product file name jakarta.transaction-api High
Product gradle artifactid jakarta.transaction-api Highest
Product jar package name jakarta Highest
Product jar package name transaction Highest
Product Manifest automatic-module-name jakarta.transaction Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/eclipse-ee4j Low
Product Manifest Bundle-Name jakarta.transaction API Medium
Product Manifest bundle-symbolicname jakarta.transaction-api Medium
Product Manifest extension-name jakarta.transaction Medium
Product pom artifactid jakarta.transaction-api Highest
Product pom developer id stephen_felts Low
Product pom developer name Stephen Felts Low
Product pom developer org Oracle, Inc. Low
Product pom groupid jakarta.transaction Highest
Product pom name API High
Product pom name ${extension.name} API High
Product pom organization name EE4J Community Low
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j High
Product pom url https://projects.eclipse.org/projects/ee4j.jta Medium
Version file version 2.0.1 High
Version gradle version 2.0.1 Highest
Version Manifest Bundle-Version 2.0.1 High
Version Manifest Implementation-Version 2.0.1 High
Version pom parent-version 2.0.1 Low
Version pom version 2.0.1 Highest
pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.1
(Confidence :High)
cpe:2.3:a:oracle:projects:2.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.validation-api-3.0.2.jar
Description:
Jakarta Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.validation/jakarta.validation-api/3.0.2/92b6631659ba35ca09e44874d3eb936edfeee532/jakarta.validation-api-3.0.2.jar
MD5: 3a1ee6efca3e41e3320599790f54c5eb
SHA1: 92b6631659ba35ca09e44874d3eb936edfeee532
SHA256: 291c25e6910cc6a7ebd96d4c6baebf6d7c37676c5482c2d96146e901b62c1fc9
Referenced In Project/Scope: server-start:webapps
jakarta.validation-api-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.validation-api High
Vendor gradle artifactid jakarta.validation-api Highest
Vendor gradle groupid jakarta.validation Highest
Vendor jar package name jakarta Highest
Vendor jar package name validation Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium
Vendor pom artifactid jakarta.validation-api Low
Vendor pom developer email emmanuel@hibernate.org Low
Vendor pom developer email guillaume.smet@hibernate.org Low
Vendor pom developer email gunnar@hibernate.org Low
Vendor pom developer email hferents@redhat.com Low
Vendor pom developer id emmanuelbernard Medium
Vendor pom developer id epbernard Medium
Vendor pom developer id guillaume.smet Medium
Vendor pom developer id gunnar.morling Medium
Vendor pom developer id hardy.ferentschik Medium
Vendor pom developer name Emmanuel Bernard Medium
Vendor pom developer name Guillaume Smet Medium
Vendor pom developer name Gunnar Morling Medium
Vendor pom developer name Hardy Ferentschik Medium
Vendor pom developer org Red Hat, Inc. Medium
Vendor pom groupid jakarta.validation Highest
Vendor pom name Jakarta Bean Validation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://beanvalidation.org Highest
Product file name jakarta.validation-api High
Product gradle artifactid jakarta.validation-api Highest
Product jar package name jakarta Highest
Product jar package name validation Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Bean Validation API Medium
Product Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium
Product pom artifactid jakarta.validation-api Highest
Product pom developer email emmanuel@hibernate.org Low
Product pom developer email guillaume.smet@hibernate.org Low
Product pom developer email gunnar@hibernate.org Low
Product pom developer email hferents@redhat.com Low
Product pom developer id emmanuelbernard Low
Product pom developer id epbernard Low
Product pom developer id guillaume.smet Low
Product pom developer id gunnar.morling Low
Product pom developer id hardy.ferentschik Low
Product pom developer name Emmanuel Bernard Low
Product pom developer name Guillaume Smet Low
Product pom developer name Gunnar Morling Low
Product pom developer name Hardy Ferentschik Low
Product pom developer org Red Hat, Inc. Low
Product pom groupid jakarta.validation Highest
Product pom name Jakarta Bean Validation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://beanvalidation.org Medium
Version file version 3.0.2 High
Version gradle version 3.0.2 Highest
Version Manifest Bundle-Version 3.0.2 High
Version pom parent-version 3.0.2 Low
Version pom version 3.0.2 Highest
pkg:maven/jakarta.validation/jakarta.validation-api@3.0.2
(Confidence :High)
jakarta.validation-api-3.1.0.jar
Description:
Jakarta Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.validation/jakarta.validation-api/3.1.0/846b536eff8a32c1b91fdeb3c9c5b6c39916767d/jakarta.validation-api-3.1.0.jar
MD5: 7de160f58f128c0ecb3cfa4d5593c5c6
SHA1: 846b536eff8a32c1b91fdeb3c9c5b6c39916767d
SHA256: 1a18593d8ba9b48215ca4993e51a4451c804a82f89e8d0d4a31a5e6b8731d4a7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.validation-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.validation-api High
Vendor gradle artifactid jakarta.validation-api Highest
Vendor gradle groupid jakarta.validation Highest
Vendor jar package name jakarta Highest
Vendor jar package name validation Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium
Vendor pom artifactid jakarta.validation-api Low
Vendor pom developer email emmanuel@hibernate.org Low
Vendor pom developer email guillaume.smet@hibernate.org Low
Vendor pom developer email gunnar@hibernate.org Low
Vendor pom developer email hferents@redhat.com Low
Vendor pom developer id emmanuelbernard Medium
Vendor pom developer id epbernard Medium
Vendor pom developer id guillaume.smet Medium
Vendor pom developer id gunnar.morling Medium
Vendor pom developer id hardy.ferentschik Medium
Vendor pom developer name Emmanuel Bernard Medium
Vendor pom developer name Guillaume Smet Medium
Vendor pom developer name Gunnar Morling Medium
Vendor pom developer name Hardy Ferentschik Medium
Vendor pom developer org Red Hat, Inc. Medium
Vendor pom groupid jakarta.validation Highest
Vendor pom name Jakarta Validation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://beanvalidation.org Highest
Product file name jakarta.validation-api High
Product gradle artifactid jakarta.validation-api Highest
Product jar package name jakarta Highest
Product jar package name validation Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Validation API Medium
Product Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium
Product pom artifactid jakarta.validation-api Highest
Product pom developer email emmanuel@hibernate.org Low
Product pom developer email guillaume.smet@hibernate.org Low
Product pom developer email gunnar@hibernate.org Low
Product pom developer email hferents@redhat.com Low
Product pom developer id emmanuelbernard Low
Product pom developer id epbernard Low
Product pom developer id guillaume.smet Low
Product pom developer id gunnar.morling Low
Product pom developer id hardy.ferentschik Low
Product pom developer name Emmanuel Bernard Low
Product pom developer name Guillaume Smet Low
Product pom developer name Gunnar Morling Low
Product pom developer name Hardy Ferentschik Low
Product pom developer org Red Hat, Inc. Low
Product pom groupid jakarta.validation Highest
Product pom name Jakarta Validation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://beanvalidation.org Medium
Version file version 3.1.0 High
Version gradle version 3.1.0 Highest
Version Manifest Bundle-Version 3.1.0 High
Version pom parent-version 3.1.0 Low
Version pom version 3.1.0 Highest
pkg:maven/jakarta.validation/jakarta.validation-api@3.1.0
(Confidence :High)
jakarta.ws.rs-api-3.1.0.jar
Description:
Jakarta RESTful Web Services
License:
EPL-2.0: http://www.eclipse.org/legal/epl-2.0
GPL-2.0-with-classpath-exception: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.ws.rs/jakarta.ws.rs-api/3.1.0/15ce10d249a38865b58fc39521f10f29ab0e3363/jakarta.ws.rs-api-3.1.0.jar
MD5: 6ce4c6749e048456b2c452c1091689ca
SHA1: 15ce10d249a38865b58fc39521f10f29ab0e3363
SHA256: 6b3b3628b8b4aedda0d24c3354335e985497d8ef3c510b8f3028e920d5b8663d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
jakarta.ws.rs-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.ws.rs-api High
Vendor gradle artifactid jakarta.ws.rs-api Highest
Vendor gradle groupid jakarta.ws.rs Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name jakarta Highest
Vendor jar package name rs Highest
Vendor jar package name ws Highest
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname jakarta.ws.rs-api Medium
Vendor Manifest extension-name jakarta.ws.rs Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.ws.rs-api Low
Vendor pom developer email jaxrs-dev@eclipse.org Low
Vendor pom developer id developers Medium
Vendor pom developer name JAX-RS API Developers Medium
Vendor pom groupid jakarta.ws.rs Highest
Vendor pom name Jakarta RESTful WS API High
Vendor pom organization name Eclipse Foundation High
Vendor pom organization url https://www.eclipse.org/org/foundation/ Medium
Vendor pom parent-artifactid all Low
Vendor pom url eclipse-ee4j/jaxrs-api Highest
Product file name jakarta.ws.rs-api High
Product gradle artifactid jakarta.ws.rs-api Highest
Product hint analyzer product web services Medium
Product jar package name jakarta Highest
Product jar package name rs Highest
Product jar package name ws Highest
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name Jakarta RESTful WS API Medium
Product Manifest bundle-symbolicname jakarta.ws.rs-api Medium
Product Manifest extension-name jakarta.ws.rs Medium
Product pom artifactid jakarta.ws.rs-api Highest
Product pom developer email jaxrs-dev@eclipse.org Low
Product pom developer id developers Low
Product pom developer name JAX-RS API Developers Low
Product pom groupid jakarta.ws.rs Highest
Product pom name Jakarta RESTful WS API High
Product pom organization name Eclipse Foundation Low
Product pom organization url https://www.eclipse.org/org/foundation/ Low
Product pom parent-artifactid all Medium
Product pom url eclipse-ee4j/jaxrs-api High
Version file version 3.1.0 High
Version gradle version 3.1.0 Highest
Version Manifest Bundle-Version 3.1.0 High
Version Manifest Implementation-Version 3.1.0 High
Version pom version 3.1.0 Highest
pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.1.0
(Confidence :High)
jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.xml.bind/jakarta.xml.bind-api/4.0.2/6cd5a999b834b63238005b7144136379dc36cad2/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jakarta.xml.bind-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor gradle artifactid jakarta.xml.bind-api Highest
Vendor gradle groupid jakarta.xml.bind Highest
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product gradle artifactid jakarta.xml.bind-api Highest
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version gradle version 4.0.2 Highest
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
jakarta.xml.bind-api-4.0.4.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.xml.bind/jakarta.xml.bind-api/4.0.4/d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc/jakarta.xml.bind-api-4.0.4.jar
MD5: 6dd465a232e545193ab8ab77cc4fbdb9
SHA1: d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc
SHA256: c507ca69a8c6dd11bf4afeec9e0d412c4fa3933fffb0a84680ea5727e8472124
Referenced In Project/Scope: server-start:webapps
jakarta.xml.bind-api-4.0.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor gradle artifactid jakarta.xml.bind-api Highest
Vendor gradle groupid jakarta.xml.bind Highest
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id 1df980a Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product gradle artifactid jakarta.xml.bind-api Highest
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id 1df980a Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.4 High
Version gradle version 4.0.4 Highest
Version Manifest Bundle-Version 4.0.4 High
Version Manifest Implementation-Version 4.0.4 High
Version pom version 4.0.4 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.4
(Confidence :High)
jakarta.xml.soap-api-3.0.2.jar
Description:
Provides the API for creating and building SOAP messages.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.xml.soap/jakarta.xml.soap-api/3.0.2/445830286faf84fe40a3f47ccd7537d69cd58c4/jakarta.xml.soap-api-3.0.2.jar
MD5: b75eb22ffc46058b28d78874902dd2d3
SHA1: 0445830286faf84fe40a3f47ccd7537d69cd58c4
SHA256: 62ecd5c3b5c107779e5ffe84922594c381f7a8e397320a05c3ee3957b5b7863f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
jakarta.xml.soap-api-3.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.soap-api High
Vendor gradle artifactid jakarta.xml.soap-api Highest
Vendor gradle groupid jakarta.xml.soap Highest
Vendor jar package name jakarta Highest
Vendor jar package name soap Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.soap-api Medium
Vendor Manifest extension-name jakarta.xml.soap Medium
Vendor Manifest implementation-build-id 03ea41a Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.soap-api Low
Vendor pom developer id lukasj Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer org Oracle, Inc. Medium
Vendor pom groupid jakarta.xml.soap Highest
Vendor pom name Jakarta SOAP with Attachments API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/saaj-api Highest
Product file name jakarta.xml.soap-api High
Product gradle artifactid jakarta.xml.soap-api Highest
Product jar package name jakarta Highest
Product jar package name soap Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta SOAP with Attachments API Medium
Product Manifest bundle-symbolicname jakarta.xml.soap-api Medium
Product Manifest extension-name jakarta.xml.soap Medium
Product Manifest implementation-build-id 03ea41a Low
Product pom artifactid jakarta.xml.soap-api Highest
Product pom developer id lukasj Low
Product pom developer name Lukas Jungmann Low
Product pom developer org Oracle, Inc. Low
Product pom groupid jakarta.xml.soap Highest
Product pom name Jakarta SOAP with Attachments API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/saaj-api High
Version file version 3.0.2 High
Version gradle version 3.0.2 Highest
Version Manifest Bundle-Version 3.0.2 High
Version Manifest Implementation-Version 3.0.2 High
Version pom parent-version 3.0.2 Low
Version pom version 3.0.2 Highest
pkg:maven/jakarta.xml.soap/jakarta.xml.soap-api@3.0.2
(Confidence :High)
jakarta.xml.ws-api-2.3.3.jar
Description:
Jakarta XML Web Services API
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.xml.ws/jakarta.xml.ws-api/2.3.3/529fe0136be92861e5a255fbc99146f1943c4332/jakarta.xml.ws-api-2.3.3.jar
MD5: ce470c38b9dbdcb8e505d41d767be748
SHA1: 529fe0136be92861e5a255fbc99146f1943c4332
SHA256: c8e0ba03c47cd5e996fd5d83540caaeab69cd8d531f128318d88e15467d112c1
Referenced In Project/Scope: server-start:runtimeClasspath
jakarta.xml.ws-api-2.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.ws-api High
Vendor gradle artifactid jakarta.xml.ws-api Highest
Vendor gradle groupid jakarta.xml.ws Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name ws Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.ws-api Medium
Vendor Manifest extension-name jakarta.xml.ws Medium
Vendor Manifest implementation-build-id 2.3.3-RELEASE-126af43 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.ws-api Low
Vendor pom developer email lukas.jungmann@oracle.com Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer email zheng.jun.li@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer id zhengjl Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom developer name Zheng Jun Li Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom groupid jakarta.xml.ws Highest
Vendor pom name Jakarta XML Web Services API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/jax-ws-api Highest
Product file name jakarta.xml.ws-api High
Product gradle artifactid jakarta.xml.ws-api Highest
Product hint analyzer product web services Medium
Product jar package name ws Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Web Services API Medium
Product Manifest bundle-symbolicname jakarta.xml.ws-api Medium
Product Manifest extension-name jakarta.xml.ws Medium
Product Manifest implementation-build-id 2.3.3-RELEASE-126af43 Low
Product pom artifactid jakarta.xml.ws-api Highest
Product pom developer email lukas.jungmann@oracle.com Low
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer email zheng.jun.li@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer id zhengjl Low
Product pom developer name Lukas Jungmann Low
Product pom developer name Roman Grigoriadi Low
Product pom developer name Zheng Jun Li Low
Product pom developer org Oracle Corporation Low
Product pom groupid jakarta.xml.ws Highest
Product pom name Jakarta XML Web Services API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/jax-ws-api High
Version file version 2.3.3 High
Version gradle version 2.3.3 Highest
Version Manifest Bundle-Version 2.3.3 High
Version Manifest Implementation-Version 2.3.3 High
Version pom parent-version 2.3.3 Low
Version pom version 2.3.3 Highest
pkg:maven/jakarta.xml.ws/jakarta.xml.ws-api@2.3.3
(Confidence :High)
cpe:2.3:a:oracle:web_services:2.3.3:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.xml.ws-api-4.0.2.jar
Description:
Jakarta XML Web Services API
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jakarta.xml.ws/jakarta.xml.ws-api/4.0.2/331ecab874ee75b48db661a331319958cb04edec/jakarta.xml.ws-api-4.0.2.jar
MD5: 9a41e8d9a62fb837d2228d47684a57da
SHA1: 331ecab874ee75b48db661a331319958cb04edec
SHA256: ae500d776eeb64471cd3e3bdfcd6a9e7de6d8f866be6d7e9b2f9ca606d68c203
Referenced In Project/Scope: server-start:webapps
jakarta.xml.ws-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.ws-api High
Vendor gradle artifactid jakarta.xml.ws-api Highest
Vendor gradle groupid jakarta.xml.ws Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name jakarta Highest
Vendor jar package name ws Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.ws-api Medium
Vendor Manifest extension-name jakarta.xml.ws Medium
Vendor Manifest implementation-build-id 4.0.2-RELEASE-a70d205 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.ws-api Low
Vendor pom developer email lukas.jungmann@oracle.com Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer email zheng.jun.li@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer id zhengjl Medium
Vendor pom developer name Lukas Jungmann Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom developer name Zheng Jun Li Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom groupid jakarta.xml.ws Highest
Vendor pom name Jakarta XML Web Services API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jax-ws-api Highest
Product file name jakarta.xml.ws-api High
Product gradle artifactid jakarta.xml.ws-api Highest
Product hint analyzer product web services Medium
Product jar package name jakarta Highest
Product jar package name ws Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Web Services API Medium
Product Manifest bundle-symbolicname jakarta.xml.ws-api Medium
Product Manifest extension-name jakarta.xml.ws Medium
Product Manifest implementation-build-id 4.0.2-RELEASE-a70d205 Low
Product pom artifactid jakarta.xml.ws-api Highest
Product pom developer email lukas.jungmann@oracle.com Low
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer email zheng.jun.li@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer id zhengjl Low
Product pom developer name Lukas Jungmann Low
Product pom developer name Roman Grigoriadi Low
Product pom developer name Zheng Jun Li Low
Product pom developer org Oracle Corporation Low
Product pom groupid jakarta.xml.ws Highest
Product pom name Jakarta XML Web Services API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jax-ws-api High
Version file version 4.0.2 High
Version gradle version 4.0.2 Highest
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom parent-version 4.0.2 Low
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.ws/jakarta.xml.ws-api@4.0.2
(Confidence :High)
cpe:2.3:a:oracle:web_services:4.0.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jasypt-1.9.3.jar
Description:
Java library which enables encryption in java apps with minimum effort.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jasypt/jasypt/1.9.3/d99ef9540f51c617f2a293b460f025d2ee563dd/jasypt-1.9.3.jar
MD5: 39327c7e38782102ecdb3c9dc4e8dcd3
SHA1: 0d99ef9540f51c617f2a293b460f025d2ee563dd
SHA256: f481fbb8dd8ce754bfde7552af4fcbe8c5e303d53663bb3d8ce9d4338e0e55aa
Referenced In Project/Scope: server-start:webapps
jasypt-1.9.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jasypt High
Vendor gradle artifactid jasypt Highest
Vendor gradle groupid org.jasypt Highest
Vendor jar package name encryption Highest
Vendor jar package name jasypt Highest
Vendor jar package name jasypt Low
Vendor jar package name org Highest
Vendor pom artifactid jasypt Low
Vendor pom developer email dfernandez AT users.sourceforge.net Low
Vendor pom developer id dfernandez Medium
Vendor pom developer name Daniel Fernandez Medium
Vendor pom groupid org.jasypt Highest
Vendor pom name JASYPT: Java Simplified Encryption High
Vendor pom organization name The JASYPT team High
Vendor pom organization url http://www.jasypt.org Medium
Vendor pom url http://www.jasypt.org Highest
Product file name jasypt High
Product gradle artifactid jasypt Highest
Product jar package name encryption Highest
Product jar package name jasypt Highest
Product jar package name org Highest
Product pom artifactid jasypt Highest
Product pom developer email dfernandez AT users.sourceforge.net Low
Product pom developer id dfernandez Low
Product pom developer name Daniel Fernandez Low
Product pom groupid org.jasypt Highest
Product pom name JASYPT: Java Simplified Encryption High
Product pom organization name The JASYPT team Low
Product pom organization url http://www.jasypt.org Low
Product pom url http://www.jasypt.org Medium
Version file version 1.9.3 High
Version gradle version 1.9.3 Highest
Version pom version 1.9.3 Highest
java-jwt-4.5.1.jar
Description:
Java client library for the Auth0 platform
License:
The MIT License (MIT): https://raw.githubusercontent.com/auth0/java-jwt/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.auth0/java-jwt/4.5.1/28cd15646d33abc2f0f6e3e6877050f37be163cb/java-jwt-4.5.1.jar
MD5: ef8804b02eed9f4f8ddf8557d1f844a1
SHA1: 28cd15646d33abc2f0f6e3e6877050f37be163cb
SHA256: 037858454e756865d3344047d300d1fe0785e8f391261645f89f9230eea786e7
Referenced In Project/Scope: server-start:runtimeClasspath
java-jwt-4.5.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name java-jwt High
Vendor gradle artifactid java-jwt Highest
Vendor gradle groupid com.auth0 Highest
Vendor jar package name auth0 Low
Vendor jar package name jwt Low
Vendor Manifest multi-release true Low
Vendor pom artifactid java-jwt Low
Vendor pom developer email oss@auth0.com Low
Vendor pom developer id auth0 Medium
Vendor pom developer name Auth0 Medium
Vendor pom groupid com.auth0 Highest
Vendor pom name java jwt High
Vendor pom url auth0/java-jwt Highest
Product file name java-jwt High
Product gradle artifactid java-jwt Highest
Product jar package name jwt Low
Product Manifest multi-release true Low
Product pom artifactid java-jwt Highest
Product pom developer email oss@auth0.com Low
Product pom developer id auth0 Low
Product pom developer name Auth0 Low
Product pom groupid com.auth0 Highest
Product pom name java jwt High
Product pom url auth0/java-jwt High
Version file version 4.5.1 High
Version gradle version 4.5.1 Highest
Version pom version 4.5.1 Highest
pkg:maven/com.auth0/java-jwt@4.5.1
(Confidence :High)
javac-shaded-9+181-r4173-1.jar
Description:
A repackaged and shaded copy of javac
License:
GNU General Public License, version 2, with the Classpath Exception: http://openjdk.java.net/legal/gplv2+ce.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.errorprone/javac-shaded/9+181-r4173-1/a399ee380b6d6b6ea53af1cfbcb086b108d1efb7/javac-shaded-9+181-r4173-1.jar
MD5: a0d7563262ef985e7e17386e9cc21002
SHA1: a399ee380b6d6b6ea53af1cfbcb086b108d1efb7
SHA256: ae6f663a36bac1855076072afd650cdc0076b08f8129fbff504e73e74095a021
Referenced In Project/Scope: server-start:runtimeClasspath
javac-shaded-9+181-r4173-1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javac-shaded-9+181-r4173-1 High
Vendor gradle artifactid javac-shaded Highest
Vendor gradle groupid com.google.errorprone Highest
Vendor jar package name javac Low
Vendor jar package name openjdk Low
Vendor jar package name tools Low
Vendor pom artifactid javac-shaded Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name Error Prone shaded javac High
Vendor pom url google/error-prone-javac Highest
Product file name javac-shaded-9+181-r4173-1 High
Product gradle artifactid javac-shaded Highest
Product jar package name javac Low
Product jar package name tools Low
Product pom artifactid javac-shaded Highest
Product pom groupid com.google.errorprone Highest
Product pom name Error Prone shaded javac High
Product pom url google/error-prone-javac High
Version gradle version 9+181-r4173-1 Highest
Version pom version 9+181-r4173-1 Highest
pkg:maven/com.google.errorprone/javac-shaded@9%2B181-r4173-1
(Confidence :High)
javassist-3.30.2-GA.jar
Description:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: https://www.mozilla.org/en-US/MPL/1.1/
LGPL 2.1: https://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.javassist/javassist/3.30.2-GA/284580b5e42dfa1b8267058566435d9e93fae7f7/javassist-3.30.2-GA.jar
MD5: f5b827b8ddec0629cc7a6d7dafc45999
SHA1: 284580b5e42dfa1b8267058566435d9e93fae7f7
SHA256: eba37290994b5e4868f3af98ff113f6244a6b099385d9ad46881307d3cb01aaf
Referenced In Project/Scope: server-start:webapps
javassist-3.30.2-GA.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javassist High
Vendor gradle artifactid javassist Highest
Vendor gradle groupid org.javassist Highest
Vendor jar package name bytecode Highest
Vendor jar package name javassist Highest
Vendor Manifest automatic-module-name org.javassist Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-symbolicname javassist Medium
Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low
Vendor pom artifactid javassist Low
Vendor pom developer email adinn@redhat.com Low
Vendor pom developer email chiba@javassist.org Low
Vendor pom developer email kabir.khan@jboss.com Low
Vendor pom developer email smarlow@redhat.com Low
Vendor pom developer id adinn Medium
Vendor pom developer id chiba Medium
Vendor pom developer id kabir.khan@jboss.com Medium
Vendor pom developer id scottmarlow Medium
Vendor pom developer name Andrew Dinn Medium
Vendor pom developer name Kabir Khan Medium
Vendor pom developer name Scott Marlow Medium
Vendor pom developer name Shigeru Chiba Medium
Vendor pom developer org JBoss Medium
Vendor pom developer org The Javassist Project Medium
Vendor pom developer org URL https://www.javassist.org/ Medium
Vendor pom developer org URL https://www.jboss.org/ Medium
Vendor pom groupid org.javassist Highest
Vendor pom name Javassist High
Vendor pom organization name Shigeru Chiba, www.javassist.org High
Vendor pom url https://www.javassist.org/ Highest
Product file name javassist High
Product gradle artifactid javassist Highest
Product jar package name bytecode Highest
Product jar package name javassist Highest
Product Manifest automatic-module-name org.javassist Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest Bundle-Name Javassist Medium
Product Manifest bundle-symbolicname javassist Medium
Product Manifest specification-title Javassist Medium
Product pom artifactid javassist Highest
Product pom developer email adinn@redhat.com Low
Product pom developer email chiba@javassist.org Low
Product pom developer email kabir.khan@jboss.com Low
Product pom developer email smarlow@redhat.com Low
Product pom developer id adinn Low
Product pom developer id chiba Low
Product pom developer id kabir.khan@jboss.com Low
Product pom developer id scottmarlow Low
Product pom developer name Andrew Dinn Low
Product pom developer name Kabir Khan Low
Product pom developer name Scott Marlow Low
Product pom developer name Shigeru Chiba Low
Product pom developer org JBoss Low
Product pom developer org The Javassist Project Low
Product pom developer org URL https://www.javassist.org/ Low
Product pom developer org URL https://www.jboss.org/ Low
Product pom groupid org.javassist Highest
Product pom name Javassist High
Product pom organization name Shigeru Chiba, www.javassist.org Low
Product pom url https://www.javassist.org/ Medium
Version gradle version 3.30.2-GA Highest
Version pom version 3.30.2-GA Highest
pkg:maven/org.javassist/javassist@3.30.2-GA
(Confidence :High)
javax.inject-1.jar
Description:
The javax.inject API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.inject/javax.inject/1/6975da39a7040257bd51d21a231b76c915872d38/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: server-start:runtimeClasspath
javax.inject-1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javax.inject-1 High
Vendor gradle artifactid javax.inject Highest
Vendor gradle groupid javax.inject Highest
Vendor jar package name inject Low
Vendor jar package name javax Low
Vendor pom artifactid javax.inject Low
Vendor pom groupid javax.inject Highest
Vendor pom name javax.inject High
Vendor pom url http://code.google.com/p/atinject/ Highest
Product file name javax.inject-1 High
Product gradle artifactid javax.inject Highest
Product jar package name inject Low
Product pom artifactid javax.inject Highest
Product pom groupid javax.inject Highest
Product pom name javax.inject High
Product pom url http://code.google.com/p/atinject/ Medium
Version file version 1 Medium
Version gradle version 1 Highest
Version pom version 1 Highest
pkg:maven/javax.inject/javax.inject@1
(Confidence :High)
javax.resource-api-1.7.1.jar
Description:
Java EE Connector Architecture API
License:
CDDL + GPLv2 with classpath exception: https://oss.oracle.com/licenses/CDDL+GPL-1.1
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.resource/javax.resource-api/1.7.1/f86b4d697ecd992ec6c4c6053736db16d41dc57f/javax.resource-api-1.7.1.jar
MD5: 41f26638ff807ef37845d6d89ef0e694
SHA1: f86b4d697ecd992ec6c4c6053736db16d41dc57f
SHA256: c75bd698263abd9c8c773e3b433a4da2c983fbc92a0a4ef5fc3286e62f41e411
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
javax.resource-api-1.7.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javax.resource-api High
Vendor gradle artifactid javax.resource-api Highest
Vendor gradle groupid javax.resource Highest
Vendor jar package name connector Highest
Vendor jar package name javax Highest
Vendor jar package name resource Highest
Vendor Manifest bundle-docurl http://www.oracle.com/ Low
Vendor Manifest bundle-symbolicname javax.resource-api Medium
Vendor Manifest extension-name javax.resource Medium
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid javax.resource-api Low
Vendor pom developer id sivakumart Medium
Vendor pom developer name Sivakumar Thyagarajan Medium
Vendor pom developer org Oracle, Inc. Medium
Vendor pom groupid javax.resource Highest
Vendor pom name API High
Vendor pom name ${extension.name} API High
Vendor pom organization name Oracle Corporation High
Vendor pom organization url http://www.oracle.com/ Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url javaee/javax.resource Highest
Product file name javax.resource-api High
Product gradle artifactid javax.resource-api Highest
Product jar package name connector Highest
Product jar package name javax Highest
Product jar package name resource Highest
Product Manifest bundle-docurl http://www.oracle.com/ Low
Product Manifest Bundle-Name javax.resource API Medium
Product Manifest bundle-symbolicname javax.resource-api Medium
Product Manifest extension-name javax.resource Medium
Product pom artifactid javax.resource-api Highest
Product pom developer id sivakumart Low
Product pom developer name Sivakumar Thyagarajan Low
Product pom developer org Oracle, Inc. Low
Product pom groupid javax.resource Highest
Product pom name API High
Product pom name ${extension.name} API High
Product pom organization name Oracle Corporation Low
Product pom organization url http://www.oracle.com/ Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url javaee/javax.resource High
Version file version 1.7.1 High
Version gradle version 1.7.1 Highest
Version Manifest Bundle-Version 1.7.1 High
Version Manifest Implementation-Version 1.7.1 High
Version pom parent-version 1.7.1 Low
Version pom version 1.7.1 Highest
pkg:maven/javax.resource/javax.resource-api@1.7.1
(Confidence :High)
javax.servlet-api-3.1.0.jar
Description:
Java(TM) Servlet 3.1 API Design Specification
License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.servlet/javax.servlet-api/3.1.0/3cd63d075497751784b2fa84be59432f4905bf7c/javax.servlet-api-3.1.0.jar
MD5: 79de69e9f5ed8c7fcb8342585732bbf7
SHA1: 3cd63d075497751784b2fa84be59432f4905bf7c
SHA256: af456b2dd41c4e82cf54f3e743bc678973d9fe35bd4d3071fa05c7e5333b8482
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
javax.servlet-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javax.servlet-api High
Vendor gradle artifactid javax.servlet-api Highest
Vendor gradle groupid javax.servlet Highest
Vendor jar package name javax Highest
Vendor jar package name servlet Highest
Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low
Vendor Manifest bundle-symbolicname javax.servlet-api Medium
Vendor Manifest extension-name javax.servlet Medium
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid javax.servlet-api Low
Vendor pom developer id mode Medium
Vendor pom developer id swchan2 Medium
Vendor pom developer name Rajiv Mordani Medium
Vendor pom developer name Shing Wai Chan Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid javax.servlet Highest
Vendor pom name Java Servlet API High
Vendor pom organization name GlassFish Community High
Vendor pom organization url https://glassfish.dev.java.net Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url http://servlet-spec.java.net Highest
Vendor pom (hint) developer org sun Medium
Product file name javax.servlet-api High
Product gradle artifactid javax.servlet-api Highest
Product jar package name javax Highest
Product jar package name servlet Highest
Product Manifest bundle-docurl https://glassfish.dev.java.net Low
Product Manifest Bundle-Name Java Servlet API Medium
Product Manifest bundle-symbolicname javax.servlet-api Medium
Product Manifest extension-name javax.servlet Medium
Product pom artifactid javax.servlet-api Highest
Product pom developer id mode Low
Product pom developer id swchan2 Low
Product pom developer name Rajiv Mordani Low
Product pom developer name Shing Wai Chan Low
Product pom developer org Oracle Low
Product pom groupid javax.servlet Highest
Product pom name Java Servlet API High
Product pom organization name GlassFish Community Low
Product pom organization url https://glassfish.dev.java.net Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url http://servlet-spec.java.net Medium
Version file version 3.1.0 High
Version gradle version 3.1.0 Highest
Version Manifest Bundle-Version 3.1.0 High
Version Manifest Implementation-Version 3.1.0 High
Version pom parent-version 3.1.0 Low
Version pom version 3.1.0 Highest
javax.transaction-api-1.3.jar
Description:
Project GlassFish Java Transaction API
License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.transaction/blob/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.transaction/javax.transaction-api/1.3/e006adf5cf3cca2181d16bd640ecb80148ec0fce/javax.transaction-api-1.3.jar
MD5: 6e9cb1684621821248b6823143ae26c0
SHA1: e006adf5cf3cca2181d16bd640ecb80148ec0fce
SHA256: 603df5e4fc1eeae8f5e5d363a8be6c1fa47d0df1df8739a05cbcb9fafd6df2da
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
javax.transaction-api-1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name javax.transaction-api High
Vendor gradle artifactid javax.transaction-api Highest
Vendor gradle groupid javax.transaction Highest
Vendor jar package name javax Highest
Vendor jar package name transaction Highest
Vendor Manifest automatic-module-name java.transaction Medium
Vendor Manifest bundle-docurl https://glassfish.java.net Low
Vendor Manifest bundle-symbolicname javax.transaction-api Medium
Vendor Manifest extension-name javax.transaction Medium
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid javax.transaction-api Low
Vendor pom developer id stephen_felts Medium
Vendor pom developer name Stephen Felts Medium
Vendor pom developer org Oracle, Inc. Medium
Vendor pom groupid javax.transaction Highest
Vendor pom name API High
Vendor pom name ${extension.name} API High
Vendor pom organization name GlassFish Community High
Vendor pom organization url https://glassfish.java.net Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url http://jta-spec.java.net Highest
Product file name javax.transaction-api High
Product gradle artifactid javax.transaction-api Highest
Product jar package name javax Highest
Product jar package name transaction Highest
Product Manifest automatic-module-name java.transaction Medium
Product Manifest bundle-docurl https://glassfish.java.net Low
Product Manifest Bundle-Name javax.transaction API Medium
Product Manifest bundle-symbolicname javax.transaction-api Medium
Product Manifest extension-name javax.transaction Medium
Product pom artifactid javax.transaction-api Highest
Product pom developer id stephen_felts Low
Product pom developer name Stephen Felts Low
Product pom developer org Oracle, Inc. Low
Product pom groupid javax.transaction Highest
Product pom name API High
Product pom name ${extension.name} API High
Product pom organization name GlassFish Community Low
Product pom organization url https://glassfish.java.net Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url http://jta-spec.java.net Medium
Version file version 1.3 High
Version gradle version 1.3 Highest
Version Manifest Bundle-Version 1.3 High
Version Manifest Implementation-Version 1.3 High
Version pom parent-version 1.3 Low
Version pom version 1.3 Highest
pkg:maven/javax.transaction/javax.transaction-api@1.3
(Confidence :High)
jaxb-api-2.2.12.jar
Description:
JAXB (JSR 222) API
License:
CDDL 1.1: https://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.xml.bind/jaxb-api/2.2.12/4c83805595b15acf41d71d49e3add7c0e85baaed/jaxb-api-2.2.12.jar
MD5: 62229737e570051d2ace48592faf7d4e
SHA1: 4c83805595b15acf41d71d49e3add7c0e85baaed
SHA256: 68a621ec18485f951d09ac76f43e57eee394dbe42cb8f2a4c59c93296fa9dcc6
Referenced In Project/Scope: server-start:webapps
jaxb-api-2.2.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-api High
Vendor gradle artifactid jaxb-api Highest
Vendor gradle groupid javax.xml.bind Highest
Vendor jar package name bind Highest
Vendor jar package name javax Highest
Vendor jar package name jaxb Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://www.oracle.com/ Low
Vendor Manifest bundle-symbolicname jaxb-api Medium
Vendor Manifest extension-name javax.xml.bind Medium
Vendor Manifest implementation-build-id UNKNOWN_BRANCH-false, 2014-10-20T14:33:58+0200 Low
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jaxb-api Low
Vendor pom developer email iaroslav.savytskyi@oracle.com Low
Vendor pom developer email martin.grebac@oracle.com Low
Vendor pom developer name Iaroslav Savytskyi Medium
Vendor pom developer name Martin Grebac Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom groupid javax.xml.bind Highest
Vendor pom name Java Architecture for XML Binding High
Vendor pom organization name Oracle Corporation High
Vendor pom organization url http://www.oracle.com/ Medium
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Vendor pom url http://jaxb.java.net/ Highest
Product file name jaxb-api High
Product gradle artifactid jaxb-api Highest
Product jar package name bind Highest
Product jar package name javax Highest
Product jar package name jaxb Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://www.oracle.com/ Low
Product Manifest Bundle-Name jaxb-api Medium
Product Manifest bundle-symbolicname jaxb-api Medium
Product Manifest extension-name javax.xml.bind Medium
Product Manifest implementation-build-id UNKNOWN_BRANCH-false, 2014-10-20T14:33:58+0200 Low
Product Manifest specification-title Java Architecture for XML Binding Medium
Product pom artifactid jaxb-api Highest
Product pom developer email iaroslav.savytskyi@oracle.com Low
Product pom developer email martin.grebac@oracle.com Low
Product pom developer name Iaroslav Savytskyi Low
Product pom developer name Martin Grebac Low
Product pom developer org Oracle Corporation Low
Product pom groupid javax.xml.bind Highest
Product pom name Java Architecture for XML Binding High
Product pom organization name Oracle Corporation Low
Product pom organization url http://www.oracle.com/ Low
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Product pom url http://jaxb.java.net/ Medium
Version file version 2.2.12 High
Version gradle version 2.2.12 Highest
Version Manifest Bundle-Version 2.2.12 High
Version Manifest specification-version 2.2.12 High
Version pom parent-version 2.2.12 Low
Version pom version 2.2.12 Highest
pkg:maven/javax.xml.bind/jaxb-api@2.2.12
(Confidence :High)
jaxb-api-2.3.1.jar
Description:
JAXB (JSR 222) API
License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.xml.bind/jaxb-api/2.3.1/8531ad5ac454cc2deb9d4d32c40c4d7451939b5d/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256: 88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jaxb-api-2.3.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-api High
Vendor gradle artifactid jaxb-api Highest
Vendor gradle groupid javax.xml.bind Highest
Vendor jar package name bind Highest
Vendor jar package name javax Highest
Vendor jar package name jaxb Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl http://www.oracle.com/ Low
Vendor Manifest bundle-symbolicname jaxb-api Medium
Vendor Manifest extension-name javax.xml.bind Medium
Vendor Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low
Vendor Manifest Implementation-Vendor Oracle Corporation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid jaxb-api Low
Vendor pom groupid javax.xml.bind Highest
Vendor pom parent-artifactid jaxb-api-parent Low
Product file name jaxb-api High
Product gradle artifactid jaxb-api Highest
Product jar package name bind Highest
Product jar package name javax Highest
Product jar package name jaxb Highest
Product jar package name xml Highest
Product Manifest bundle-docurl http://www.oracle.com/ Low
Product Manifest Bundle-Name jaxb-api Medium
Product Manifest bundle-symbolicname jaxb-api Medium
Product Manifest extension-name javax.xml.bind Medium
Product Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low
Product Manifest multi-release true Low
Product Manifest specification-title jaxb-api Medium
Product pom artifactid jaxb-api Highest
Product pom groupid javax.xml.bind Highest
Product pom parent-artifactid jaxb-api-parent Medium
Version file version 2.3.1 High
Version gradle version 2.3.1 Highest
Version Manifest Bundle-Version 2.3.1 High
Version pom version 2.3.1 Highest
pkg:maven/javax.xml.bind/jaxb-api@2.3.1
(Confidence :High)
jaxb-core-4.0.5.jar
Description:
JAXB Core module. Contains sources required by XJC, JXC and Runtime modules.
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/jaxb-core/4.0.5/7b4b11ea5542eea4ad55e1080b23be436795b3/jaxb-core-4.0.5.jar
MD5: ab09aef6bebd4438b0a02707881801e4
SHA1: 007b4b11ea5542eea4ad55e1080b23be436795b3
SHA256: ad3fd9bf00de3eda9859f70b6cfb011e2fe9904804e16a2665092888ece0fdca
Referenced In Project/Scope: server-start:webapps
jaxb-core-4.0.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-core High
Vendor gradle artifactid jaxb-core Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name core Highest
Vendor jar package name glassfish Highest
Vendor jar package name jaxb Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.jaxb.core Medium
Vendor Manifest git-revision cb19596 Low
Vendor Manifest implementation-build-id 4.0.5 - cb19596 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jaxb-core Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB Core High
Vendor pom parent-artifactid jaxb-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name jaxb-core High
Product gradle artifactid jaxb-core Highest
Product jar package name core Highest
Product jar package name glassfish Highest
Product jar package name jaxb Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JAXB Core Medium
Product Manifest bundle-symbolicname org.glassfish.jaxb.core Medium
Product Manifest git-revision cb19596 Low
Product Manifest implementation-build-id 4.0.5 - cb19596 Low
Product Manifest Implementation-Title Eclipse Implementation of JAXB High
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-core Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB Core High
Product pom parent-artifactid jaxb-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 4.0.5 High
Version gradle version 4.0.5 Highest
Version Manifest build-version 4.0.5 Medium
Version Manifest Bundle-Version 4.0.5 High
Version Manifest implementation-build-id 4.0.5 Low
Version pom version 4.0.5 Highest
pkg:maven/org.glassfish.jaxb/jaxb-core@4.0.5
(Confidence :High)
jaxb-impl-2.3.3.jar (shaded: com.sun.istack:istack-commons-runtime:3.0.11)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind/jaxb-impl/2.3.3/3758e8c1664979749e647a9ca8c7ea1cd83c9b1e/jaxb-impl-2.3.3.jar/META-INF/maven/com.sun.istack/istack-commons-runtime/pom.xml
MD5: 2cf61b2d9ed8b708932ba4d2bdd53025
SHA1: 1c4b0f15c5b1aeb7ba30ba0f6a21c10ee112d2b2
SHA256: ae1c070432a8cc35b92960758175014e991193af982e0ad083e40885611d7e94
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid istack-commons-runtime Low
Vendor pom groupid com.sun.istack Highest
Vendor pom name istack common utility code runtime High
Vendor pom parent-artifactid istack-commons Low
Product pom artifactid istack-commons-runtime Highest
Product pom groupid com.sun.istack Highest
Product pom name istack common utility code runtime High
Product pom parent-artifactid istack-commons Medium
Version pom version 3.0.11 Highest
pkg:maven/com.sun.istack/istack-commons-runtime@3.0.11
(Confidence :High)
jaxb-impl-2.3.3.jar (shaded: org.glassfish.jaxb:jaxb-runtime:2.3.3)
Description:
JAXB (JSR 222) Reference Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind/jaxb-impl/2.3.3/3758e8c1664979749e647a9ca8c7ea1cd83c9b1e/jaxb-impl-2.3.3.jar/META-INF/maven/org.glassfish.jaxb/jaxb-runtime/pom.xml
MD5: 7612c04cd616dd6d2a471427a3b87518
SHA1: 2efabedb3f95d04c4b1aa6c71beb16d6d1283f95
SHA256: 92dfe5a3925a9194f0a348ca7a4d5ae7dc64fca79ceab5bcd04ef947f42f36f4
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jaxb-runtime Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB Runtime High
Vendor pom parent-artifactid jaxb-runtime-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom artifactid jaxb-runtime Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB Runtime High
Product pom parent-artifactid jaxb-runtime-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version pom version 2.3.3 Highest
pkg:maven/org.glassfish.jaxb/jaxb-runtime@2.3.3
(Confidence :High)
jaxb-impl-2.3.3.jar (shaded: org.glassfish.jaxb:txw2:2.3.3)
Description:
TXW is a library that allows you to write XML documents.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind/jaxb-impl/2.3.3/3758e8c1664979749e647a9ca8c7ea1cd83c9b1e/jaxb-impl-2.3.3.jar/META-INF/maven/org.glassfish.jaxb/txw2/pom.xml
MD5: d500c9f1fa5827030d0ecee5e5b8122b
SHA1: 69002631b1dd2c1205c099feaca71689090e3fa1
SHA256: 578621ff5ae4feaf6e41c3e0575ba67db3aa57aeb70ed68611795cddfb4b577f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid txw2 Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name TXW2 Runtime High
Vendor pom parent-artifactid jaxb-txw-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom artifactid txw2 Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name TXW2 Runtime High
Product pom parent-artifactid jaxb-txw-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version pom version 2.3.3 Highest
pkg:maven/org.glassfish.jaxb/txw2@2.3.3
(Confidence :High)
jaxb-impl-2.3.3.jar
Description:
Old JAXB Runtime module. Contains sources required for runtime processing.
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind/jaxb-impl/2.3.3/3758e8c1664979749e647a9ca8c7ea1cd83c9b1e/jaxb-impl-2.3.3.jar
MD5: 8f59ab4ced2bb2e3a732e924852fac98
SHA1: 3758e8c1664979749e647a9ca8c7ea1cd83c9b1e
SHA256: e5178d0c7948247f75a13c689bf36f4d5d4910a121f712aa3b20ae94377069d8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jaxb-impl-2.3.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-impl High
Vendor gradle artifactid jaxb-impl Highest
Vendor gradle groupid com.sun.xml.bind Highest
Vendor jar package name bind Highest
Vendor jar package name com Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium
Vendor Manifest git-revision 60e0433 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jaxb-impl Low
Vendor pom groupid com.sun.xml.bind Highest
Vendor pom name Old JAXB Runtime High
Vendor pom parent-artifactid jaxb-bundles Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product file name jaxb-impl High
Product gradle artifactid jaxb-impl Highest
Product jar package name bind Highest
Product jar package name com Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Old JAXB Runtime Medium
Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-impl Medium
Product Manifest git-revision 60e0433 Low
Product Manifest Implementation-Title Jakarta XML Binding Implementation High
Product Manifest multi-release true Low
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-impl Highest
Product pom groupid com.sun.xml.bind Highest
Product pom name Old JAXB Runtime High
Product pom parent-artifactid jaxb-bundles Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version file version 2.3.3 High
Version gradle version 2.3.3 Highest
Version Manifest build-id 2.3.3 Medium
Version Manifest Bundle-Version 2.3.3 High
Version Manifest Implementation-Version 2.3.3 High
Version Manifest major-version 2.3.3 Medium
Version pom version 2.3.3 Highest
pkg:maven/com.sun.xml.bind/jaxb-impl@2.3.3
(Confidence :High)
jaxb-jxc-2.3.3.jar
Description:
Old JAXB schema generator.The *tool* to generate XML schema based on java classes.
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind/jaxb-jxc/2.3.3/f6084b9b7025d52d423c4e51db4b46a842d82170/jaxb-jxc-2.3.3.jar
MD5: d7254593b9d760665ae6478b527ef028
SHA1: f6084b9b7025d52d423c4e51db4b46a842d82170
SHA256: a6e31082e268a68e9fdc4fa2352360c57708e21aeadc3264974dafd12b00aa65
Referenced In Project/Scope: server-start:runtimeClasspath
jaxb-jxc-2.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-jxc High
Vendor gradle artifactid jaxb-jxc Highest
Vendor gradle groupid com.sun.xml.bind Highest
Vendor jar package name com Highest
Vendor jar package name jxc Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.bind.jaxb-jxc Medium
Vendor Manifest git-revision 60e0433 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jaxb-jxc Low
Vendor pom groupid com.sun.xml.bind Highest
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB JXC High
Vendor pom name Old JAXB JXC High
Vendor pom parent-artifactid jaxb-bundles Low
Vendor pom parent-artifactid jaxb-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product file name jaxb-jxc High
Product gradle artifactid jaxb-jxc Highest
Product jar package name com Highest
Product jar package name jxc Highest
Product jar package name sun Highest
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Old JAXB JXC Medium
Product Manifest bundle-symbolicname com.sun.xml.bind.jaxb-jxc Medium
Product Manifest git-revision 60e0433 Low
Product Manifest Implementation-Title Jakarta XML Binding Implementation High
Product Manifest multi-release true Low
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-jxc Highest
Product pom groupid com.sun.xml.bind Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB JXC High
Product pom name Old JAXB JXC High
Product pom parent-artifactid jaxb-bundles Medium
Product pom parent-artifactid jaxb-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version file version 2.3.3 High
Version gradle version 2.3.3 Highest
Version Manifest build-id 2.3.3 Medium
Version Manifest Bundle-Version 2.3.3 High
Version Manifest Implementation-Version 2.3.3 High
Version Manifest major-version 2.3.3 Medium
Version pom version 2.3.3 Highest
pkg:maven/com.sun.xml.bind/jaxb-jxc@2.3.3
(Confidence :High)
pkg:maven/org.glassfish.jaxb/jaxb-jxc@2.3.3
(Confidence :High)
jaxb-runtime-2.3.2.jar
Description:
JAXB (JSR 222) Reference Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/jaxb-runtime/2.3.2/5528bc882ea499a09d720b42af11785c4fc6be2a/jaxb-runtime-2.3.2.jar
MD5: 9c3bf13a58e56c1b955bf5a365ca10b2
SHA1: 5528bc882ea499a09d720b42af11785c4fc6be2a
SHA256: e6e0a1e89fb6ff786279e6a0082d5cef52dc2ebe67053d041800737652b4fd1b
Referenced In Project/Scope: server-start:compileClasspath
jaxb-runtime-2.3.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-runtime High
Vendor gradle artifactid jaxb-runtime Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name bind Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest git-revision ae93d95 Low
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id com.oracle Medium
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom artifactid jaxb-runtime Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB Runtime High
Vendor pom parent-artifactid jaxb-runtime-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product file name jaxb-runtime High
Product gradle artifactid jaxb-runtime Highest
Product jar package name bind Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest git-revision ae93d95 Low
Product Manifest Implementation-Title JAXB Implementation High
Product Manifest specification-title Java Architecture for XML Binding Medium
Product pom artifactid jaxb-runtime Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB Runtime High
Product pom parent-artifactid jaxb-runtime-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version file version 2.3.2 High
Version gradle version 2.3.2 Highest
Version Manifest build-id 2.3.2 Medium
Version Manifest Implementation-Version 2.3.2 High
Version Manifest major-version 2.3.2 Medium
Version pom version 2.3.2 Highest
pkg:maven/org.glassfish.jaxb/jaxb-runtime@2.3.2
(Confidence :High)
jaxb-runtime-2.3.6.jar
Description:
JAXB (JSR 222) Reference Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/jaxb-runtime/2.3.6/1e6cd0e5d9f9919c8c8824fb4d310b09a978a60e/jaxb-runtime-2.3.6.jar
MD5: 29acad12b7cdd22b2a5ab66cd7439d48
SHA1: 1e6cd0e5d9f9919c8c8824fb4d310b09a978a60e
SHA256: cd87d4b98a8bec1d237aed61472ef4adb6a8bb0515cbde1fd62fdd9781c16770
Referenced In Project/Scope: server-start:runtimeClasspath
jaxb-runtime-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-runtime High
Vendor gradle artifactid jaxb-runtime Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name bind Highest
Vendor jar package name com Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium
Vendor Manifest git-revision e9f7f5f Low
Vendor Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jaxb-runtime Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB Runtime High
Vendor pom parent-artifactid jaxb-runtime-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name jaxb-runtime High
Product gradle artifactid jaxb-runtime Highest
Product jar package name bind Highest
Product jar package name com Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JAXB Runtime Medium
Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium
Product Manifest git-revision e9f7f5f Low
Product Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Product Manifest Implementation-Title Jakarta XML Binding Implementation High
Product Manifest multi-release true Low
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-runtime Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB Runtime High
Product pom parent-artifactid jaxb-runtime-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest build-id 2.3.6 Medium
Version Manifest Bundle-Version 2.3.6 High
Version Manifest implementation-build-id 2.3.6 Low
Version Manifest Implementation-Version 2.3.6 High
Version Manifest major-version 2.3.6 Medium
Version pom version 2.3.6 Highest
pkg:maven/org.glassfish.jaxb/jaxb-runtime@2.3.6
(Confidence :High)
jaxb-runtime-4.0.5.jar
Description:
JAXB (JSR 222) Reference Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/jaxb-runtime/4.0.5/ca84c2a7169b5293e232b9d00d1e4e36d4c3914a/jaxb-runtime-4.0.5.jar
MD5: c7384f1f95b8a8e15291485ff9dbe4f3
SHA1: ca84c2a7169b5293e232b9d00d1e4e36d4c3914a
SHA256: 485d8940e76373a7f300815ea5504bf5b726c234425ad30971019d133124cca4
Referenced In Project/Scope: server-start:webapps
jaxb-runtime-4.0.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-runtime High
Vendor gradle artifactid jaxb-runtime Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name glassfish Highest
Vendor jar package name jaxb Highest
Vendor jar package name runtime Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium
Vendor Manifest git-revision cb19596 Low
Vendor Manifest implementation-build-id 4.0.5 - cb19596 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jaxb-runtime Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB Runtime High
Vendor pom parent-artifactid jaxb-runtime-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name jaxb-runtime High
Product gradle artifactid jaxb-runtime Highest
Product jar package name glassfish Highest
Product jar package name jaxb Highest
Product jar package name runtime Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JAXB Runtime Medium
Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium
Product Manifest git-revision cb19596 Low
Product Manifest implementation-build-id 4.0.5 - cb19596 Low
Product Manifest Implementation-Title Eclipse Implementation of JAXB High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-runtime Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB Runtime High
Product pom parent-artifactid jaxb-runtime-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 4.0.5 High
Version gradle version 4.0.5 Highest
Version Manifest build-version 4.0.5 Medium
Version Manifest Bundle-Version 4.0.5 High
Version Manifest implementation-build-id 4.0.5 Low
Version pom version 4.0.5 Highest
pkg:maven/org.glassfish.jaxb/jaxb-runtime@4.0.5
(Confidence :High)
jaxb-xjc-2.3.6.jar
Description:
JAXB Binding Compiler. Contains source code needed for binding customization files into java sources.
In other words: the *tool* to generate java classes for the given xml representation.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/jaxb-xjc/2.3.6/f94c2776c1cb6e892e7f95598aeefd73bd505d95/jaxb-xjc-2.3.6.jar
MD5: 0d6d26d1872ee086baa49054dc62a140
SHA1: f94c2776c1cb6e892e7f95598aeefd73bd505d95
SHA256: 703df153dd86d2b6d058a0af8ca60f545a8299e261231f5bbf6a27539eb32c8a
Referenced In Project/Scope: server-start:runtimeClasspath
jaxb-xjc-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxb-xjc High
Vendor gradle artifactid jaxb-xjc Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name com Highest
Vendor jar package name sun Highest
Vendor jar package name xjc Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest git-revision e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jaxb-xjc Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name JAXB XJC High
Vendor pom parent-artifactid jaxb-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name jaxb-xjc High
Product gradle artifactid jaxb-xjc Highest
Product jar package name com Highest
Product jar package name sun Highest
Product jar package name xjc Highest
Product Manifest git-revision e9f7f5f Low
Product Manifest Implementation-Title Jakarta XML Binding Implementation High
Product Manifest multi-release true Low
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid jaxb-xjc Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name JAXB XJC High
Product pom parent-artifactid jaxb-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest build-id 2.3.6 Medium
Version Manifest Implementation-Version 2.3.6 High
Version Manifest major-version 2.3.6 Medium
Version pom version 2.3.6 Highest
pkg:maven/org.glassfish.jaxb/jaxb-xjc@2.3.6
(Confidence :High)
jaxen-1.2.0.jar
Description:
Jaxen is a universal XPath engine for Java.
License:
BSD License 2.0: https://raw.githubusercontent.com/jaxen-xpath/jaxen/master/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jaxen/jaxen/1.2.0/c10535a925bd35129a4329bc75065cc6b5293f2c/jaxen-1.2.0.jar
MD5: c32cf69356254b8f5050fce6e86358e9
SHA1: c10535a925bd35129a4329bc75065cc6b5293f2c
SHA256: 70feef9dd75ad064def05a3ce8975aeba515ee7d1be146d12199c8828a64174c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jaxen-1.2.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxen High
Vendor gradle artifactid jaxen Highest
Vendor gradle groupid jaxen Highest
Vendor jar package name jaxen Highest
Vendor jar package name xpath Highest
Vendor Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low
Vendor Manifest bundle-symbolicname jaxen Medium
Vendor pom artifactid jaxen Low
Vendor pom developer email bob@eng.werken.com Low
Vendor pom developer email brian.ewins@gmail.com Low
Vendor pom developer email contact@megginson.com Low
Vendor pom developer email elharo@ibiblio.org Low
Vendor pom developer email erwin@klomp.org Low
Vendor pom developer email james_strachan@yahoo.co.uk Low
Vendor pom developer email jdvorak@users.sourceforge.net Low
Vendor pom developer email mbelonga@users.sourceforge.net Low
Vendor pom developer email peter.royal@pobox.com Low
Vendor pom developer email purpletech@users.sourceforge.net Low
Vendor pom developer email scott@dotnot.org Low
Vendor pom developer email szegedia@users.sourceforge.net Low
Vendor pom developer email xcut@users.sourceforge.net Low
Vendor pom developer id bewins Medium
Vendor pom developer id bob Medium
Vendor pom developer id cnentwich Medium
Vendor pom developer id dmegginson Medium
Vendor pom developer id eboldwidt Medium
Vendor pom developer id elharo Medium
Vendor pom developer id jdvorak Medium
Vendor pom developer id jstrachan Medium
Vendor pom developer id mbelonga Medium
Vendor pom developer id proyal Medium
Vendor pom developer id purpletech Medium
Vendor pom developer id ssanders Medium
Vendor pom developer id szegedia Medium
Vendor pom developer name Alexander Day Chaffee Medium
Vendor pom developer name Attila Szegedi Medium
Vendor pom developer name Bob McWhirter Medium
Vendor pom developer name Brian Ewins Medium
Vendor pom developer name Christian Nentwich Medium
Vendor pom developer name David Megginson Medium
Vendor pom developer name Elliotte Rusty Harold Medium
Vendor pom developer name Erwin Bolwidt Medium
Vendor pom developer name James Strachan Medium
Vendor pom developer name Jan Dvorak Medium
Vendor pom developer name Mark A. Belonga Medium
Vendor pom developer name Peter Royal Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer org Cafe au Lait Medium
Vendor pom developer org dotnot Medium
Vendor pom developer org Megginson Technologies Medium
Vendor pom developer org Purple Technologies Medium
Vendor pom developer org Spiritsoft Medium
Vendor pom developer org The Werken Company Medium
Vendor pom groupid jaxen Highest
Vendor pom name jaxen High
Vendor pom organization name The Jaxen Project High
Vendor pom organization url http://www.cafeconleche.org/jaxen Medium
Vendor pom url http://www.cafeconleche.org/jaxen Highest
Product file name jaxen High
Product gradle artifactid jaxen Highest
Product jar package name jaxen Highest
Product jar package name xpath Highest
Product Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low
Product Manifest Bundle-Name jaxen Medium
Product Manifest bundle-symbolicname jaxen Medium
Product pom artifactid jaxen Highest
Product pom developer email bob@eng.werken.com Low
Product pom developer email brian.ewins@gmail.com Low
Product pom developer email contact@megginson.com Low
Product pom developer email elharo@ibiblio.org Low
Product pom developer email erwin@klomp.org Low
Product pom developer email james_strachan@yahoo.co.uk Low
Product pom developer email jdvorak@users.sourceforge.net Low
Product pom developer email mbelonga@users.sourceforge.net Low
Product pom developer email peter.royal@pobox.com Low
Product pom developer email purpletech@users.sourceforge.net Low
Product pom developer email scott@dotnot.org Low
Product pom developer email szegedia@users.sourceforge.net Low
Product pom developer email xcut@users.sourceforge.net Low
Product pom developer id bewins Low
Product pom developer id bob Low
Product pom developer id cnentwich Low
Product pom developer id dmegginson Low
Product pom developer id eboldwidt Low
Product pom developer id elharo Low
Product pom developer id jdvorak Low
Product pom developer id jstrachan Low
Product pom developer id mbelonga Low
Product pom developer id proyal Low
Product pom developer id purpletech Low
Product pom developer id ssanders Low
Product pom developer id szegedia Low
Product pom developer name Alexander Day Chaffee Low
Product pom developer name Attila Szegedi Low
Product pom developer name Bob McWhirter Low
Product pom developer name Brian Ewins Low
Product pom developer name Christian Nentwich Low
Product pom developer name David Megginson Low
Product pom developer name Elliotte Rusty Harold Low
Product pom developer name Erwin Bolwidt Low
Product pom developer name James Strachan Low
Product pom developer name Jan Dvorak Low
Product pom developer name Mark A. Belonga Low
Product pom developer name Peter Royal Low
Product pom developer name Scott Sanders Low
Product pom developer org Cafe au Lait Low
Product pom developer org dotnot Low
Product pom developer org Megginson Technologies Low
Product pom developer org Purple Technologies Low
Product pom developer org Spiritsoft Low
Product pom developer org The Werken Company Low
Product pom groupid jaxen Highest
Product pom name jaxen High
Product pom organization name The Jaxen Project Low
Product pom organization url http://www.cafeconleche.org/jaxen Low
Product pom url http://www.cafeconleche.org/jaxen Medium
Version file version 1.2.0 High
Version gradle version 1.2.0 Highest
Version Manifest Bundle-Version 1.2.0 High
Version pom version 1.2.0 Highest
pkg:maven/jaxen/jaxen@1.2.0
(Confidence :High)
jaxws-tools-2.3.3.jar (shaded: com.sun.xml.ws:wscompile:2.3.3)
Description:
JAX-WS RI Tools
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.ws/jaxws-tools/2.3.3/dacff515f8dacb7767857e4126b0bedece8b7d9c/jaxws-tools-2.3.3.jar/META-INF/maven/com.sun.xml.ws/wscompile/pom.xml
MD5: 5c25754519b8b10722418a7aaaed3577
SHA1: cf9d76b8d5b4385f6238aba78541cae8052fbcbe
SHA256: c0d9a362a0dbaf4975e824478088447f49e74d482c3566d30707d5fb6453b0b2
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor hint analyzer vendor web services Medium
Vendor pom artifactid wscompile Low
Vendor pom groupid com.sun.xml.ws Highest
Vendor pom name JAX-WS RI Tools (wscompile) High
Vendor pom parent-artifactid project Low
Product hint analyzer product web services Medium
Product pom artifactid wscompile Highest
Product pom groupid com.sun.xml.ws Highest
Product pom name JAX-WS RI Tools (wscompile) High
Product pom parent-artifactid project Medium
Version pom version 2.3.3 Highest
pkg:maven/com.sun.xml.ws/wscompile@2.3.3
(Confidence :High)
jaxws-tools-2.3.3.jar
Description:
Open source Reference Implementation of JSR-224: Java API for XML Web Services
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.ws/jaxws-tools/2.3.3/dacff515f8dacb7767857e4126b0bedece8b7d9c/jaxws-tools-2.3.3.jar
MD5: 2857ca54f3e5766268b9b05eb466c91a
SHA1: dacff515f8dacb7767857e4126b0bedece8b7d9c
SHA256: 6aa1506f7f5083ee84dafc6784e7367b038e6ea5f7c0e819c03022a90277509d
Referenced In Project/Scope: server-start:runtimeClasspath
jaxws-tools-2.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jaxws-tools High
Vendor gradle artifactid jaxws-tools Highest
Vendor gradle groupid com.sun.xml.ws Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name api Highest
Vendor jar package name com Highest
Vendor jar package name sun Highest
Vendor jar package name tools Highest
Vendor jar package name ws Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.ws.jaxws-tools Medium
Vendor Manifest extension-name com.sun.tools.jaxws Medium
Vendor Manifest git-revision b4c5bb6 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jaxws-tools Low
Vendor pom groupid com.sun.xml.ws Highest
Vendor pom name JAX-WS RI Tools (jaxws-tools) High
Vendor pom parent-artifactid project Low
Product file name jaxws-tools High
Product gradle artifactid jaxws-tools Highest
Product hint analyzer product web services Medium
Product jar package name api Highest
Product jar package name com Highest
Product jar package name sun Highest
Product jar package name tools Highest
Product jar package name ws Highest
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name JAX-WS RI Tools (jaxws-tools) Medium
Product Manifest bundle-symbolicname com.sun.xml.ws.jaxws-tools Medium
Product Manifest extension-name com.sun.tools.jaxws Medium
Product Manifest git-revision b4c5bb6 Low
Product Manifest Implementation-Title Jakarta XML Web Services Implementation High
Product Manifest multi-release true Low
Product Manifest specification-title Jakarta XML Web Services Medium
Product pom artifactid jaxws-tools Highest
Product pom groupid com.sun.xml.ws Highest
Product pom name JAX-WS RI Tools (jaxws-tools) High
Product pom parent-artifactid project Medium
Version file version 2.3.3 High
Version gradle version 2.3.3 Highest
Version Manifest build-id 2.3.3 Medium
Version Manifest Bundle-Version 2.3.3 High
Version Manifest Implementation-Version 2.3.3 High
Version Manifest major-version 2.3.3 Medium
Version pom version 2.3.3 Highest
pkg:maven/com.sun.xml.ws/jaxws-tools@2.3.3
(Confidence :High)
cpe:2.3:a:oracle:web_services:2.3.3:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jboss-logging-3.4.1.Final.jar
Description:
The JBoss Logging Framework
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.logging/jboss-logging/3.4.1.Final/40fd4d696c55793e996d1ff3c475833f836c2498/jboss-logging-3.4.1.Final.jar
MD5: 52ee373b84e39570c78c0815006375bc
SHA1: 40fd4d696c55793e996d1ff3c475833f836c2498
SHA256: 8efe877d93e5e1057a1388b2950503b88b0c28447364fde08adbec61e524eeb8
Referenced In Project/Scope: server-start:runtimeClasspath
jboss-logging-3.4.1.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jboss-logging High
Vendor gradle artifactid jboss-logging Highest
Vendor gradle groupid org.jboss.logging Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name jboss Highest
Vendor jar package name logging Highest
Vendor Manifest automatic-module-name org.jboss.logging Medium
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Vendor Manifest implementation-url http://www.jboss.org Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid jboss-logging Low
Vendor pom groupid org.jboss.logging Highest
Vendor pom name JBoss Logging 3 High
Vendor pom parent-artifactid jboss-parent Low
Vendor pom parent-groupid org.jboss Medium
Vendor pom url http://www.jboss.org Highest
Product file name jboss-logging High
Product gradle artifactid jboss-logging Highest
Product jar package name jboss Highest
Product jar package name logging Highest
Product Manifest automatic-module-name org.jboss.logging Medium
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest Bundle-Name JBoss Logging 3 Medium
Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Product Manifest Implementation-Title JBoss Logging 3 High
Product Manifest implementation-url http://www.jboss.org Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title JBoss Logging 3 Medium
Product pom artifactid jboss-logging Highest
Product pom groupid org.jboss.logging Highest
Product pom name JBoss Logging 3 High
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Medium
Product pom url http://www.jboss.org Medium
Version gradle version 3.4.1.Final Highest
Version Manifest Bundle-Version 3.4.1.Final High
Version Manifest Implementation-Version 3.4.1.Final High
Version pom parent-version 3.4.1.Final Low
Version pom version 3.4.1.Final Highest
pkg:maven/org.jboss.logging/jboss-logging@3.4.1.Final
(Confidence :High)
jcifs-ng-2.1.10.jar
Description:
A pure-java CIFS/SMB client library
License:
LGPL: https://www.gnu.org/licenses/lgpl.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/eu.agno3.jcifs/jcifs-ng/2.1.10/94b4c0b173540ae98c379ea278713665fd8ab3eb/jcifs-ng-2.1.10.jar
MD5: 82fa5f5eb6da0927002d3f1aef644197
SHA1: 94b4c0b173540ae98c379ea278713665fd8ab3eb
SHA256: 1940332a416644b3b464335d0e0fb12530fb2c1e4cfb57e7d3339b46b2f0af48
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jcifs-ng-2.1.10.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jcifs-ng High
Vendor gradle artifactid jcifs-ng Highest
Vendor gradle groupid eu.agno3.jcifs Highest
Vendor jar package name jcifs Highest
Vendor jar package name smb Highest
Vendor Manifest bundle-symbolicname eu.agno3.jcifsng Medium
Vendor pom artifactid jcifs-ng Low
Vendor pom developer email bechler@agno3.eu Low
Vendor pom developer name Moritz Bechler Medium
Vendor pom developer org AgNO3 GmbH & Co. KG Medium
Vendor pom developer org URL https://github.com/AgNO3/ Medium
Vendor pom groupid eu.agno3.jcifs Highest
Vendor pom name jCIFS NG High
Vendor pom url AgNO3/jcifs-ng/ Highest
Product file name jcifs-ng High
Product gradle artifactid jcifs-ng Highest
Product jar package name jcifs Highest
Product jar package name smb Highest
Product Manifest Bundle-Name jCIFS NG Medium
Product Manifest bundle-symbolicname eu.agno3.jcifsng Medium
Product pom artifactid jcifs-ng Highest
Product pom developer email bechler@agno3.eu Low
Product pom developer name Moritz Bechler Low
Product pom developer org AgNO3 GmbH & Co. KG Low
Product pom developer org URL https://github.com/AgNO3/ Low
Product pom groupid eu.agno3.jcifs Highest
Product pom name jCIFS NG High
Product pom url AgNO3/jcifs-ng/ High
Version file version 2.1.10 High
Version gradle version 2.1.10 Highest
Version pom version 2.1.10 Highest
CVE-2026-35002 suppress
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CVSSv4:
Base Score: CRITICAL (9.3)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
jcl-over-slf4j-2.0.17.jar
Description:
JCL 1.2 implemented over SLF4J
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.slf4j/jcl-over-slf4j/2.0.17/76ea503eb688f06556a9ba69995d7eab63e34531/jcl-over-slf4j-2.0.17.jar
MD5: 4fcd46ca51e55b9fd9b0db34474927e0
SHA1: 76ea503eb688f06556a9ba69995d7eab63e34531
SHA256: affd06771589ebfe454bb11315a4f466ecaa135b95f3e7939534cf1d2fd7064c
Referenced In Project/Scope: server-start:runtimeClasspath
jcl-over-slf4j-2.0.17.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/ch.qos.logback/logback-classic@1.5.21
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/org.slf4j/slf4j-api@2.0.17
Evidence
Type Source Name Value Confidence
Vendor file name jcl-over-slf4j High
Vendor gradle artifactid jcl-over-slf4j Highest
Vendor gradle groupid org.slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor pom artifactid jcl-over-slf4j Low
Vendor pom groupid org.slf4j Highest
Vendor pom name JCL 1.2 implemented over SLF4J High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name jcl-over-slf4j High
Product gradle artifactid jcl-over-slf4j Highest
Product jar package name 9 Highest
Product jar package name apache Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name JCL 1.2 implemented over SLF4J Medium
Product Manifest bundle-symbolicname jcl.over.slf4j Medium
Product Manifest Implementation-Title jcl-over-slf4j High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product pom artifactid jcl-over-slf4j Highest
Product pom groupid org.slf4j Highest
Product pom name JCL 1.2 implemented over SLF4J High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version gradle version 2.0.17 Highest
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/jcl-over-slf4j@2.0.17
(Confidence :High)
jctools-core-2.1.2.jar
Description:
Java Concurrency Tools Core Library
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jctools/jctools-core/2.1.2/8ec46a6a26e7c1c7e57e2590a043238ffc462144/jctools-core-2.1.2.jar
MD5: 2489a6a01999f1397248941ab5d84071
SHA1: 8ec46a6a26e7c1c7e57e2590a043238ffc462144
SHA256: 93dcfe1b4b5c2ae8109a98003e2092d04f83ace4ed0cc0b1754c895c81ddaee6
Referenced In Project/Scope: server-start:runtimeClasspath
jctools-core-2.1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jctools-core High
Vendor gradle artifactid jctools-core Highest
Vendor gradle groupid org.jctools Highest
Vendor jar package name jctools Highest
Vendor Manifest bundle-symbolicname org.jctools.core Medium
Vendor pom artifactid jctools-core Low
Vendor pom groupid org.jctools Highest
Vendor pom name Java Concurrency Tools Core Library High
Vendor pom url JCTools Highest
Product file name jctools-core High
Product gradle artifactid jctools-core Highest
Product jar package name jctools Highest
Product Manifest Bundle-Name Java Concurrency Tools Core Library Medium
Product Manifest bundle-symbolicname org.jctools.core Medium
Product pom artifactid jctools-core Highest
Product pom groupid org.jctools Highest
Product pom name Java Concurrency Tools Core Library High
Product pom url JCTools High
Version file version 2.1.2 High
Version gradle version 2.1.2 Highest
Version Manifest Bundle-Version 2.1.2 High
Version pom version 2.1.2 Highest
pkg:maven/org.jctools/jctools-core@2.1.2
(Confidence :High)
jersey-client-3.1.11.jar
Description:
Jersey core client implementation
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php, https://opensource.org/licenses/BSD-2-Clause, http://www.apache.org/licenses/LICENSE-2.0.html, https://creativecommons.org/publicdomain/zero/1.0/, https://asm.ow2.io/license.html, jquery.org/license, http://www.opensource.org/licenses/mit-license.php, https://www.w3.org/Consortium/Legal/copyright-documents-19990405
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.core/jersey-client/3.1.11/d33fa8450c53b5d4c3405e9fecdf68e8d190af64/jersey-client-3.1.11.jar
MD5: e50f99ed8ed91671bc17a1454a49360e
SHA1: d33fa8450c53b5d4c3405e9fecdf68e8d190af64
SHA256: 9f0f532a6babb530f4c7d6fc4f452b996a97aa7c34248bf249eea8a2ce639758
Referenced In Project/Scope: server-start:webapps
jersey-client-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-client High
Vendor gradle artifactid jersey-client Highest
Vendor gradle groupid org.glassfish.jersey.core Highest
Vendor jar package name client Highest
Vendor jar package name glassfish Highest
Vendor jar package name jersey Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-client Medium
Vendor pom artifactid jersey-client Low
Vendor pom groupid org.glassfish.jersey.core Highest
Vendor pom name jersey-core-client High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.glassfish.jersey Medium
Product file name jersey-client High
Product gradle artifactid jersey-client Highest
Product jar package name client Highest
Product jar package name glassfish Highest
Product jar package name jersey Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-core-client Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-client Medium
Product pom artifactid jersey-client Highest
Product pom groupid org.glassfish.jersey.core Highest
Product pom name jersey-core-client High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.glassfish.jersey Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jersey-common-3.1.11.jar
Description:
Jersey core common packages
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
The GNU General Public License (GPL), Version 2, With Classpath Exception: https://www.gnu.org/software/classpath/license.html
Apache License, 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
Public Domain: https://creativecommons.org/publicdomain/zero/1.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.core/jersey-common/3.1.11/58cea05a20223bc23ffd96ade81536d61a26ac3/jersey-common-3.1.11.jar
MD5: 24d74457850f006727590b0e32106205
SHA1: 058cea05a20223bc23ffd96ade81536d61a26ac3
SHA256: ec516d7c2fdcfcd7eb7739eacf3cd6914e17a1595fd45826b33c8765965981b2
Referenced In Project/Scope: server-start:webapps
jersey-common-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-common High
Vendor gradle artifactid jersey-common Highest
Vendor gradle groupid org.glassfish.jersey.core Highest
Vendor jar package name glassfish Highest
Vendor jar package name jersey Highest
Vendor jar package name org Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-common Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jersey-common Low
Vendor pom groupid org.glassfish.jersey.core Highest
Vendor pom name jersey-core-common High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.glassfish.jersey Medium
Product file name jersey-common High
Product gradle artifactid jersey-common Highest
Product jar package name glassfish Highest
Product jar package name jersey Highest
Product jar package name org Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-core-common Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-common Medium
Product Manifest multi-release true Low
Product pom artifactid jersey-common Highest
Product pom groupid org.glassfish.jersey.core Highest
Product pom name jersey-core-common High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.glassfish.jersey Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jersey-container-servlet-core-3.1.11.jar
Description:
Jersey core Servlet 3.x implementation
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php, https://opensource.org/licenses/BSD-2-Clause, http://www.apache.org/licenses/LICENSE-2.0.html, https://creativecommons.org/publicdomain/zero/1.0/, https://asm.ow2.io/license.html, jquery.org/license, http://www.opensource.org/licenses/mit-license.php, https://www.w3.org/Consortium/Legal/copyright-documents-19990405
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.containers/jersey-container-servlet-core/3.1.11/1ed90ffac6a6cfd9a496a3a8002dc0b2037470c4/jersey-container-servlet-core-3.1.11.jar
MD5: b00f1766cd2b102572f9f0aa85710106
SHA1: 1ed90ffac6a6cfd9a496a3a8002dc0b2037470c4
SHA256: 4c93b928d93037d7250ab1db9b9eb5e2bd12cf9e67cd48d25dcc835249d47e40
Referenced In Project/Scope: server-start:webapps
jersey-container-servlet-core-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-container-servlet-core High
Vendor gradle artifactid jersey-container-servlet-core Highest
Vendor gradle groupid org.glassfish.jersey.containers Highest
Vendor jar package name glassfish Highest
Vendor jar package name jersey Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.containers.jersey-container-servlet-core Medium
Vendor pom artifactid jersey-container-servlet-core Low
Vendor pom groupid org.glassfish.jersey.containers Highest
Vendor pom name jersey-container-servlet-core High
Vendor pom parent-artifactid project Low
Product file name jersey-container-servlet-core High
Product gradle artifactid jersey-container-servlet-core Highest
Product jar package name glassfish Highest
Product jar package name jersey Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-container-servlet-core Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.containers.jersey-container-servlet-core Medium
Product pom artifactid jersey-container-servlet-core Highest
Product pom groupid org.glassfish.jersey.containers Highest
Product pom name jersey-container-servlet-core High
Product pom parent-artifactid project Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jersey-hk2-3.1.11.jar
Description:
HK2 InjectionManager implementation
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php, https://opensource.org/licenses/BSD-2-Clause, http://www.apache.org/licenses/LICENSE-2.0.html, https://creativecommons.org/publicdomain/zero/1.0/, https://asm.ow2.io/license.html, jquery.org/license, http://www.opensource.org/licenses/mit-license.php, https://www.w3.org/Consortium/Legal/copyright-documents-19990405
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.inject/jersey-hk2/3.1.11/3f51dfcd27ed8a773eb42f0317c9a4de07328d07/jersey-hk2-3.1.11.jar
MD5: 3dc15f546bdf4c45125179ee69a87399
SHA1: 3f51dfcd27ed8a773eb42f0317c9a4de07328d07
SHA256: faeee985d70b8223a9eb22baabf579d9f860141716efcaf74b0a252a63959fc3
Referenced In Project/Scope: server-start:webapps
jersey-hk2-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-hk2 High
Vendor gradle artifactid jersey-hk2 Highest
Vendor gradle groupid org.glassfish.jersey.inject Highest
Vendor jar package name glassfish Highest
Vendor jar package name hk2 Highest
Vendor jar package name inject Highest
Vendor jar package name jersey Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.inject.jersey-hk2 Medium
Vendor pom artifactid jersey-hk2 Low
Vendor pom groupid org.glassfish.jersey.inject Highest
Vendor pom name jersey-inject-hk2 High
Vendor pom parent-artifactid project Low
Product file name jersey-hk2 High
Product gradle artifactid jersey-hk2 Highest
Product jar package name glassfish Highest
Product jar package name hk2 Highest
Product jar package name inject Highest
Product jar package name jersey Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-inject-hk2 Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.inject.jersey-hk2 Medium
Product pom artifactid jersey-hk2 Highest
Product pom groupid org.glassfish.jersey.inject Highest
Product pom name jersey-inject-hk2 High
Product pom parent-artifactid project Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jersey-media-multipart-3.1.11.jar
Description:
Jersey Multipart entity providers support module.
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php, https://opensource.org/licenses/BSD-2-Clause, http://www.apache.org/licenses/LICENSE-2.0.html, https://creativecommons.org/publicdomain/zero/1.0/, https://asm.ow2.io/license.html, jquery.org/license, http://www.opensource.org/licenses/mit-license.php, https://www.w3.org/Consortium/Legal/copyright-documents-19990405
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.media/jersey-media-multipart/3.1.11/bd24fc31c6d70b48b418ea97f0ddb45838e01324/jersey-media-multipart-3.1.11.jar
MD5: 52048bfe5c1f1486b4c51775314f6c34
SHA1: bd24fc31c6d70b48b418ea97f0ddb45838e01324
SHA256: 335d4b92e033f290cb9433d34d000c33ce0016c0be4d15a5297981cc6c5b433e
Referenced In Project/Scope: server-start:webapps
jersey-media-multipart-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-media-multipart High
Vendor gradle artifactid jersey-media-multipart Highest
Vendor gradle groupid org.glassfish.jersey.media Highest
Vendor jar package name glassfish Highest
Vendor jar package name jersey Highest
Vendor jar package name media Highest
Vendor jar package name multipart Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.media.jersey-media-multipart Medium
Vendor pom artifactid jersey-media-multipart Low
Vendor pom groupid org.glassfish.jersey.media Highest
Vendor pom name jersey-media-multipart High
Vendor pom parent-artifactid project Low
Product file name jersey-media-multipart High
Product gradle artifactid jersey-media-multipart Highest
Product jar package name glassfish Highest
Product jar package name jersey Highest
Product jar package name media Highest
Product jar package name multipart Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-media-multipart Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.media.jersey-media-multipart Medium
Product pom artifactid jersey-media-multipart Highest
Product pom groupid org.glassfish.jersey.media Highest
Product pom name jersey-media-multipart High
Product pom parent-artifactid project Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jersey-server-3.1.11.jar
Description:
Jersey core server implementation
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
The GNU General Public License (GPL), Version 2, With Classpath Exception: https://www.gnu.org/software/classpath/license.html
Apache License, 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
Modified BSD: https://asm.ow2.io/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jersey.core/jersey-server/3.1.11/b65a67a4ce399063cd88107b360d210d434f1e9a/jersey-server-3.1.11.jar
MD5: dc77c1ecc1eca1253d0ba37a0e3aa9a2
SHA1: b65a67a4ce399063cd88107b360d210d434f1e9a
SHA256: 7dde2adf6600f3e8f723e37a8c96c31838a682f8db854fdcfcf4f00695d6f903
Referenced In Project/Scope: server-start:webapps
jersey-server-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jersey-server High
Vendor gradle artifactid jersey-server Highest
Vendor gradle groupid org.glassfish.jersey.core Highest
Vendor jar package name glassfish Highest
Vendor jar package name jersey Highest
Vendor jar package name org Highest
Vendor jar package name server Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Vendor Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-server Medium
Vendor pom artifactid jersey-server Low
Vendor pom groupid org.glassfish.jersey.core Highest
Vendor pom name jersey-core-server High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.glassfish.jersey Medium
Product file name jersey-server High
Product gradle artifactid jersey-server Highest
Product jar package name glassfish Highest
Product jar package name jersey Highest
Product jar package name org Highest
Product jar package name server Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low
Product Manifest Bundle-Name jersey-core-server Medium
Product Manifest bundle-symbolicname org.glassfish.jersey.core.jersey-server Medium
Product pom artifactid jersey-server Highest
Product pom groupid org.glassfish.jersey.core Highest
Product pom name jersey-core-server High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.glassfish.jersey Medium
Version file version 3.1.11 High
Version gradle version 3.1.11 Highest
Version Manifest Bundle-Version 3.1.11 High
Version pom version 3.1.11 Highest
jetty-alpn-client-12.1.8.jar
Description:
Jetty ALPN Client API Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-alpn-client/12.1.8/eba832cbc0dc8da2e3a8bd3534806a2b9d321418/jetty-alpn-client-12.1.8.jar
MD5: b8c3aa6be24b17b63c6c3df0dcb607ba
SHA1: eba832cbc0dc8da2e3a8bd3534806a2b9d321418
SHA256: 91953f4a034590e7dac4589038fe0ef7400e04cd2e1e54c0027d88ba0c545f18
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-alpn-client-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-alpn-client High
Vendor gradle artifactid jetty-alpn-client Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name alpn Highest
Vendor jar package name client Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.alpn.client Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-alpn-client Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: ALPN :: Client High
Vendor pom parent-artifactid jetty-alpn Low
Product file name jetty-alpn-client High
Product gradle artifactid jetty-alpn-client Highest
Product jar package name alpn Highest
Product jar package name client Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: ALPN :: Client Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.alpn.client Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-alpn-client Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: ALPN :: Client High
Product pom parent-artifactid jetty-alpn Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-alpn-conscrypt-server-12.1.8.jar
Description:
Jetty ALPN Server Conscrypt Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-alpn-conscrypt-server/12.1.8/4656edd8516fff59499ed9a0a737f6c6797ab2d/jetty-alpn-conscrypt-server-12.1.8.jar
MD5: 6e494ed4983e263194d696c23e8abfa9
SHA1: 04656edd8516fff59499ed9a0a737f6c6797ab2d
SHA256: ec569589f68d928e85d4f4f9b6f63768b46a3141bd68b555d16288c7aadc9882
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-alpn-conscrypt-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-alpn-conscrypt-server High
Vendor gradle artifactid jetty-alpn-conscrypt-server Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name alpn Highest
Vendor jar package name conscrypt Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.alpn.conscrypt.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Server" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-alpn-conscrypt-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: ALPN :: Conscrypt Server High
Vendor pom parent-artifactid jetty-alpn Low
Product file name jetty-alpn-conscrypt-server High
Product gradle artifactid jetty-alpn-conscrypt-server Highest
Product jar package name alpn Highest
Product jar package name conscrypt Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: ALPN :: Conscrypt Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.alpn.conscrypt.server Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Server" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-alpn-conscrypt-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: ALPN :: Conscrypt Server High
Product pom parent-artifactid jetty-alpn Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-alpn-java-client-12.1.8.jar
Description:
Jetty ALPN Client OpenJDK Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-alpn-java-client/12.1.8/72314c334fd32da5a75ec435d6f9cb9a12345afe/jetty-alpn-java-client-12.1.8.jar
MD5: ec80cf2a8e7a514e2bc23b047a08d4f1
SHA1: 72314c334fd32da5a75ec435d6f9cb9a12345afe
SHA256: 781696614cd0afd684cbb2a252021bca7c85fbb68bc0c28c8a9a7c65362f4d4a
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-alpn-java-client-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-alpn-java-client High
Vendor gradle artifactid jetty-alpn-java-client Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name alpn Highest
Vendor jar package name eclipse Highest
Vendor jar package name java Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.alpn.java.client Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Client" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-alpn-java-client Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: ALPN :: Java Client High
Vendor pom parent-artifactid jetty-alpn Low
Product file name jetty-alpn-java-client High
Product gradle artifactid jetty-alpn-java-client Highest
Product jar package name alpn Highest
Product jar package name eclipse Highest
Product jar package name java Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: ALPN :: Java Client Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.alpn.java.client Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Client" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-alpn-java-client Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: ALPN :: Java Client High
Product pom parent-artifactid jetty-alpn Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-alpn-java-server-12.1.8.jar
Description:
Jetty ALPN Server OpenJDK Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-alpn-java-server/12.1.8/c81e3a13de2c8cf0173f3841c411e0c31e9022a9/jetty-alpn-java-server-12.1.8.jar
MD5: 2ae28985edf13eacec2034ee5c1deaba
SHA1: c81e3a13de2c8cf0173f3841c411e0c31e9022a9
SHA256: 36cf96f5e254792ff078ce56242ffc5a8cb2dcd1bafb8364f8d8db0f286004db
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-alpn-java-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-alpn-java-server High
Vendor gradle artifactid jetty-alpn-java-server Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name alpn Highest
Vendor jar package name eclipse Highest
Vendor jar package name java Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.alpn.java.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Server" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-alpn-java-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: ALPN :: Java Server High
Vendor pom parent-artifactid jetty-alpn Low
Product file name jetty-alpn-java-server High
Product gradle artifactid jetty-alpn-java-server Highest
Product jar package name alpn Highest
Product jar package name eclipse Highest
Product jar package name java Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: ALPN :: Java Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.alpn.java.server Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.io.ssl.ALPNProcessor$Server" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-alpn-java-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: ALPN :: Java Server High
Product pom parent-artifactid jetty-alpn Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-alpn-server-12.1.8.jar
Description:
Jetty ALPN Server API Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-alpn-server/12.1.8/19bf9257d0012161b5e1f86dd2ecef1b06dd858c/jetty-alpn-server-12.1.8.jar
MD5: 083a0c6085d7c4d48d21353f2fdd2032
SHA1: 19bf9257d0012161b5e1f86dd2ecef1b06dd858c
SHA256: 7f35204e0837154f4348e81dcc84d15187055fccc0a922cc0c751ddb2753e8dd
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-alpn-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-alpn-server High
Vendor gradle artifactid jetty-alpn-server Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name alpn Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name server Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.alpn.server;singleton:=true Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-alpn-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: ALPN :: Server High
Vendor pom parent-artifactid jetty-alpn Low
Product file name jetty-alpn-server High
Product gradle artifactid jetty-alpn-server Highest
Product jar package name alpn Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name server Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: ALPN :: Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.alpn.server;singleton:=true Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-alpn-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: ALPN :: Server High
Product pom parent-artifactid jetty-alpn Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-annotations-12.1.8.jar
Description:
Jetty Annotations Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-annotations/12.1.8/83ef023274878069091ab8bccf266e7a9a8eb72d/jetty-annotations-12.1.8.jar
MD5: 25a44398020eaea470a71824b607d06f
SHA1: 83ef023274878069091ab8bccf266e7a9a8eb72d
SHA256: 7cefb27b4478c4e30d337ca2b215840bb009aac3e2c6c69a30bf41ed1de892b3
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-annotations-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-annotations High
Vendor gradle artifactid jetty-annotations Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name annotations Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.annotations Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-annotations Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Annotations High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-annotations High
Product gradle artifactid jetty-annotations Highest
Product jar package name annotations Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Annotations Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.annotations Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-annotations Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Annotations High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-client-12.1.8.jar
Description:
Jetty Client API and HTTP/1.1 Implementation Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-client/12.1.8/82c2805f296ff253ccdd36a8fb4d9a15bb5694e/jetty-client-12.1.8.jar
MD5: a5265f00eec6340aa885f22e8979d495
SHA1: 082c2805f296ff253ccdd36a8fb4d9a15bb5694e
SHA256: 460d4d74c95a591bf6c16be6388186427b773c0110605b3d329955f7a442122c
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-client-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-client High
Vendor gradle artifactid jetty-client Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name client Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.client Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-client Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: HTTP Client High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-client High
Product gradle artifactid jetty-client Highest
Product jar package name client Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: HTTP Client Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.client Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-client Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: HTTP Client High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-compression-common-12.1.8.jar
Description:
Jetty Compression Common Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.compression/jetty-compression-common/12.1.8/a88edf9dbf4dad0deb8b799483fbc9f8f217af78/jetty-compression-common-12.1.8.jar
MD5: 9c6508d9f073abf897ca775bcd8cccb0
SHA1: a88edf9dbf4dad0deb8b799483fbc9f8f217af78
SHA256: 46f12d348115f310130c7df6e736017c6e7dc032f19b96a0dc2658f56ec43bf1
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-compression-common-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-compression-common High
Vendor gradle artifactid jetty-compression-common Highest
Vendor gradle groupid org.eclipse.jetty.compression Highest
Vendor jar package name compression Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.compression.common Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-compression-common Low
Vendor pom groupid org.eclipse.jetty.compression Highest
Vendor pom name Core :: Compression :: Common High
Vendor pom parent-artifactid jetty-compression Low
Product file name jetty-compression-common High
Product gradle artifactid jetty-compression-common Highest
Product jar package name compression Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Compression :: Common Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.compression.common Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-compression-common Highest
Product pom groupid org.eclipse.jetty.compression Highest
Product pom name Core :: Compression :: Common High
Product pom parent-artifactid jetty-compression Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-compression-gzip-12.1.8.jar
Description:
Jetty Compression Gzip Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.compression/jetty-compression-gzip/12.1.8/cb44ba5d5a05383e8fa612bf265aa86b238e0893/jetty-compression-gzip-12.1.8.jar
MD5: 9680c74c689de5bfd88f3a50d11636d7
SHA1: cb44ba5d5a05383e8fa612bf265aa86b238e0893
SHA256: 482455c2e4b243913354dfd52cf2a68becfb9a7479c1deb385019f97925f0ae0
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-compression-gzip-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-compression-gzip High
Vendor gradle artifactid jetty-compression-gzip Highest
Vendor gradle groupid org.eclipse.jetty.compression Highest
Vendor jar package name compression Highest
Vendor jar package name eclipse Highest
Vendor jar package name gzip Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.compression.gzip Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.compression.Compression" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-compression-gzip Low
Vendor pom groupid org.eclipse.jetty.compression Highest
Vendor pom name Core :: Compression :: Gzip Support High
Vendor pom parent-artifactid jetty-compression Low
Product file name jetty-compression-gzip High
Product gradle artifactid jetty-compression-gzip Highest
Product jar package name compression Highest
Product jar package name eclipse Highest
Product jar package name gzip Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Compression :: Gzip Support Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.compression.gzip Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.compression.Compression" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-compression-gzip Highest
Product pom groupid org.eclipse.jetty.compression Highest
Product pom name Core :: Compression :: Gzip Support High
Product pom parent-artifactid jetty-compression Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-deploy-12.1.8.jar
Description:
Jetty Deployer Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-deploy/12.1.8/d37ec3197448ee0cf4895f90ba08530f4441f4e6/jetty-deploy-12.1.8.jar
MD5: 36168f0a2ff0a4857c2953dfa50fb3be
SHA1: d37ec3197448ee0cf4895f90ba08530f4441f4e6
SHA256: 46e91f87ad0f45db660136f761f65770beb9a7bda626fc01409ff507c15692cc
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-deploy-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-deploy High
Vendor gradle artifactid jetty-deploy Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name deploy Highest
Vendor jar package name deployer Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.deploy Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-deploy Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Deployer High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-deploy High
Product gradle artifactid jetty-deploy Highest
Product jar package name deploy Highest
Product jar package name deployer Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Deployer Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.deploy Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-deploy Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Deployer High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee-webapp-12.1.8.jar
Description:
Jetty EE Web Application Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee/jetty-ee-webapp/12.1.8/d2e9f2449f95901162b33b1278b665531f0a2949/jetty-ee-webapp-12.1.8.jar
MD5: 534606aaac229b855ac2689d3dc64a40
SHA1: d2e9f2449f95901162b33b1278b665531f0a2949
SHA256: e9fec4d92b8b0b5b6ade18268944de28710df8fe83417c2d5670cb42540b0a45
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee-webapp-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee-webapp High
Vendor gradle artifactid jetty-ee-webapp Highest
Vendor gradle groupid org.eclipse.jetty.ee Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee Highest
Vendor jar package name jetty Highest
Vendor jar package name webapp Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee.webapp Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee-webapp Low
Vendor pom groupid org.eclipse.jetty.ee Highest
Vendor pom name Core :: EE :: Web Application High
Vendor pom parent-artifactid jetty-ee Low
Product file name jetty-ee-webapp High
Product gradle artifactid jetty-ee-webapp Highest
Product jar package name eclipse Highest
Product jar package name ee Highest
Product jar package name jetty Highest
Product jar package name webapp Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: EE :: Web Application Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee.webapp Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee-webapp Highest
Product pom groupid org.eclipse.jetty.ee Highest
Product pom name Core :: EE :: Web Application High
Product pom parent-artifactid jetty-ee Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-annotations-12.1.8.jar
Description:
Annotation support for deploying servlets in jetty.
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-annotations/12.1.8/6f314d934a389d7c069fd82ec9a5b5b682114914/jetty-ee10-annotations-12.1.8.jar
MD5: 6e06c982bcd1afa14d9d326aafcb10e9
SHA1: 6f314d934a389d7c069fd82ec9a5b5b682114914
SHA256: 9ae2cebd0388a5009ff85e4c740e8cc79b2a165472032a51020a640dc64b53d2
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee10-annotations-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-annotations High
Vendor gradle artifactid jetty-ee10-annotations Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name annotations Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.annotations Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-annotations Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: Servlet Annotations High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-annotations High
Product gradle artifactid jetty-ee10-annotations Highest
Product jar package name annotations Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: Servlet Annotations Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.annotations Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-annotations Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: Servlet Annotations High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-jaspi-12.1.8.jar
Description:
Jetty security infrastructure
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-jaspi/12.1.8/e5ead55ba9f0839752b3fb327a4ca1491fa3bf5b/jetty-ee10-jaspi-12.1.8.jar
MD5: 5b658762ebf6527288f9043f5bc1a721
SHA1: e5ead55ba9f0839752b3fb327a4ca1491fa3bf5b
SHA256: 2c83aa62934a8a82399a04162a57a1338641cac37fb800f9017a8d0d609fc5d2
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-ee10-jaspi-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-jaspi High
Vendor gradle artifactid jetty-ee10-jaspi Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name security Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.security.jaspi Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.servlet.security.Authenticator$Factory" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-jaspi Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: JASPI High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-jaspi High
Product gradle artifactid jetty-ee10-jaspi Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name security Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: JASPI Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.security.jaspi Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.servlet.security.Authenticator$Factory" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-jaspi Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: JASPI High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-plus-12.1.8.jar
Description:
Jetty JavaEE style services
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-plus/12.1.8/77dde816a41ec2ccdac4de3db16b8f40ede76033/jetty-ee10-plus-12.1.8.jar
MD5: 716b8bdb3fe1033c092bb4478df466b5
SHA1: 77dde816a41ec2ccdac4de3db16b8f40ede76033
SHA256: 7e16fb8fcd7492a13c98fe0416a85fb8ddf6dfd90564e8e4ced76af209c424b8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee10-plus-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-plus High
Vendor gradle artifactid jetty-ee10-plus Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name plus Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.plus Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-plus Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: Plus High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-plus High
Product gradle artifactid jetty-ee10-plus Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name plus Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: Plus Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.plus Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-plus Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: Plus High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-quickstart-12.1.8.jar
Description:
Jetty Quick Start
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-quickstart/12.1.8/bfac0da71f59b7fffc50a0f6665e7583e384bf1/jetty-ee10-quickstart-12.1.8.jar
MD5: 8fb590b8c61193f1c1d230c8865f81d1
SHA1: 0bfac0da71f59b7fffc50a0f6665e7583e384bf1
SHA256: 532fc7d63d63dfde13b5f629ca6a8a9b7dd132a078c06e3f06da82aff4fe27cd
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-ee10-quickstart-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-quickstart High
Vendor gradle artifactid jetty-ee10-quickstart Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name quickstart Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.quickstart Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-quickstart Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: Quick Start High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-quickstart High
Product gradle artifactid jetty-ee10-quickstart Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name quickstart Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: Quick Start Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.quickstart Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-quickstart Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: Quick Start High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-servlet-12.1.8.jar
Description:
Jetty Servlet Container
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-servlet/12.1.8/33b226821b5a88f6785ea5f13a90ecb4112cec87/jetty-ee10-servlet-12.1.8.jar
MD5: eb60ab2999bcebac23397e12eab56c84
SHA1: 33b226821b5a88f6785ea5f13a90ecb4112cec87
SHA256: c6251faae241b2b6879ce8fb9177366ca4793ff9356f60793b8d10a1f1fef404
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee10-servlet-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-servlet High
Vendor gradle artifactid jetty-ee10-servlet Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.servlet Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-servlet Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: Servlet High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-servlet High
Product gradle artifactid jetty-ee10-servlet Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: Servlet Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.servlet Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-servlet Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: Servlet High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-servlets-12.1.8.jar
Description:
Utility Servlets from Jetty
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-servlets/12.1.8/2bb3241579f1a6ba879ebdd51bfa565935eada4b/jetty-ee10-servlets-12.1.8.jar
MD5: 5d72fe07f4019968f7474c9997e762f5
SHA1: 2bb3241579f1a6ba879ebdd51bfa565935eada4b
SHA256: b0af9c62f9eeeab4af13dcd1b9b0f5d4fdf97955c977d54ca1458f1402b29e3d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee10-servlets-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-servlets High
Vendor gradle artifactid jetty-ee10-servlets Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name servlets Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.servlets Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-servlets Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: Utility Servlets and Filters High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-servlets High
Product gradle artifactid jetty-ee10-servlets Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name servlets Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: Utility Servlets and Filters Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.servlets Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-servlets Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: Utility Servlets and Filters High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-ee10-webapp-12.1.8.jar
Description:
Jetty web application support
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.ee10/jetty-ee10-webapp/12.1.8/c9eebb08e95b6c7688d02ef59257614f8a195026/jetty-ee10-webapp-12.1.8.jar
MD5: df7eae6f180d5a933767f4c4636301ff
SHA1: c9eebb08e95b6c7688d02ef59257614f8a195026
SHA256: 1a534cb6287a88736fad2ac54295ab5dc1aba4dc9d2c94e39ead7f01d377a56f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-ee10-webapp-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-ee10-webapp High
Vendor gradle artifactid jetty-ee10-webapp Highest
Vendor gradle groupid org.eclipse.jetty.ee10 Highest
Vendor jar package name eclipse Highest
Vendor jar package name ee10 Highest
Vendor jar package name jetty Highest
Vendor jar package name webapp Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.ee10.webapp Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-ee10-webapp Low
Vendor pom groupid org.eclipse.jetty.ee10 Highest
Vendor pom name EE10 :: WebApp High
Vendor pom parent-artifactid jetty-ee10 Low
Product file name jetty-ee10-webapp High
Product gradle artifactid jetty-ee10-webapp Highest
Product jar package name eclipse Highest
Product jar package name ee10 Highest
Product jar package name jetty Highest
Product jar package name webapp Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name EE10 :: WebApp Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.ee10.webapp Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.ee10.webapp.Configuration" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-ee10-webapp Highest
Product pom groupid org.eclipse.jetty.ee10 Highest
Product pom name EE10 :: WebApp High
Product pom parent-artifactid jetty-ee10 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-http-12.1.8.jar
Description:
Jetty HTTP Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/12.1.8/f81c67e84bdac2a1bd0ce343a927b8b0c35d91a1/jetty-http-12.1.8.jar
MD5: 8ac4b6aa8bcbd260cbc7aa12ae572904
SHA1: f81c67e84bdac2a1bd0ce343a927b8b0c35d91a1
SHA256: 32c351984fd74e7db9b3120f7aa43c034a9d7fe290386747ff318f4c4221d94b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-http-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-http High
Vendor gradle artifactid jetty-http Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name http Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.http Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-http Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: HTTP High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-http High
Product gradle artifactid jetty-http Highest
Product jar package name eclipse Highest
Product jar package name http Highest
Product jar package name httpfieldpreencoder Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: HTTP Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.http Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-http Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: HTTP High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-http2-common-12.1.8.jar
Description:
Jetty HTTP/2 Common Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.http2/jetty-http2-common/12.1.8/7bb96d3c2b28946660cc3097ca391d8eca181363/jetty-http2-common-12.1.8.jar
MD5: c18d8f0747df78b4126586d106c9421e
SHA1: 7bb96d3c2b28946660cc3097ca391d8eca181363
SHA256: fba638a53abd3985d0cb568ed35170cb708dbdda364aa6c087a4e54a4ad850cb
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-http2-common-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-http2-common High
Vendor gradle artifactid jetty-http2-common Highest
Vendor gradle groupid org.eclipse.jetty.http2 Highest
Vendor jar package name eclipse Highest
Vendor jar package name http2 Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.http2.common Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-http2-common Low
Vendor pom groupid org.eclipse.jetty.http2 Highest
Vendor pom name Core :: HTTP2 :: Common High
Vendor pom parent-artifactid jetty-http2 Low
Product file name jetty-http2-common High
Product gradle artifactid jetty-http2-common Highest
Product jar package name eclipse Highest
Product jar package name http2 Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: HTTP2 :: Common Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.http2.common Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-http2-common Highest
Product pom groupid org.eclipse.jetty.http2 Highest
Product pom name Core :: HTTP2 :: Common High
Product pom parent-artifactid jetty-http2 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-http2-hpack-12.1.8.jar
Description:
Jetty HTTP/2 HPACK Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.http2/jetty-http2-hpack/12.1.8/4239e1a8d00dd1fa6afe29c7623e531b7490516/jetty-http2-hpack-12.1.8.jar
MD5: de508b8a4f3c62468208283ebdf14020
SHA1: 04239e1a8d00dd1fa6afe29c7623e531b7490516
SHA256: 7eb7fc3d1420fcc8c04df7cdd8e35f6e96a927f5a4cc455734d108af7079a898
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-http2-hpack-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-http2-hpack High
Vendor gradle artifactid jetty-http2-hpack Highest
Vendor gradle groupid org.eclipse.jetty.http2 Highest
Vendor jar package name eclipse Highest
Vendor jar package name hpack Highest
Vendor jar package name http2 Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.http2.hpack Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-http2-hpack Low
Vendor pom groupid org.eclipse.jetty.http2 Highest
Vendor pom name Core :: HTTP2 :: HPACK High
Vendor pom parent-artifactid jetty-http2 Low
Product file name jetty-http2-hpack High
Product gradle artifactid jetty-http2-hpack Highest
Product jar package name eclipse Highest
Product jar package name hpack Highest
Product jar package name http2 Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: HTTP2 :: HPACK Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.http2.hpack Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.http.HttpFieldPreEncoder" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-http2-hpack Highest
Product pom groupid org.eclipse.jetty.http2 Highest
Product pom name Core :: HTTP2 :: HPACK High
Product pom parent-artifactid jetty-http2 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-http2-server-12.1.8.jar
Description:
Jetty HTTP/2 Server Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.http2/jetty-http2-server/12.1.8/d6a3ba74c43cd2355b1ef90b1a5e06b57e77f40d/jetty-http2-server-12.1.8.jar
MD5: 0a7e0eb69f48649c0439e59fd5c60dcc
SHA1: d6a3ba74c43cd2355b1ef90b1a5e06b57e77f40d
SHA256: e5c99e8b7dc386f6e61a661458128e0c0a6a40be29df1333715328e0f5feb284
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-http2-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-http2-server High
Vendor gradle artifactid jetty-http2-server Highest
Vendor gradle groupid org.eclipse.jetty.http2 Highest
Vendor jar package name eclipse Highest
Vendor jar package name http2 Highest
Vendor jar package name jetty Highest
Vendor jar package name server Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.http2.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-http2-server Low
Vendor pom groupid org.eclipse.jetty.http2 Highest
Vendor pom name Core :: HTTP2 :: Server High
Vendor pom parent-artifactid jetty-http2 Low
Product file name jetty-http2-server High
Product gradle artifactid jetty-http2-server Highest
Product jar package name eclipse Highest
Product jar package name http2 Highest
Product jar package name jetty Highest
Product jar package name server Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: HTTP2 :: Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.http2.server Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-http2-server Highest
Product pom groupid org.eclipse.jetty.http2 Highest
Product pom name Core :: HTTP2 :: Server High
Product pom parent-artifactid jetty-http2 Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-io-12.1.8.jar
Description:
Jetty I/O Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-io/12.1.8/d3c296acc6b8faa9ed69bd10f5a6afab05a61222/jetty-io-12.1.8.jar
MD5: 62475115a7f7b9ee160adb339b9f546f
SHA1: d3c296acc6b8faa9ed69bd10f5a6afab05a61222
SHA256: c45a68ceed3526f5ca0974768caa61f6683c3d5591a819fbcf3c0480a64ab245
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-io-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-io High
Vendor gradle artifactid jetty-io Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name io Highest
Vendor jar package name jetty Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-io Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: IO High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-io High
Product gradle artifactid jetty-io Highest
Product jar package name eclipse Highest
Product jar package name io Highest
Product jar package name jetty Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: IO Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-io Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: IO High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-jmx-12.1.8.jar
Description:
Jetty JMX Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-jmx/12.1.8/ae31f4568f1cd7b611190e1d80057a1cc9d78031/jetty-jmx-12.1.8.jar
MD5: 697660bf3d040abe690009e760666530
SHA1: ae31f4568f1cd7b611190e1d80057a1cc9d78031
SHA256: ee0bcc35da8abef43eba822afce66fa227cc6ec170a258d03f3f89df42454ab5
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-jmx-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-jmx High
Vendor gradle artifactid jetty-jmx Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name jmx Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-jmx Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: JMX High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-jmx High
Product gradle artifactid jetty-jmx Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name jmx Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: JMX Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-jmx Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: JMX High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-jndi-12.1.8.jar
Description:
Jetty JNDI Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-jndi/12.1.8/33d153f60d2c96a1b67561c4a9edc7563fc7c3a6/jetty-jndi-12.1.8.jar
MD5: 31990a3e0c9bbd5c7142d66345e3da5c
SHA1: 33d153f60d2c96a1b67561c4a9edc7563fc7c3a6
SHA256: e13688fbe27219cf30b7c2dea27e584b2bd29c4fc2b2b74374eff877fe8a7bcc
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-jndi-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-jndi High
Vendor gradle artifactid jetty-jndi Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name jndi Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.jndi Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-jndi Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: JNDI High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-jndi High
Product gradle artifactid jetty-jndi Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name jndi Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: JNDI Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.jndi Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-jndi Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: JNDI High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-keystore-12.1.8.jar
Description:
Jetty Test KeyStore Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-keystore/12.1.8/a6b8ae8badfa86eb81212fe474fadae295ae08e1/jetty-keystore-12.1.8.jar
MD5: 4e026af7458941e985067d25ba5a6851
SHA1: a6b8ae8badfa86eb81212fe474fadae295ae08e1
SHA256: b7456e7781d5da1ed0b2b952680405988ebcd18976ea3c895919da2bb4ed8b96
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-keystore-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-keystore High
Vendor gradle artifactid jetty-keystore Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name keystore Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.keystore Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-keystore Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Test Keystore High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-keystore High
Product gradle artifactid jetty-keystore Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name keystore Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Test Keystore Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.keystore Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-keystore Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Test Keystore High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-memcached-sessions-12.1.8.jar
Description:
Jetty module for Integrations :: Memcached :: Sessions
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty.memcached/jetty-memcached-sessions/12.1.8/24f27ec44e275dc20ff27659b592c5ecc21ccdb6/jetty-memcached-sessions-12.1.8.jar
MD5: 0beae16c41bdfb2054570352c9fecbb0
SHA1: 24f27ec44e275dc20ff27659b592c5ecc21ccdb6
SHA256: 325958c90b9f3baf9799c16882bc3f202928d6fcf93e339a478fad06fa237963
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-memcached-sessions-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-memcached-sessions High
Vendor gradle artifactid jetty-memcached-sessions Highest
Vendor gradle groupid org.eclipse.jetty.memcached Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name memcached Highest
Vendor jar package name session Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.memcached.session Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-memcached-sessions Low
Vendor pom groupid org.eclipse.jetty.memcached Highest
Vendor pom name Integrations :: Memcached :: Sessions High
Vendor pom parent-artifactid jetty-memcached Low
Product file name jetty-memcached-sessions High
Product gradle artifactid jetty-memcached-sessions Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name memcached Highest
Product jar package name session Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Integrations :: Memcached :: Sessions Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.memcached.session Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-memcached-sessions Highest
Product pom groupid org.eclipse.jetty.memcached Highest
Product pom name Integrations :: Memcached :: Sessions High
Product pom parent-artifactid jetty-memcached Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-nosql-12.1.8.jar
Description:
Jetty module for Integrations :: NoSQL :: Sessions
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-nosql/12.1.8/88924ed8f6cddd4e970753adc0b1e132af549e15/jetty-nosql-12.1.8.jar
MD5: bb7518991142d54aec5c1768c29e65f6
SHA1: 88924ed8f6cddd4e970753adc0b1e132af549e15
SHA256: e1f109ab906d30596bef6fbeb574e8a5473afb8006072ca7d4eacb9f607be1cc
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-nosql-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-nosql High
Vendor gradle artifactid jetty-nosql Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name nosql Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.nosql Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-nosql Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Integrations :: NoSQL :: Sessions High
Vendor pom parent-artifactid jetty-integrations Low
Product file name jetty-nosql High
Product gradle artifactid jetty-nosql Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name nosql Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Integrations :: NoSQL :: Sessions Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.nosql Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-nosql Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Integrations :: NoSQL :: Sessions High
Product pom parent-artifactid jetty-integrations Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-openid-12.1.8.jar
Description:
Jetty OpenID Connect Infrastructure
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-openid/12.1.8/bf42bbda535bb25e0293177a3589eb489e4342c5/jetty-openid-12.1.8.jar
MD5: 3576fe03225d9452c71a3cebaf4a1c11
SHA1: bf42bbda535bb25e0293177a3589eb489e4342c5
SHA256: f56e0a329e531011a9d03fc7c46fe98cd8e36a15ee8c83c2f30ef25073af9c73
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-openid-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-openid High
Vendor gradle artifactid jetty-openid Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name openid Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.openid Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.security.Authenticator$Factory" Low
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-openid Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: OpenID High
Vendor pom parent-artifactid jetty-integrations Low
Product file name jetty-openid High
Product gradle artifactid jetty-openid Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name openid Highest
Product jar package name security Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: OpenID Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.openid Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.eclipse.jetty.security.Authenticator$Factory" Low
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-openid Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: OpenID High
Product pom parent-artifactid jetty-integrations Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-plus-12.1.8.jar
Description:
Jetty JNDI and Annotation Support Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-plus/12.1.8/f6bb2e545063821aba6276118278ba773e5eb6c6/jetty-plus-12.1.8.jar
MD5: 4b4bee391a550d6a5c14df5172798eba
SHA1: f6bb2e545063821aba6276118278ba773e5eb6c6
SHA256: 912a3c423c5a8911fb074519016d699b4221e722536ae66315a7c2db595df5f9
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-plus-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-plus High
Vendor gradle artifactid jetty-plus Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name annotation Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name jndi Highest
Vendor jar package name plus Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.plus Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-plus Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Plus High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-plus High
Product gradle artifactid jetty-plus Highest
Product jar package name annotation Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name jndi Highest
Product jar package name plus Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Plus Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.plus Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-plus Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Plus High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-proxy-12.1.8.jar
Description:
Jetty Proxy Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-proxy/12.1.8/4c642d96e5ff15a4ee8ac016a8dd41a6b88a581e/jetty-proxy-12.1.8.jar
MD5: 227f4cba5ab9b7ff42bbc0de33c80a0e
SHA1: 4c642d96e5ff15a4ee8ac016a8dd41a6b88a581e
SHA256: b8387449fbb959bbb7788c56c1e3cf78a7069c60529842ce6a8d7e3751fe97fb
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-proxy-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-proxy High
Vendor gradle artifactid jetty-proxy Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name proxy Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.proxy Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-proxy Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Proxy High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-proxy High
Product gradle artifactid jetty-proxy Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name proxy Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Proxy Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.proxy Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-proxy Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Proxy High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-rewrite-12.1.8.jar
Description:
Jetty Rewrite Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-rewrite/12.1.8/ee35fd7b3eb480c1c98a0be712938dfa4cb7e4f8/jetty-rewrite-12.1.8.jar
MD5: e7c9812d3f0b1ab3556deb452745c158
SHA1: ee35fd7b3eb480c1c98a0be712938dfa4cb7e4f8
SHA256: 059cb6b7282c66d5c8eacdaf7ecc25f51a255edd0de9885e5aaba3e1392d93fd
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-rewrite-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-rewrite High
Vendor gradle artifactid jetty-rewrite Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name rewrite Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.rewrite Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-rewrite Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Rewrite High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-rewrite High
Product gradle artifactid jetty-rewrite Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name rewrite Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Rewrite Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.rewrite Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-rewrite Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Rewrite High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-security-12.1.8.jar
Description:
Jetty Server Security Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-security/12.1.8/7f232a53199b527eee7047550efd84cdb11bf6ad/jetty-security-12.1.8.jar
MD5: 886a13d3232e2fe7ebe42a05bcfd0023
SHA1: 7f232a53199b527eee7047550efd84cdb11bf6ad
SHA256: 44add9ee95b955d96979cc74e32ec751ea807ebc0f5139eb13adcfc23712c58f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-security-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-security High
Vendor gradle artifactid jetty-security Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name security Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.security Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-security Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Security High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-security High
Product gradle artifactid jetty-security Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name security Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Security Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.security Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-security Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Security High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-server-12.1.8.jar
Description:
Jetty Server Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/12.1.8/685b1767938944fdf846b233902afdc375767d0/jetty-server-12.1.8.jar
MD5: 989b63a44b7397bcc9e996811d30d8a8
SHA1: 0685b1767938944fdf846b233902afdc375767d0
SHA256: 71b8862a72305aebb65909b8b9f3c9a0c790ef3245c6056e56b48117aec238fe
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-server High
Vendor gradle artifactid jetty-server Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name server Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Server High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-server High
Product gradle artifactid jetty-server Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name server Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.server Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Server High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-session-12.1.8.jar
Description:
Jetty Session Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-session/12.1.8/4c9e22e3db77591958eb9a10d963a60e26c0333a/jetty-session-12.1.8.jar
MD5: ca2b2f3fa9749655de59f7e4a07e810a
SHA1: 4c9e22e3db77591958eb9a10d963a60e26c0333a
SHA256: ebe84dd41942d7adda5f7d1304095d274e7915999451d848e887cbd409f947ea
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-session-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-session High
Vendor gradle artifactid jetty-session Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name session Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.session Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-session Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Sessions High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-session High
Product gradle artifactid jetty-session Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name session Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Sessions Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.session Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-session Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Sessions High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-unixdomain-server-12.1.8.jar
Description:
Jetty Unix-Domain Sockets Server Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-unixdomain-server/12.1.8/d7f59488a5c07059388182e79caa014effe70cad/jetty-unixdomain-server-12.1.8.jar
MD5: 3124d567341e49a637752507ae107644
SHA1: d7f59488a5c07059388182e79caa014effe70cad
SHA256: 8ba90a08d8db7130ca5aaf8c1a7f8fef922792f12702041cbbe63c07fee08881
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-unixdomain-server-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-unixdomain-server High
Vendor gradle artifactid jetty-unixdomain-server Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name server Highest
Vendor jar package name unixdomain Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.unixdomain.server Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-unixdomain-server Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Unix-Domain Sockets :: Server High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-unixdomain-server High
Product gradle artifactid jetty-unixdomain-server Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name server Highest
Product jar package name unixdomain Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Unix-Domain Sockets :: Server Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.unixdomain.server Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-unixdomain-server Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Unix-Domain Sockets :: Server High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-util-12.1.8.jar
Description:
Jetty Utilities Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util/12.1.8/96a48334b31af4d852a25e150a89255e117b5045/jetty-util-12.1.8.jar
MD5: 08e1bc3009f9beacbb1130cbf8d7ef61
SHA1: 96a48334b31af4d852a25e150a89255e117b5045
SHA256: 00432715f20c3ddc8d4fe3b01974253a7772f1830f7712da71af30348b01c822
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-util-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-util High
Vendor gradle artifactid jetty-util Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name util Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.util Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-util Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Utilities High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-util High
Product gradle artifactid jetty-util Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name util Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Utilities Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.util Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-util Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Utilities High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-util-ajax-12.1.8.jar
Description:
Jetty JSON Utilities Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-util-ajax/12.1.8/78ad2456d1e9f00bd44737b15052528ca3592d32/jetty-util-ajax-12.1.8.jar
MD5: c5a258ab31d7651bbbd2fcd5a4738e5b
SHA1: 78ad2456d1e9f00bd44737b15052528ca3592d32
SHA256: bb127d1fb397148eb63107a29a16b17d755acd2308919d3891df84d7ba3406ea
Referenced In Project/Scope: server-start:runtimeClasspath
jetty-util-ajax-12.1.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-util-ajax High
Vendor gradle artifactid jetty-util-ajax Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name ajax Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name util Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.util.ajax Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-util-ajax Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: Utilities :: JSON High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-util-ajax High
Product gradle artifactid jetty-util-ajax Highest
Product jar package name ajax Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name util Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: Utilities :: JSON Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.util.ajax Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-util-ajax Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: Utilities :: JSON High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jetty-xml-12.1.8.jar
Description:
Jetty XML Artifact
License:
EPL-2.0 OR Apache-2.0
https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-xml/12.1.8/cb879f41667e409c53ff0a2136a03d6b538156c6/jetty-xml-12.1.8.jar
MD5: 1666e5dcfd111f057e2f61c388b46fd5
SHA1: cb879f41667e409c53ff0a2136a03d6b538156c6
SHA256: 0d8eef335d4bd1961e38861dce9128e0d65ba3a21d3e771ef4fa78045feb3516
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jetty-xml-12.1.8.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jetty-xml High
Vendor gradle artifactid jetty-xml Highest
Vendor gradle groupid org.eclipse.jetty Highest
Vendor jar package name eclipse Highest
Vendor jar package name jetty Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 25 Low
Vendor Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Vendor Manifest bundle-docurl https://jetty.org/ Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.xml Medium
Vendor Manifest Implementation-Vendor Eclipse Jetty Project High
Vendor Manifest url https://jetty.org/ Low
Vendor pom artifactid jetty-xml Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Core :: XML High
Vendor pom parent-artifactid jetty-core Low
Product file name jetty-xml High
Product gradle artifactid jetty-xml Highest
Product jar package name eclipse Highest
Product jar package name jetty Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 25 Low
Product Manifest bundle-copyright Copyright (c) 1995 Mort Bay Consulting Pty Ltd and others. Low
Product Manifest bundle-docurl https://jetty.org/ Low
Product Manifest Bundle-Name Core :: XML Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.xml Medium
Product Manifest url https://jetty.org/ Low
Product pom artifactid jetty-xml Highest
Product pom groupid org.eclipse.jetty Highest
Product pom name Core :: XML High
Product pom parent-artifactid jetty-core Medium
Version file version 12.1.8 High
Version gradle version 12.1.8 Highest
Version Manifest Bundle-Version 12.1.8 High
Version Manifest Implementation-Version 12.1.8 High
Version pom version 12.1.8 Highest
jibx-run-1.3.3.jar
Description:
JiBX runtime code
License:
http://jibx.sourceforge.net/jibx-license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jibx/jibx-run/1.3.3/7828a2a63cda4ee1b0da3fe05b8652e49e73697d/jibx-run-1.3.3.jar
MD5: 76f763b5d103f81b49bad5ff9bc8c2ad
SHA1: 7828a2a63cda4ee1b0da3fe05b8652e49e73697d
SHA256: 2dbe9429e10587d36dd3a2c68ffac377417995e10870ec05449e18277c2be27e
Referenced In Project/Scope: server-start:runtimeClasspath
jibx-run-1.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jibx-run High
Vendor gradle artifactid jibx-run Highest
Vendor gradle groupid org.jibx Highest
Vendor jar package name jibx Highest
Vendor jar package name runtime Highest
Vendor Manifest bundle-docurl http://www.jibx.org Low
Vendor Manifest bundle-symbolicname jibx-run Medium
Vendor pom artifactid jibx-run Low
Vendor pom groupid org.jibx Highest
Vendor pom name jibx-run - JiBX runtime High
Vendor pom parent-artifactid main-reactor Low
Vendor pom parent-groupid org.jibx.config Medium
Product file name jibx-run High
Product gradle artifactid jibx-run Highest
Product jar package name jibx Highest
Product jar package name runtime Highest
Product Manifest bundle-docurl http://www.jibx.org Low
Product Manifest Bundle-Name jibx-run - JiBX runtime Medium
Product Manifest bundle-symbolicname jibx-run Medium
Product pom artifactid jibx-run Highest
Product pom groupid org.jibx Highest
Product pom name jibx-run - JiBX runtime High
Product pom parent-artifactid main-reactor Medium
Product pom parent-groupid org.jibx.config Medium
Version file version 1.3.3 High
Version gradle version 1.3.3 Highest
Version Manifest Bundle-Version 1.3.3 High
Version pom version 1.3.3 Highest
pkg:maven/org.jibx/jibx-run@1.3.3
(Confidence :High)
jline-3.26.0.jar (shaded: org.jline:jansi-core:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jansi-core/pom.xml
MD5: b6e465aa47831fe034d38c6ef67b06db
SHA1: 0fdcc9e72850ff7fab838b3d063bf1beb908dbb7
SHA256: 80f53bca8fa53deaf09a03a8277201a3819d9fdcc81736f710cf958fa94fb423
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jansi-core Low
Vendor pom groupid org.jline Highest
Vendor pom name Jansi Core High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jansi-core Highest
Product pom groupid org.jline Highest
Product pom name Jansi Core High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-builtins:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-builtins/pom.xml
MD5: c92a0253c28cc60c60884bc983e953f3
SHA1: 80221379a7e4dc5f85eb106c724fbbb4338576a2
SHA256: d5d766d5cfe04788a59431383c99dc3164a07c809d3e16aeef5b6d27dcdccc8f
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-builtins Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Builtins High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-builtins Highest
Product pom groupid org.jline Highest
Product pom name JLine Builtins High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-native:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-native/pom.xml
MD5: 5689aed33ececfaeb9b61aa0d6257b14
SHA1: dcd6d0ff64c0d56cb83fd8c00e707fbbc9abc05c
SHA256: 9f40981a725e6ab155b6432757500ea75c5ab3107ef9c13aaba52a41059c6c17
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-native Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Native Library High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-native Highest
Product pom groupid org.jline Highest
Product pom name JLine Native Library High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-reader:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-reader/pom.xml
MD5: a0d38d43cbba56363cfcc57aa4c95a22
SHA1: c749090bb08b0f561b18dd530f857cc9630e35d0
SHA256: f05f0fbf885eed7341ca7bb14da3be13fd2104bb08dc7e1d317e80925a1ce8fd
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-reader Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Reader High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-reader Highest
Product pom groupid org.jline Highest
Product pom name JLine Reader High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-remote-ssh:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-remote-ssh/pom.xml
MD5: b72f67e6b60c204d4794911b36818128
SHA1: 8dd617be528c71388fecac9bb4f82381f8f875b7
SHA256: a77ad4d7d66c461339e94e53516e7fb504e409fb0fcb34c9b651e7f2d33ee172
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-remote-ssh Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Remote SSH High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-remote-ssh Highest
Product pom groupid org.jline Highest
Product pom name JLine Remote SSH High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-remote-telnet:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml
MD5: 2e9e6137bbdb5ecb7b6d73a6c7c29b9d
SHA1: 07274e52d047e284fbdde6514937a1456a7c6639
SHA256: 748675aaaec027ddc264fe51fc83ec4f52df918e952784fa2ee09788159f676f
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-remote-telnet Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Remote Telnet High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-remote-telnet Highest
Product pom groupid org.jline Highest
Product pom name JLine Remote Telnet High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-style:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-style/pom.xml
MD5: aa9995a893393248b12a53c56abac91e
SHA1: a0364c36a11e8f73b69df7fae9927489a3b6fed8
SHA256: 89cf6b0ed729409b290bdc851f6ad16e22c54cef6dbfdb465b35b78ae62946e0
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-style Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Style High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-style Highest
Product pom groupid org.jline Highest
Product pom name JLine Style High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-terminal-ffm:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-terminal-ffm/pom.xml
MD5: facd2bad4ebb5522060439de8cdd511a
SHA1: e15b0f0ca9555019934861370d533bd881d9a144
SHA256: f4af41b3c16bbc6fb4fd71d45787608dc0e8ab99d3b10c1e83e7d0b78b072d0b
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-terminal-ffm Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine FFM Terminal High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-terminal-ffm Highest
Product pom groupid org.jline Highest
Product pom name JLine FFM Terminal High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-terminal-jansi:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-terminal-jansi/pom.xml
MD5: e775db2d7857f0ec164d9c8651e3fea2
SHA1: f1a6df0edcac9bffd842c32c97d555d6b8878db7
SHA256: 98619dea9aaaddda16adc62e56a1575b1d5737956d8a6776fe31078637717330
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-terminal-jansi Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine JANSI Terminal High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-terminal-jansi Highest
Product pom groupid org.jline Highest
Product pom name JLine JANSI Terminal High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-terminal-jna:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-terminal-jna/pom.xml
MD5: be76420174f74c8c8a99215f783bec53
SHA1: 635a821fc1fde492b8da41a242dbf0288d8bc2e4
SHA256: 88dcbebaf0406cf36460a011e7f2a7bc5834067fb41ef2e6c7a951b4c0c09803
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-terminal-jna Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine JNA Terminal High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-terminal-jna Highest
Product pom groupid org.jline Highest
Product pom name JLine JNA Terminal High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-terminal-jni:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-terminal-jni/pom.xml
MD5: 75e186687905901f1361b719d79eca00
SHA1: 432d8e636d8765f091d4205300f7e3c5f51ac59b
SHA256: eaba4512bd49d1616adc66ca5106dd7bae17609cb361a090d14755ce72d55bd5
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-terminal-jni Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine JNI Terminal High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-terminal-jni Highest
Product pom groupid org.jline Highest
Product pom name JLine JNI Terminal High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar (shaded: org.jline:jline-terminal:3.26.0)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/META-INF/maven/org.jline/jline-terminal/pom.xml
MD5: a369265dc6f3c1be49725c2b529ae595
SHA1: 9116df6b7e366b415be5cc308189e267ac59554a
SHA256: ee3708331f323983546cb1e64b0891b3ed232d6d576069acd90fbb1dc970bd35
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline-terminal Low
Vendor pom groupid org.jline Highest
Vendor pom name JLine Terminal High
Vendor pom parent-artifactid jline-parent Low
Product pom artifactid jline-terminal Highest
Product pom groupid org.jline Highest
Product pom name JLine Terminal High
Product pom parent-artifactid jline-parent Medium
Version pom version 3.26.0 Highest
jline-3.26.0.jar
Description:
JLine
License:
The BSD License: https://opensource.org/licenses/BSD-3-Clause
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar
MD5: 8cbe6b335f4000daa927ec12084790a2
SHA1: 77231a7bae9cfca8da8cd0c4139644f47204ea1e
SHA256: fbccb5d23e31b2b3e278268b1c8e83e54c58bab230ae63c7a7d05d49ac621d1e
Referenced In Project/Scope: server-start:runtimeClasspath
jline-3.26.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jline High
Vendor gradle artifactid jline Highest
Vendor gradle groupid org.jline Highest
Vendor jar package name jline Highest
Vendor Manifest automatic-module-name org.jline Medium
Vendor Manifest build-jdk-spec 22 Low
Vendor Manifest bundle-symbolicname org.jline Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor pom artifactid jline Low
Vendor pom developer email gnodet@gmail.com Low
Vendor pom developer id gnodet Medium
Vendor pom developer name Guillaume Nodet Medium
Vendor pom groupid org.jline Highest
Vendor pom name JLine Bundle High
Vendor pom parent-artifactid jline-parent Low
Vendor pom url jline/jline3/jline Highest
Product file name jline High
Product gradle artifactid jline Highest
Product jar package name jline Highest
Product Manifest automatic-module-name org.jline Medium
Product Manifest build-jdk-spec 22 Low
Product Manifest Bundle-Name JLine Bundle Medium
Product Manifest bundle-symbolicname org.jline Medium
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product pom artifactid jline Highest
Product pom developer email gnodet@gmail.com Low
Product pom developer id gnodet Low
Product pom developer name Guillaume Nodet Low
Product pom groupid org.jline Highest
Product pom name JLine Bundle High
Product pom parent-artifactid jline-parent Medium
Product pom url jline/jline3/jline High
Version file version 3.26.0 High
Version gradle version 3.26.0 Highest
Version Manifest Bundle-Version 3.26.0 High
Version pom version 3.26.0 Highest
jline-3.26.0.jar: jlinenative.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/org/jline/nativ/Windows/x86/jlinenative.dll
MD5: abf6c94ff08105a5b1fa03cc0363d871
SHA1: 7a1f1e28d6341e761e1909c1f374af7fc3a1f26a
SHA256: 01d3a57321cfdb2416064739c586be8838268430de2696f445fb9c434b1dca56
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name jlinenative High
Product file name jlinenative High
jline-3.26.0.jar: jlinenative.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jline/jline/3.26.0/77231a7bae9cfca8da8cd0c4139644f47204ea1e/jline-3.26.0.jar/org/jline/nativ/Windows/x86_64/jlinenative.dll
MD5: c8c7f1eeeb063a2afd7286020f97a106
SHA1: 0aa22a1d147ae2da25ea14ed1a357a4dbf98d42a
SHA256: c5e7fd55ce5cbbdb6265d2f7d429d5abee9ea41ad50cfd63baf0848fa3a6411d
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name jlinenative High
Product file name jlinenative High
jna-5.3.1.jar
Description:
JNA Library
License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.java.dev.jna/jna/5.3.1/6eb9d07456c56b9c2560722e90382252f0f98405/jna-5.3.1.jar
MD5: df3ad04f50fb50840eeb674210200f64
SHA1: 6eb9d07456c56b9c2560722e90382252f0f98405
SHA256: 01cb505c0698d0f7acf3524c7e73acb7dc424a5bae5e9c86ce44075ab32bc4ee
Referenced In Project/Scope: server-start:runtimeClasspath
jna-5.3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jna High
Vendor gradle artifactid jna Highest
Vendor gradle groupid net.java.dev.jna Highest
Vendor jar package name jna Highest
Vendor jar package name jna Low
Vendor jar package name sun Highest
Vendor jar package name sun Low
Vendor jar (hint) package name oracle Highest
Vendor jar (hint) package name oracle Low
Vendor Manifest automatic-module-name com.sun.jna Medium
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname com.sun.jna Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access High
Vendor pom url java-native-access/jna Highest
Product file name jna High
Product gradle artifactid jna Highest
Product jar package name jna Highest
Product jar package name jna Low
Product jar package name library Highest
Product jar package name native Highest
Product jar package name sun Highest
Product jar package name win32 Highest
Product Manifest automatic-module-name com.sun.jna Medium
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna Medium
Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname com.sun.jna Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access High
Product pom url java-native-access/jna High
Version file version 5.3.1 High
Version gradle version 5.3.1 Highest
Version Manifest Bundle-Version 5.3.1 High
Version pom version 5.3.1 Highest
pkg:maven/net.java.dev.jna/jna@5.3.1
(Confidence :High)
cpe:2.3:a:oracle:java_se:5.3.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jna-5.3.1.jar: jnidispatch.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.java.dev.jna/jna/5.3.1/6eb9d07456c56b9c2560722e90382252f0f98405/jna-5.3.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 3c016613eb59259f94e2add2b8d926c0
SHA1: e26183f9919ed1daf5c1856c16f8a074bd9ef6dc
SHA256: df09119557efe5a5fc2237996b09c3da34fb60eb3ff0c6a5b2a35ec4212e0119
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.3.1.jar: jnidispatch.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.java.dev.jna/jna/5.3.1/6eb9d07456c56b9c2560722e90382252f0f98405/jna-5.3.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 391d7cbfc2c03d0be890541004e6a0ac
SHA1: 1a48c577532b6dbec44b5401fa8268a86daa35b0
SHA256: 2d0342e81527fc07255f6585e7de2e89dcd33b2ccf3e770eb83889353265cec3
Referenced In Project/Scope: server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
joda-time-2.10.5.jar
Description:
Date and time library to replace JDK date handling
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/joda-time/joda-time/2.10.5/7f1d89817cd20a32444d5ab4160f035ab9b864e7/joda-time-2.10.5.jar
MD5: a64a54718846cf874324c0967f74e57e
SHA1: 7f1d89817cd20a32444d5ab4160f035ab9b864e7
SHA256: 4ee73e7ff8e2df0d4e3408cf1a1527a59f265dd9fb43fb9b2eb818d87f93759e
Referenced In Project/Scope: server-start:runtimeClasspath
joda-time-2.10.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name joda-time High
Vendor gradle artifactid joda-time Highest
Vendor gradle groupid joda-time Highest
Vendor jar package name joda Highest
Vendor jar package name time Highest
Vendor Manifest automatic-module-name org.joda.time Medium
Vendor Manifest bundle-docurl https://www.joda.org/joda-time/ Low
Vendor Manifest bundle-symbolicname joda-time Medium
Vendor Manifest extension-name joda-time Medium
Vendor Manifest implementation-url https://www.joda.org/joda-time/ Low
Vendor Manifest Implementation-Vendor Joda.org High
Vendor Manifest Implementation-Vendor-Id org.joda Medium
Vendor Manifest specification-vendor Joda.org Low
Vendor pom artifactid joda-time Low
Vendor pom developer id broneill Medium
Vendor pom developer id jodastephen Medium
Vendor pom developer name Brian S O'Neill Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom groupid joda-time Highest
Vendor pom name Joda-Time High
Vendor pom organization name Joda.org High
Vendor pom organization url https://www.joda.org Medium
Vendor pom url https://www.joda.org/joda-time/ Highest
Product file name joda-time High
Product gradle artifactid joda-time Highest
Product jar package name joda Highest
Product jar package name time Highest
Product Manifest automatic-module-name org.joda.time Medium
Product Manifest bundle-docurl https://www.joda.org/joda-time/ Low
Product Manifest Bundle-Name Joda-Time Medium
Product Manifest bundle-symbolicname joda-time Medium
Product Manifest extension-name joda-time Medium
Product Manifest Implementation-Title org.joda.time High
Product Manifest implementation-url https://www.joda.org/joda-time/ Low
Product Manifest specification-title Joda-Time Medium
Product pom artifactid joda-time Highest
Product pom developer id broneill Low
Product pom developer id jodastephen Low
Product pom developer name Brian S O'Neill Low
Product pom developer name Stephen Colebourne Low
Product pom groupid joda-time Highest
Product pom name Joda-Time High
Product pom organization name Joda.org Low
Product pom organization url https://www.joda.org Low
Product pom url https://www.joda.org/joda-time/ Medium
Version file version 2.10.5 High
Version gradle version 2.10.5 Highest
Version Manifest Bundle-Version 2.10.5 High
Version Manifest Implementation-Version 2.10.5 High
Version pom version 2.10.5 Highest
pkg:maven/joda-time/joda-time@2.10.5
(Confidence :High)
joda-time-2.8.jar
Description:
Date and time library to replace JDK date handling
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/joda-time/joda-time/2.8/9f2785d7184b97d005a44241ccaf980f43b9ccdb/joda-time-2.8.jar
MD5: 4c17df2ad20161112283dbe6475e70d2
SHA1: 9f2785d7184b97d005a44241ccaf980f43b9ccdb
SHA256: 55ae8d6baf406ccfec88cc444de4a452c5725859b70a076ba50a7a7b75f68ed1
Referenced In Project/Scope: server-start:compileClasspath
joda-time-2.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name joda-time High
Vendor gradle artifactid joda-time Highest
Vendor gradle groupid joda-time Highest
Vendor jar package name joda Highest
Vendor jar package name time Highest
Vendor Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Vendor Manifest bundle-symbolicname joda-time Medium
Vendor Manifest extension-name joda-time Medium
Vendor Manifest implementation-url http://www.joda.org/joda-time/ Low
Vendor Manifest Implementation-Vendor Joda.org High
Vendor Manifest Implementation-Vendor-Id org.joda Medium
Vendor Manifest specification-vendor Joda.org Low
Vendor pom artifactid joda-time Low
Vendor pom developer id broneill Medium
Vendor pom developer id jodastephen Medium
Vendor pom developer name Brian S O'Neill Medium
Vendor pom developer name Stephen Colebourne Medium
Vendor pom groupid joda-time Highest
Vendor pom name Joda-Time High
Vendor pom organization name Joda.org High
Vendor pom organization url http://www.joda.org Medium
Vendor pom url http://www.joda.org/joda-time/ Highest
Product file name joda-time High
Product gradle artifactid joda-time Highest
Product jar package name joda Highest
Product jar package name time Highest
Product Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Product Manifest Bundle-Name Joda-Time Medium
Product Manifest bundle-symbolicname joda-time Medium
Product Manifest extension-name joda-time Medium
Product Manifest Implementation-Title org.joda.time High
Product Manifest implementation-url http://www.joda.org/joda-time/ Low
Product Manifest specification-title Joda-Time Medium
Product pom artifactid joda-time Highest
Product pom developer id broneill Low
Product pom developer id jodastephen Low
Product pom developer name Brian S O'Neill Low
Product pom developer name Stephen Colebourne Low
Product pom groupid joda-time Highest
Product pom name Joda-Time High
Product pom organization name Joda.org Low
Product pom organization url http://www.joda.org Low
Product pom url http://www.joda.org/joda-time/ Medium
Version file version 2.8 High
Version gradle version 2.8 Highest
Version Manifest Bundle-Version 2.8 High
Version Manifest Implementation-Version 2.8 High
Version pom version 2.8 Highest
pkg:maven/joda-time/joda-time@2.8
(Confidence :High)
joost-0.9.1.jar
Description:
Joost STX processor
License:
Mozilla Public License 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.sf.joost/joost/0.9.1/562b1423b47489e0b3244a36c39bb6d3f33dd991/joost-0.9.1.jar
MD5: e0b14084194b1a4f7e5640c3b9fb25eb
SHA1: 562b1423b47489e0b3244a36c39bb6d3f33dd991
SHA256: 79546ea187b321ecab5e2679e84e021575d40aff6f78250c49e43d0ba7c0e4bc
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
joost-0.9.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name joost High
Vendor gradle artifactid joost Highest
Vendor gradle groupid net.sf.joost Highest
Vendor jar package name joost Low
Vendor jar package name net Low
Vendor jar package name sf Low
Vendor pom artifactid joost Low
Vendor pom developer email obecker@users.sourceforge.net Low
Vendor pom developer id obecker Medium
Vendor pom developer name Oliver Becker Medium
Vendor pom groupid net.sf.joost Highest
Vendor pom name Joost High
Vendor pom url http://joost.sourceforge.net/ Highest
Product file name joost High
Product gradle artifactid joost Highest
Product jar package name joost Low
Product jar package name sf Low
Product pom artifactid joost Highest
Product pom developer email obecker@users.sourceforge.net Low
Product pom developer id obecker Low
Product pom developer name Oliver Becker Low
Product pom groupid net.sf.joost Highest
Product pom name Joost High
Product pom url http://joost.sourceforge.net/ Medium
Version file version 0.9.1 High
Version gradle version 0.9.1 Highest
Version pom version 0.9.1 Highest
pkg:maven/net.sf.joost/joost@0.9.1
(Confidence :High)
jsch-0.1.55.jar
Description:
JSch is a pure Java implementation of SSH2
License:
Revised BSD: http://www.jcraft.com/jsch/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.jcraft/jsch/0.1.55/bbd40e5aa7aa3cfad5db34965456cee738a42a50/jsch-0.1.55.jar
MD5: c395ada0fc012d66f11bd30246f6c84d
SHA1: bbd40e5aa7aa3cfad5db34965456cee738a42a50
SHA256: d492b15a6d2ea3f1cc39c422c953c40c12289073dbe8360d98c0f6f9ec74fc44
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jsch-0.1.55.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jsch High
Vendor gradle artifactid jsch Highest
Vendor gradle groupid com.jcraft Highest
Vendor jar package name jcraft Highest
Vendor jar package name jcraft Low
Vendor jar package name jsch Highest
Vendor jar package name jsch Low
Vendor pom artifactid jsch Low
Vendor pom developer email ymnk at jcraft D0t com Low
Vendor pom developer id ymnk Medium
Vendor pom developer name Atsuhiko Yamanaka Medium
Vendor pom developer org JCraft,Inc. Medium
Vendor pom developer org URL http://www.jcraft.com/ Medium
Vendor pom groupid com.jcraft Highest
Vendor pom name JSch High
Vendor pom organization name JCraft,Inc. High
Vendor pom organization url http://www.jcraft.com/ Medium
Vendor pom url http://www.jcraft.com/jsch/ Highest
Product file name jsch High
Product gradle artifactid jsch Highest
Product jar package name jcraft Highest
Product jar package name jsch Highest
Product jar package name jsch Low
Product pom artifactid jsch Highest
Product pom developer email ymnk at jcraft D0t com Low
Product pom developer id ymnk Low
Product pom developer name Atsuhiko Yamanaka Low
Product pom developer org JCraft,Inc. Low
Product pom developer org URL http://www.jcraft.com/ Low
Product pom groupid com.jcraft Highest
Product pom name JSch High
Product pom organization name JCraft,Inc. Low
Product pom organization url http://www.jcraft.com/ Low
Product pom url http://www.jcraft.com/jsch/ Medium
Version file version 0.1.55 High
Version gradle version 0.1.55 Highest
Version pom version 0.1.55 Highest
json-20250517.jar
Description:
JSON is a light-weight, language independent, data interchange format.
See http://www.JSON.org/
The files in this package implement JSON encoders/decoders in Java.
It also includes the capability to convert between JSON and XML, HTTP
headers, Cookies, and CDL.
This is a reference implementation. There are a large number of JSON packages
in Java. Perhaps someday the Java community will standardize on one. Until
then, choose carefully.
License:
Public Domain: https://github.com/stleary/JSON-java/blob/master/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.json/json/20250517/d67181bbd819ccceb929b580a4e2fcb0c8b17cd8/json-20250517.jar
MD5: 5a4902fae2d0d499487981f616f81567
SHA1: d67181bbd819ccceb929b580a4e2fcb0c8b17cd8
SHA256: 3ea61b2a06e31edf1c91134fe9106b0ebb16628be169f3db75bc7a2b06b45796
Referenced In Project/Scope: server-start:runtimeClasspath
json-20250517.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name json-20250517 High
Vendor gradle artifactid json Highest
Vendor gradle groupid org.json Highest
Vendor jar package name cdl Highest
Vendor jar package name http Highest
Vendor jar package name json Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-symbolicname json Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid json Low
Vendor pom developer email douglas@crockford.com Low
Vendor pom developer name Douglas Crockford Medium
Vendor pom groupid org.json Highest
Vendor pom name JSON in Java High
Vendor pom url douglascrockford/JSON-java Highest
Product file name json-20250517 High
Product gradle artifactid json Highest
Product jar package name cdl Highest
Product jar package name http Highest
Product jar package name json Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Bundle-Name JSON in Java Medium
Product Manifest bundle-symbolicname json Medium
Product Manifest multi-release true Low
Product pom artifactid json Highest
Product pom developer email douglas@crockford.com Low
Product pom developer name Douglas Crockford Low
Product pom groupid org.json Highest
Product pom name JSON in Java High
Product pom url douglascrockford/JSON-java High
Version file version 20250517 Medium
Version gradle version 20250517 Highest
Version pom version 20250517 Highest
pkg:maven/org.json/json@20250517
(Confidence :High)
json-utils-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/json-utils/2.26.30/3ebb143bd65f71e07af0678c1ee8d8a8861a411b/json-utils-2.26.30.jar
MD5: b6bdabe3ea29c2d14ecd00f88d7d9c4b
SHA1: 3ebb143bd65f71e07af0678c1ee8d8a8861a411b
SHA256: 538a0b75da9a35358f21bc9d131f5ed884911f633e34f14fada1b2b199f48178
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
json-utils-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name json-utils High
Vendor gradle artifactid json-utils Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name protocols Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.protocols.jsoncore Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid json-utils Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Core :: Protocols :: Json Utils High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name json-utils High
Product gradle artifactid json-utils Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name protocols Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.protocols.jsoncore Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid json-utils Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Core :: Protocols :: Json Utils High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
jsoup-1.18.1.jar
Description:
jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers.
License:
The MIT License: https://jsoup.org/license
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jsoup/jsoup/1.18.1/cb7cd991d47b44101cbe4655dec611cdc01f8a02/jsoup-1.18.1.jar
MD5: d39a0c88a28969d13707b95e035d9442
SHA1: cb7cd991d47b44101cbe4655dec611cdc01f8a02
SHA256: 3bb5b0ec02998abe45a51f37d7ce67c3068b4ccd4ab63c965929ec5074d64e91
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jsoup-1.18.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jsoup High
Vendor gradle artifactid jsoup Highest
Vendor gradle groupid org.jsoup Highest
Vendor jar package name jsoup Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://jsoup.org/ Low
Vendor Manifest bundle-symbolicname org.jsoup Medium
Vendor Manifest Implementation-Vendor Jonathan Hedley High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor pom artifactid jsoup Low
Vendor pom developer email jonathan@hedley.net Low
Vendor pom developer id jhy Medium
Vendor pom developer name Jonathan Hedley Medium
Vendor pom groupid org.jsoup Highest
Vendor pom name jsoup Java HTML Parser High
Vendor pom organization name Jonathan Hedley High
Vendor pom organization url https://jhy.io/ Medium
Vendor pom url https://jsoup.org/ Highest
Product file name jsoup High
Product gradle artifactid jsoup Highest
Product jar package name 9 Highest
Product jar package name jsoup Highest
Product jar package name org Highest
Product jar package name parser Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://jsoup.org/ Low
Product Manifest Bundle-Name jsoup Java HTML Parser Medium
Product Manifest bundle-symbolicname org.jsoup Medium
Product Manifest Implementation-Title jsoup Java HTML Parser High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product pom artifactid jsoup Highest
Product pom developer email jonathan@hedley.net Low
Product pom developer id jhy Low
Product pom developer name Jonathan Hedley Low
Product pom groupid org.jsoup Highest
Product pom name jsoup Java HTML Parser High
Product pom organization name Jonathan Hedley Low
Product pom organization url https://jhy.io/ Low
Product pom url https://jsoup.org/ Medium
Version file version 1.18.1 High
Version gradle version 1.18.1 Highest
Version Manifest Bundle-Version 1.18.1 High
Version Manifest Implementation-Version 1.18.1 High
Version pom version 1.18.1 Highest
jspecify-1.0.0.jar
Description:
An artifact of well-specified annotations to power static analysis checks and JVM language interop.
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jspecify/jspecify/1.0.0/7425a601c1c7ec76645a78d22b8c6a627edee507/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jspecify High
Vendor gradle artifactid jspecify Highest
Vendor gradle groupid org.jspecify Highest
Vendor jar package name annotations Low
Vendor jar package name jspecify Highest
Vendor jar package name jspecify Low
Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jspecify Low
Vendor pom developer email kevinb9n@gmail.com Low
Vendor pom developer id kevinb9n Medium
Vendor pom developer name Kevin Bourrillion Medium
Vendor pom groupid org.jspecify Highest
Vendor pom name JSpecify annotations High
Vendor pom url http://jspecify.org/ Highest
Product file name jspecify High
Product gradle artifactid jspecify Highest
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name jspecify Highest
Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Product Manifest Bundle-Name JSpecify annotations Medium
Product Manifest bundle-symbolicname org.jspecify.jspecify Medium
Product Manifest multi-release true Low
Product pom artifactid jspecify Highest
Product pom developer email kevinb9n@gmail.com Low
Product pom developer id kevinb9n Low
Product pom developer name Kevin Bourrillion Low
Product pom groupid org.jspecify Highest
Product pom name JSpecify annotations High
Product pom url http://jspecify.org/ Medium
Version file version 1.0.0 High
Version gradle version 1.0.0 Highest
Version Manifest Bundle-Version 1.0.0 High
Version Manifest Implementation-Version 1.0.0 High
Version pom version 1.0.0 Highest
pkg:maven/org.jspecify/jspecify@1.0.0
(Confidence :High)
jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.google.code.findbugs/jsr305/3.0.2/25ea2e8b0c338a877313bd4672d3fe056ea78f0d/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor gradle artifactid jsr305 Highest
Vendor gradle groupid com.google.code.findbugs Highest
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product gradle artifactid jsr305 Highest
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version gradle version 3.0.2 Highest
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/javax.ws.rs/jsr311-api/1.1.1/59033da2a1afd56af1ac576750a8d0b1830d59e6/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
SHA256: ab1534b73b5fa055808e6598a5e73b599ccda28c3159c3c0908977809422ee4a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jsr311-api-1.1.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jsr311-api High
Vendor gradle artifactid jsr311-api Highest
Vendor gradle groupid javax.ws.rs Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name javax Highest
Vendor jar package name rs Highest
Vendor jar package name ws Highest
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor Manifest extension-name javax.ws.rs Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid jsr311-api Low
Vendor pom groupid javax.ws.rs Highest
Vendor pom name jsr311-api High
Vendor pom organization name Sun Microsystems, Inc High
Vendor pom organization url http://www.sun.com/ Medium
Vendor pom url https://jsr311.dev.java.net Highest
Product file name jsr311-api High
Product gradle artifactid jsr311-api Highest
Product hint analyzer product web services Medium
Product jar package name javax Highest
Product jar package name rs Highest
Product jar package name ws Highest
Product Manifest bundle-docurl http://www.sun.com/ Low
Product Manifest Bundle-Name jsr311-api Medium
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Product Manifest extension-name javax.ws.rs Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product pom artifactid jsr311-api Highest
Product pom groupid javax.ws.rs Highest
Product pom name jsr311-api High
Product pom organization name Sun Microsystems, Inc Low
Product pom organization url http://www.sun.com/ Low
Product pom url https://jsr311.dev.java.net Medium
Version file version 1.1.1 High
Version gradle version 1.1.1 Highest
Version Manifest Bundle-Version 1.1.1 High
Version Manifest specification-version 1.1.1 High
Version pom version 1.1.1 Highest
pkg:maven/javax.ws.rs/jsr311-api@1.1.1
(Confidence :High)
jul-to-slf4j-2.0.17.jar
Description:
JUL to SLF4J bridge
License:
https://opensource.org/license/mit
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.slf4j/jul-to-slf4j/2.0.17/524cb6ccc2b68a57604750e1ab8b13b5a786a6aa/jul-to-slf4j-2.0.17.jar
MD5: a42936c56611e4794c42908fb3d3a647
SHA1: 524cb6ccc2b68a57604750e1ab8b13b5a786a6aa
SHA256: a7afcd23b9cfd1475e55c94f943b808c5922035e7e2c2a5c65a487a4106bc538
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
jul-to-slf4j-2.0.17.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/ch.qos.logback/logback-classic@1.5.21
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/org.slf4j/slf4j-api@2.0.17
pkg:maven/org.slf4j/slf4j-api@2.0.17
Evidence
Type Source Name Value Confidence
Vendor file name jul-to-slf4j High
Vendor gradle artifactid jul-to-slf4j Highest
Vendor gradle groupid org.slf4j Highest
Vendor jar package name bridge Highest
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname jul.to.slf4j Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jul-to-slf4j Low
Vendor pom groupid org.slf4j Highest
Vendor pom name JUL to SLF4J bridge High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name jul-to-slf4j High
Product gradle artifactid jul-to-slf4j Highest
Product jar package name bridge Highest
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name JUL to SLF4J bridge Medium
Product Manifest bundle-symbolicname jul.to.slf4j Medium
Product Manifest Implementation-Title jul-to-slf4j High
Product Manifest multi-release true Low
Product pom artifactid jul-to-slf4j Highest
Product pom groupid org.slf4j Highest
Product pom name JUL to SLF4J bridge High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version gradle version 2.0.17 Highest
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/jul-to-slf4j@2.0.17
(Confidence :High)
junit-4.13.2.jar
Description:
JUnit is a unit testing framework for Java, created by Erich Gamma and Kent Beck.
License:
Eclipse Public License 1.0: http://www.eclipse.org/legal/epl-v10.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/junit/junit/4.13.2/8ac9e16d933b6fb43bc7f576336b8f4d7eb5ba12/junit-4.13.2.jar
MD5: d98a9a02a99a9acd22d7653cbcc1f31f
SHA1: 8ac9e16d933b6fb43bc7f576336b8f4d7eb5ba12
SHA256: 8e495b634469d64fb8acfa3495a065cbacc8a0fff55ce1e31007be4c16dc57d3
Referenced In Project/Scope: server-start:runtimeClasspath
junit-4.13.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name junit High
Vendor gradle artifactid junit Highest
Vendor gradle groupid junit Highest
Vendor jar package name junit Highest
Vendor jar package name junit Low
Vendor Manifest automatic-module-name junit Medium
Vendor Manifest implementation-url http://junit.org Low
Vendor Manifest Implementation-Vendor JUnit High
Vendor Manifest Implementation-Vendor-Id junit Medium
Vendor pom artifactid junit Low
Vendor pom developer email david@saff.net Low
Vendor pom developer email kcooney@google.com Low
Vendor pom developer email mail@marcphilipp.de Low
Vendor pom developer email mail@stefan-birkner.de Low
Vendor pom developer id dsaff Medium
Vendor pom developer id kcooney Medium
Vendor pom developer id marcphilipp Medium
Vendor pom developer id stefanbirkner Medium
Vendor pom developer name David Saff Medium
Vendor pom developer name Kevin Cooney Medium
Vendor pom developer name Marc Philipp Medium
Vendor pom developer name Stefan Birkner Medium
Vendor pom groupid junit Highest
Vendor pom name JUnit High
Vendor pom organization name JUnit High
Vendor pom organization url http://www.junit.org Medium
Vendor pom url http://junit.org Highest
Product file name junit High
Product gradle artifactid junit Highest
Product jar package name junit Highest
Product Manifest automatic-module-name junit Medium
Product Manifest Implementation-Title JUnit High
Product Manifest implementation-url http://junit.org Low
Product pom artifactid junit Highest
Product pom developer email david@saff.net Low
Product pom developer email kcooney@google.com Low
Product pom developer email mail@marcphilipp.de Low
Product pom developer email mail@stefan-birkner.de Low
Product pom developer id dsaff Low
Product pom developer id kcooney Low
Product pom developer id marcphilipp Low
Product pom developer id stefanbirkner Low
Product pom developer name David Saff Low
Product pom developer name Kevin Cooney Low
Product pom developer name Marc Philipp Low
Product pom developer name Stefan Birkner Low
Product pom groupid junit Highest
Product pom name JUnit High
Product pom organization name JUnit Low
Product pom organization url http://www.junit.org Low
Product pom url http://junit.org Medium
Version file version 4.13.2 High
Version gradle version 4.13.2 Highest
Version Manifest Implementation-Version 4.13.2 High
Version pom version 4.13.2 Highest
pkg:maven/junit/junit@4.13.2
(Confidence :High)
cpe:2.3:a:junit:junit4:4.13.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
juniversalchardet-1.0.3.jar
Description:
Java port of universalchardet
License:
Mozilla Public License 1.1 (MPL 1.1): http://www.mozilla.org/MPL/MPL-1.1.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.googlecode.juniversalchardet/juniversalchardet/1.0.3/cd49678784c46aa8789c060538e0154013bb421b/juniversalchardet-1.0.3.jar
MD5: d9ea0a9a275336c175b343f2e4cd8f27
SHA1: cd49678784c46aa8789c060538e0154013bb421b
SHA256: 757bfe906193b8b651e79dc26cd67d6b55d0770a2cdfb0381591504f779d4a76
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
juniversalchardet-1.0.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name juniversalchardet High
Vendor gradle artifactid juniversalchardet Highest
Vendor gradle groupid com.googlecode.juniversalchardet Highest
Vendor jar package name mozilla Low
Vendor jar package name prober Low
Vendor jar package name universalchardet Highest
Vendor jar package name universalchardet Low
Vendor pom artifactid juniversalchardet Low
Vendor pom developer email takscape@gmail.com Low
Vendor pom developer id takscape Medium
Vendor pom groupid com.googlecode.juniversalchardet Highest
Vendor pom name juniversalchardet High
Vendor pom url http://juniversalchardet.googlecode.com/ Highest
Product file name juniversalchardet High
Product gradle artifactid juniversalchardet Highest
Product jar package name prober Low
Product jar package name universalchardet Highest
Product jar package name universalchardet Low
Product pom artifactid juniversalchardet Highest
Product pom developer email takscape@gmail.com Low
Product pom developer id takscape Low
Product pom groupid com.googlecode.juniversalchardet Highest
Product pom name juniversalchardet High
Product pom url http://juniversalchardet.googlecode.com/ Medium
Version file version 1.0.3 High
Version gradle version 1.0.3 Highest
Version pom version 1.0.3 Highest
pkg:maven/com.googlecode.juniversalchardet/juniversalchardet@1.0.3
(Confidence :High)
jutf7-1.0.0.jar
Description:
This library provides UTF-7 and Modified UTF-7 Charsets for
Java.
Sun's default Java distribution lacks support for the UTF-7
character set. Though it is not used commonly, it is still
sometimes encountered in e-mails, or applications handling
e-mail.
The package is written as java.nio.charset extension, which
means it can be used without special installation or
configuration. Just drop the jar in your classpath, and you are
ready to go.
License:
MIT license: LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.beetstra.jutf7/jutf7/1.0.0/5308ab88a1049e8d75fe3d6c0a9e7b1305dd0520/jutf7-1.0.0.jar
MD5: 1da83d93039fdaef13aa7a1b9e99cb6c
SHA1: 5308ab88a1049e8d75fe3d6c0a9e7b1305dd0520
SHA256: f8b2ed901526e9dd9bcd15ce0f5d312de0efda7c63fbe918672d080236dc04bc
Referenced In Project/Scope: server-start:runtimeClasspath
jutf7-1.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name jutf7 High
Vendor gradle artifactid jutf7 Highest
Vendor gradle groupid com.beetstra.jutf7 Highest
Vendor jar package name beetstra Highest
Vendor jar package name jutf7 Highest
Vendor Manifest url http://jutf7.sourceforge.net/ Low
Vendor pom artifactid jutf7 Low
Vendor pom developer email jtbeetstra@users.sourceforge.net Low
Vendor pom developer id jtbeetstra Medium
Vendor pom developer name Jaap Beetstra Medium
Vendor pom groupid com.beetstra.jutf7 Highest
Vendor pom name jutf7 High
Vendor pom url http://jutf7.sourceforge.net/ Highest
Product file name jutf7 High
Product gradle artifactid jutf7 Highest
Product jar package name beetstra Highest
Product jar package name jutf7 Highest
Product Manifest url http://jutf7.sourceforge.net/ Low
Product pom artifactid jutf7 Highest
Product pom developer email jtbeetstra@users.sourceforge.net Low
Product pom developer id jtbeetstra Low
Product pom developer name Jaap Beetstra Low
Product pom groupid com.beetstra.jutf7 Highest
Product pom name jutf7 High
Product pom url http://jutf7.sourceforge.net/ Medium
Version file version 1.0.0 High
Version gradle version 1.0.0 Highest
Version pom version 1.0.0 Highest
pkg:maven/com.beetstra.jutf7/jutf7@1.0.0
(Confidence :High)
keycloak-common-26.5.3.jar
Description:
Common library and dependencies shared with server and all adapters
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-common/26.5.3/ff3d6da60ef168aee18abcbcaeab21ca9cbc1799/keycloak-common-26.5.3.jar
MD5: d486873d9fc5eb70034b4e6739e66acd
SHA1: ff3d6da60ef168aee18abcbcaeab21ca9cbc1799
SHA256: 72c4da697c498cb576b7746b60a3ae23561a1713518582f6c82b368212208860
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-common-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-common High
Vendor gradle artifactid keycloak-common Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name common Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-common Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-common Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Common High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-common High
Product gradle artifactid keycloak-common Highest
Product jar package name common Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Common High
Product Manifest implementation-url http://keycloak.org/keycloak-common Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Common Medium
Product pom artifactid keycloak-common Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Common High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
keycloak-core-26.5.3.jar
Description:
Keycloak Core
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-core/26.5.3/7a7dabe1e2a3fbf4859bf8fd919aa334315668e9/keycloak-core-26.5.3.jar
MD5: f4bb445f9fa5e8f5c4a6112d19493209
SHA1: 7a7dabe1e2a3fbf4859bf8fd919aa334315668e9
SHA256: 72ad05ce844fe11c176ac2e844566e28f768a8ce55fcb835c9be3afbc8e565e4
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-core-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-core High
Vendor gradle artifactid keycloak-core Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-core Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-core Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Core High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-core High
Product gradle artifactid keycloak-core Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Core High
Product Manifest implementation-url http://keycloak.org/keycloak-core Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Core Medium
Product pom artifactid keycloak-core Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Core High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
keycloak-crypto-default-26.5.3.jar
Description:
Keycloak Crypto Default
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-crypto-default/26.5.3/edd7861f3951546e9068c1284ac8ef2830901166/keycloak-crypto-default-26.5.3.jar
MD5: 47a43ba58297f069da4aa26a6482a492
SHA1: edd7861f3951546e9068c1284ac8ef2830901166
SHA256: 7a254cc7e6bc9372432a65a3b8a9ca123009edfdd885537ea3a8a85358aaa84a
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-crypto-default-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-crypto-default High
Vendor gradle artifactid keycloak-crypto-default Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name crypto Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-crypto-parent/keycloak-crypto-default Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-crypto-default Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Crypto Default High
Vendor pom parent-artifactid keycloak-crypto-parent Low
Product file name keycloak-crypto-default High
Product gradle artifactid keycloak-crypto-default Highest
Product jar package name crypto Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Crypto Default High
Product Manifest implementation-url http://keycloak.org/keycloak-crypto-parent/keycloak-crypto-default Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Crypto Default Medium
Product pom artifactid keycloak-crypto-default Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Crypto Default High
Product pom parent-artifactid keycloak-crypto-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
keycloak-server-spi-26.5.3.jar
Description:
Keycloak Server SPI
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-server-spi/26.5.3/e841d1eee34b60dab8f329f385a840174b09013b/keycloak-server-spi-26.5.3.jar
MD5: 27754ea3fb3422300119370dc284285d
SHA1: e841d1eee34b60dab8f329f385a840174b09013b
SHA256: ca2af301f35248842537ee163520a9aa78bc413e9a65b66dfb66f23c5a11884a
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-server-spi-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-server-spi High
Vendor gradle artifactid keycloak-server-spi Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name keycloak Highest
Vendor jar package name spi Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-server-spi Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-server-spi Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Server SPI High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-server-spi High
Product gradle artifactid keycloak-server-spi Highest
Product jar package name http Highest
Product jar package name keycloak Highest
Product jar package name spi Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Server SPI High
Product Manifest implementation-url http://keycloak.org/keycloak-server-spi Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Server SPI Medium
Product pom artifactid keycloak-server-spi Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Server SPI High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
keycloak-server-spi-private-26.5.3.jar
Description:
Keycloak Server Private SPI
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-server-spi-private/26.5.3/f0081c668de0c42eeacab7fb48bc8229710673f0/keycloak-server-spi-private-26.5.3.jar
MD5: 94913c938d7c94773297ee44390df85e
SHA1: f0081c668de0c42eeacab7fb48bc8229710673f0
SHA256: af484c28f0a7f1edc8228308a029d90efbcc4ef3e10c3fb4fde01a5e54fd85ee
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-server-spi-private-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-server-spi-private High
Vendor gradle artifactid keycloak-server-spi-private Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-server-spi-private Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-server-spi-private Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Server Private SPI High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-server-spi-private High
Product gradle artifactid keycloak-server-spi-private Highest
Product jar package name http Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Server Private SPI High
Product Manifest implementation-url http://keycloak.org/keycloak-server-spi-private Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Server Private SPI Medium
Product pom artifactid keycloak-server-spi-private Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Server Private SPI High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
kotlin-stdlib-1.9.10.jar
Description:
Kotlin Standard Library for JVM
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains.kotlin/kotlin-stdlib/1.9.10/72812e8a368917ab5c0a5081b56915ffdfec93b7/kotlin-stdlib-1.9.10.jar
MD5: da8348128b101f854fafa9a31e3806bd
SHA1: 72812e8a368917ab5c0a5081b56915ffdfec93b7
SHA256: 55e989c512b80907799f854309f3bc7782c5b3d13932442d0379d5c472711504
Referenced In Project/Scope: server-start:compileClasspath
kotlin-stdlib-1.9.10.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib High
Vendor gradle artifactid kotlin-stdlib Highest
Vendor gradle groupid org.jetbrains.kotlin Highest
Vendor jar package name kotlin Low
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor Manifest multi-release true Low
Vendor pom artifactid kotlin-stdlib Low
Vendor pom developer name Kotlin Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains.kotlin Highest
Vendor pom name Kotlin Stdlib High
Vendor pom url https://kotlinlang.org/ Highest
Product file name kotlin-stdlib High
Product gradle artifactid kotlin-stdlib Highest
Product jar package name kotlin Highest
Product Manifest Implementation-Title kotlin-stdlib High
Product Manifest kotlin-runtime-component Main Low
Product Manifest multi-release true Low
Product pom artifactid kotlin-stdlib Highest
Product pom developer name Kotlin Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains.kotlin Highest
Product pom name Kotlin Stdlib High
Product pom url https://kotlinlang.org/ Medium
Version file version 1.9.10 High
Version gradle version 1.9.10 Highest
Version pom version 1.9.10 Highest
CVE-2020-29582 suppress
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CWE-276 Incorrect Default Permissions
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
kotlin-stdlib-2.1.21.jar
Description:
Kotlin Standard Library
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains.kotlin/kotlin-stdlib/2.1.21/97a0975aa19d925e109537af60eb46902920015c/kotlin-stdlib-2.1.21.jar
MD5: 01269975f32698511a6062a4db034d00
SHA1: 97a0975aa19d925e109537af60eb46902920015c
SHA256: 263bdc679e1f62012db7b091796279b6d71cf36f4797a98ff1ace05835f201c8
Referenced In Project/Scope: server-start:runtimeClasspath
kotlin-stdlib-2.1.21.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib High
Vendor gradle artifactid kotlin-stdlib Highest
Vendor gradle groupid org.jetbrains.kotlin Highest
Vendor jar package name kotlin Low
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor Manifest multi-release true Low
Vendor pom artifactid kotlin-stdlib Low
Vendor pom developer name Kotlin Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains.kotlin Highest
Vendor pom name Kotlin Stdlib High
Vendor pom url https://kotlinlang.org/ Highest
Product file name kotlin-stdlib High
Product gradle artifactid kotlin-stdlib Highest
Product jar package name kotlin Highest
Product Manifest Implementation-Title kotlin-stdlib High
Product Manifest kotlin-runtime-component Main Low
Product Manifest multi-release true Low
Product pom artifactid kotlin-stdlib Highest
Product pom developer name Kotlin Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains.kotlin Highest
Product pom name Kotlin Stdlib High
Product pom url https://kotlinlang.org/ Medium
Version file version 2.1.21 High
Version gradle version 2.1.21 Highest
Version pom version 2.1.21 Highest
kotlin-stdlib-common-1.9.10.jar
Description:
Kotlin Common Standard Library
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains.kotlin/kotlin-stdlib-common/1.9.10/dafaf2c27f27c09220cee312df10917d9a5d97ce/kotlin-stdlib-common-1.9.10.jar
MD5: de4024a53c843e959f2d50ecd1f0e951
SHA1: dafaf2c27f27c09220cee312df10917d9a5d97ce
SHA256: cde3341ba18a2ba262b0b7cf6c55b20c90e8d434e42c9a13e6a3f770db965a88
Referenced In Project/Scope: server-start:compileClasspath
kotlin-stdlib-common-1.9.10.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib-common High
Vendor gradle artifactid kotlin-stdlib-common Highest
Vendor gradle groupid org.jetbrains.kotlin Highest
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor pom artifactid kotlin-stdlib-common Low
Vendor pom developer name Kotlin Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains.kotlin Highest
Vendor pom name Kotlin Stdlib Common High
Vendor pom url https://kotlinlang.org/ Highest
Product file name kotlin-stdlib-common High
Product gradle artifactid kotlin-stdlib-common Highest
Product Manifest Implementation-Title kotlin-stdlib-common High
Product Manifest kotlin-runtime-component Main Low
Product pom artifactid kotlin-stdlib-common Highest
Product pom developer name Kotlin Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains.kotlin Highest
Product pom name Kotlin Stdlib Common High
Product pom url https://kotlinlang.org/ Medium
Version file version 1.9.10 High
Version gradle version 1.9.10 Highest
Version pom version 1.9.10 Highest
CVE-2020-29582 suppress
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CWE-276 Incorrect Default Permissions
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
kotlin-stdlib-jdk7-1.9.10.jar
Description:
Kotlin Standard Library JDK 7 extension
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains.kotlin/kotlin-stdlib-jdk7/1.9.10/bc5bfc2690338defd5195b05c57562f2194eeb10/kotlin-stdlib-jdk7-1.9.10.jar
MD5: 14f35bcc452b095f3034a1471960cccc
SHA1: bc5bfc2690338defd5195b05c57562f2194eeb10
SHA256: ac6361bf9ad1ed382c2103d9712c47cdec166232b4903ed596e8876b0681c9b7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
kotlin-stdlib-jdk7-1.9.10.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib-jdk7 High
Vendor gradle artifactid kotlin-stdlib-jdk7 Highest
Vendor gradle groupid org.jetbrains.kotlin Highest
Vendor jar package name meta-inf Low
Vendor jar package name versions Low
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor Manifest multi-release true Low
Vendor pom artifactid kotlin-stdlib-jdk7 Low
Vendor pom developer name Kotlin Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains.kotlin Highest
Vendor pom name Kotlin Stdlib Jdk7 High
Vendor pom url https://kotlinlang.org/ Highest
Product file name kotlin-stdlib-jdk7 High
Product gradle artifactid kotlin-stdlib-jdk7 Highest
Product jar package name module-info Low
Product jar package name versions Low
Product Manifest Implementation-Title kotlin-stdlib-jdk7 High
Product Manifest kotlin-runtime-component Main Low
Product Manifest multi-release true Low
Product pom artifactid kotlin-stdlib-jdk7 Highest
Product pom developer name Kotlin Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains.kotlin Highest
Product pom name Kotlin Stdlib Jdk7 High
Product pom url https://kotlinlang.org/ Medium
Version file version 1.9.10 High
Version gradle version 1.9.10 Highest
Version pom version 1.9.10 Highest
CVE-2020-29582 suppress
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CWE-276 Incorrect Default Permissions
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
kotlin-stdlib-jdk8-1.9.10.jar
Description:
Kotlin Standard Library JDK 8 extension
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jetbrains.kotlin/kotlin-stdlib-jdk8/1.9.10/c7510d64a83411a649c76f2778304ddf71d7437b/kotlin-stdlib-jdk8-1.9.10.jar
MD5: d223cbd9e57f02cf4e9f3d9ed01edcee
SHA1: c7510d64a83411a649c76f2778304ddf71d7437b
SHA256: a4c74d94d64ce1abe53760fe0389dd941f6fc558d0dab35e47c085a11ec80f28
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
kotlin-stdlib-jdk8-1.9.10.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib-jdk8 High
Vendor gradle artifactid kotlin-stdlib-jdk8 Highest
Vendor gradle groupid org.jetbrains.kotlin Highest
Vendor jar package name meta-inf Low
Vendor jar package name versions Low
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor Manifest multi-release true Low
Vendor pom artifactid kotlin-stdlib-jdk8 Low
Vendor pom developer name Kotlin Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL https://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains.kotlin Highest
Vendor pom name Kotlin Stdlib Jdk8 High
Vendor pom url https://kotlinlang.org/ Highest
Product file name kotlin-stdlib-jdk8 High
Product gradle artifactid kotlin-stdlib-jdk8 Highest
Product jar package name module-info Low
Product jar package name versions Low
Product Manifest Implementation-Title kotlin-stdlib-jdk8 High
Product Manifest kotlin-runtime-component Main Low
Product Manifest multi-release true Low
Product pom artifactid kotlin-stdlib-jdk8 Highest
Product pom developer name Kotlin Team Low
Product pom developer org JetBrains Low
Product pom developer org URL https://www.jetbrains.com Low
Product pom groupid org.jetbrains.kotlin Highest
Product pom name Kotlin Stdlib Jdk8 High
Product pom url https://kotlinlang.org/ Medium
Version file version 1.9.10 High
Version gradle version 1.9.10 Highest
Version pom version 1.9.10 Highest
CVE-2020-29582 suppress
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CWE-276 Incorrect Default Permissions
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
logback-classic-1.5.21.jar
Description:
logback-classic module
License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/ch.qos.logback/logback-classic/1.5.21/904915aa29a0bbff111ae90ed85541b2991a72fc/logback-classic-1.5.21.jar
MD5: e4aa08ccbae42f0a94ef6d706d0d5cf8
SHA1: 904915aa29a0bbff111ae90ed85541b2991a72fc
SHA256: b2523f7b0dabf4386c81312f0371d267e3a9fbce409046f16b042bf68571ba4a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
logback-classic-1.5.21.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name logback-classic High
Vendor gradle artifactid logback-classic Highest
Vendor gradle groupid ch.qos.logback Highest
Vendor jar package name ch Highest
Vendor jar package name classic Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.classic Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest provide-capability osgi.service;objectClass:List="jakarta.servlet.ServletContainerInitializer";effective:=active,osgi.service;objectClass:List="org.slf4j.spi.SLF4JServiceProvider";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.servlet.ServletContainerInitializer";register:="ch.qos.logback.classic.servlet.LogbackServletContainerInitializer",osgi.serviceloader;osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider";register:="ch.qos.logback.classic.spi.LogbackServiceProvider" Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-classic Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Classic Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-classic High
Product gradle artifactid logback-classic Highest
Product jar package name ch Highest
Product jar package name classic Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Classic Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.classic Medium
Product Manifest Implementation-Title Logback Classic Module High
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest provide-capability osgi.service;objectClass:List="jakarta.servlet.ServletContainerInitializer";effective:=active,osgi.service;objectClass:List="org.slf4j.spi.SLF4JServiceProvider";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.servlet.ServletContainerInitializer";register:="ch.qos.logback.classic.servlet.LogbackServletContainerInitializer",osgi.serviceloader;osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider";register:="ch.qos.logback.classic.spi.LogbackServiceProvider" Low
Product Manifest specification-title Logback Classic Module Medium
Product pom artifactid logback-classic Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Classic Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.5.21 High
Version gradle version 1.5.21 Highest
Version Manifest Bundle-Version 1.5.21 High
Version Manifest Implementation-Version 1.5.21 High
Version pom version 1.5.21 Highest
logback-core-1.5.21.jar
Description:
logback-core module
License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.5.21/970bf47cbc34d24e47f375b6b4e407d6d699474f/logback-core-1.5.21.jar
MD5: 00c20552b89470eff9f01f21c77d44d7
SHA1: 970bf47cbc34d24e47f375b6b4e407d6d699474f
SHA256: 0825ac1fc5296369121e5423e397c52d125b0e3fae743cfc0d8e416159f14f44
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
logback-core-1.5.21.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/ch.qos.logback/logback-classic@1.5.21
Evidence
Type Source Name Value Confidence
Vendor file name logback-core High
Vendor gradle artifactid logback-core Highest
Vendor gradle groupid ch.qos.logback Highest
Vendor jar package name ch Highest
Vendor jar package name core Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-core Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Core Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-core High
Product gradle artifactid logback-core Highest
Product jar package name 21 Highest
Product jar package name ch Highest
Product jar package name core Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Core Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest Implementation-Title Logback Core Module High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Logback Core Module Medium
Product pom artifactid logback-core Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Core Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.5.21 High
Version gradle version 1.5.21 Highest
Version Manifest Bundle-Version 1.5.21 High
Version Manifest Implementation-Version 1.5.21 High
Version pom version 1.5.21 Highest
lombok-1.18.30.jar
Description:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!
License:
The MIT License: https://projectlombok.org/LICENSE
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.projectlombok/lombok/1.18.30/f195ee86e6c896ea47a1d39defbe20eb59cd149d/lombok-1.18.30.jar
MD5: 14e90bb14cac804c1a6e2024e78f436d
SHA1: f195ee86e6c896ea47a1d39defbe20eb59cd149d
SHA256: 14151b47582d570b4de16a147ece3bdbd19ace4aee5bde3a5578c87db9ecb998
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:lombok
server-start:annotationProcessor
lombok-1.18.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name lombok High
Vendor gradle artifactid lombok Highest
Vendor gradle groupid org.projectlombok Highest
Vendor jar package name lombok Highest
Vendor jar package name lombok Low
Vendor Manifest automatic-module-name lombok Medium
Vendor Manifest can-redefine-classes true Low
Vendor pom artifactid lombok Low
Vendor pom developer email reinier@projectlombok.org Low
Vendor pom developer email roel@projectlombok.org Low
Vendor pom developer id rspilker Medium
Vendor pom developer id rzwitserloot Medium
Vendor pom developer name Reinier Zwitserloot Medium
Vendor pom developer name Roel Spilker Medium
Vendor pom groupid org.projectlombok Highest
Vendor pom name Project Lombok High
Vendor pom url https://projectlombok.org Highest
Product file name lombok High
Product gradle artifactid lombok Highest
Product jar package name lombok Highest
Product Manifest automatic-module-name lombok Medium
Product Manifest can-redefine-classes true Low
Product pom artifactid lombok Highest
Product pom developer email reinier@projectlombok.org Low
Product pom developer email roel@projectlombok.org Low
Product pom developer id rspilker Low
Product pom developer id rzwitserloot Low
Product pom developer name Reinier Zwitserloot Low
Product pom developer name Roel Spilker Low
Product pom groupid org.projectlombok Highest
Product pom name Project Lombok High
Product pom url https://projectlombok.org Medium
Version file version 1.18.30 High
Version gradle version 1.18.30 Highest
Version Manifest lombok-version 1.18.30 Medium
Version pom version 1.18.30 Highest
pkg:maven/org.projectlombok/lombok@1.18.30
(Confidence :High)
lombok-1.18.30.jar: mavenEcjBootstrapAgent.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.projectlombok/lombok/1.18.30/f195ee86e6c896ea47a1d39defbe20eb59cd149d/lombok-1.18.30.jar/lombok/launch/mavenEcjBootstrapAgent.jar
MD5: 2bc7812d729aa7f761f721c6f0620848
SHA1: e67209a53266080be85e8848c01fd15af98700c7
SHA256: 63da6c6457ba6bfb61867cf644542464783adc57bbf36a7f0843c2822c288169
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:lombok
server-start:annotationProcessor
Evidence
Type Source Name Value Confidence
Vendor file name mavenEcjBootstrapAgent High
Vendor jar package name launch Low
Vendor jar package name lombok Low
Vendor Manifest can-redefine-classes true Low
Product file name mavenEcjBootstrapAgent High
Product jar package name launch Low
Product Manifest can-redefine-classes true Low
lucene-core-9.12.0.jar
Description:
Apache Lucene (module: core)
License:
Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.lucene/lucene-core/9.12.0/fdb055d569bb20bfce9618fe2b01c29bab7f290c/lucene-core-9.12.0.jar
MD5: dd2ac67819c84831a53ec739d4889852
SHA1: fdb055d569bb20bfce9618fe2b01c29bab7f290c
SHA256: 6c7b774b75cd8f369e246f365a47caa54ae991cae6afa49c7f339e9921ca58a0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
lucene-core-9.12.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name lucene-core High
Vendor gradle artifactid lucene-core Highest
Vendor gradle groupid org.apache.lucene Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name lucene Highest
Vendor jar package name lucene Low
Vendor jar package name org Highest
Vendor Manifest extension-name org.apache.lucene Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest x-build-os Mac OS X x86_64 11.4 Low
Vendor pom artifactid lucene-core Low
Vendor pom groupid org.apache.lucene Highest
Vendor pom name Apache Lucene (module: core) High
Vendor pom url https://lucene.apache.org/ Highest
Product file name lucene-core High
Product gradle artifactid lucene-core Highest
Product jar package name apache Highest
Product jar package name lucene Highest
Product jar package name lucene Low
Product jar package name org Highest
Product jar package name search Highest
Product Manifest extension-name org.apache.lucene Medium
Product Manifest Implementation-Title org.apache.lucene High
Product Manifest multi-release true Low
Product Manifest specification-title Lucene Search Engine: core Medium
Product Manifest x-build-os Mac OS X x86_64 11.4 Low
Product pom artifactid lucene-core Highest
Product pom groupid org.apache.lucene Highest
Product pom name Apache Lucene (module: core) High
Product pom url https://lucene.apache.org/ Medium
Version file version 9.12.0 High
Version gradle version 9.12.0 Highest
Version pom version 9.12.0 Highest
pkg:maven/org.apache.lucene/lucene-core@9.12.0
(Confidence :High)
lz4-java-1.10.1.jar
Description:
Java bindings and pure Java implementations of LZ4 and XXHash
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/at.yawk.lz4/lz4-java/1.10.1/f541d7f910fe3d76f38f799c507c48cc81b12ecb/lz4-java-1.10.1.jar
MD5: 8ea4d77e6a652da0162a69b6aea6e4a9
SHA1: f541d7f910fe3d76f38f799c507c48cc81b12ecb
SHA256: a58a84c4271e50df4c96ed916ccb7e48a869f8ed9cdcda1ad5d3d4c33b0214a3
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
lz4-java-1.10.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name lz4-java High
Vendor gradle artifactid lz4-java Highest
Vendor gradle groupid at.yawk.lz4 Highest
Vendor jar package name lz4 Highest
Vendor jar package name xxhash Highest
Vendor Manifest automatic-module-name org.lz4.java Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-symbolicname lz4-java Medium
Vendor Manifest originally-created-by Maven JAR Plugin 3.4.1 Low
Vendor pom artifactid lz4-java Low
Vendor pom developer email jpountz@gmail.com Low
Vendor pom developer email me@yawk.at Low
Vendor pom developer email Rei.Odaira@gmail.com Low
Vendor pom developer id jpountz Medium
Vendor pom developer id odaira Medium
Vendor pom developer id yawkat Medium
Vendor pom developer name Adrien Grand Medium
Vendor pom developer name Jonas Konrad Medium
Vendor pom developer name Rei Odaira Medium
Vendor pom groupid at.yawk.lz4 Highest
Vendor pom name LZ4 Java Compression High
Vendor pom url yawkat/lz4-java Highest
Product file name lz4-java High
Product gradle artifactid lz4-java Highest
Product jar package name lz4 Highest
Product jar package name xxhash Highest
Product Manifest automatic-module-name org.lz4.java Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest Bundle-Name lz4-java Medium
Product Manifest bundle-symbolicname lz4-java Medium
Product Manifest originally-created-by Maven JAR Plugin 3.4.1 Low
Product pom artifactid lz4-java Highest
Product pom developer email jpountz@gmail.com Low
Product pom developer email me@yawk.at Low
Product pom developer email Rei.Odaira@gmail.com Low
Product pom developer id jpountz Low
Product pom developer id odaira Low
Product pom developer id yawkat Low
Product pom developer name Adrien Grand Low
Product pom developer name Jonas Konrad Low
Product pom developer name Rei Odaira Low
Product pom groupid at.yawk.lz4 Highest
Product pom name LZ4 Java Compression High
Product pom url yawkat/lz4-java High
Version file version 1.10.1 High
Version gradle version 1.10.1 Highest
Version pom version 1.10.1 Highest
pkg:maven/at.yawk.lz4/lz4-java@1.10.1
(Confidence :High)
mapstruct-1.5.1.Final.jar
Description:
An annotation processor for generating type-safe bean mappers
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.mapstruct/mapstruct/1.5.1.Final/7594423c07ce57b7e649e926c455208854f68322/mapstruct-1.5.1.Final.jar
MD5: f4083f543bdaac749e91073ddf05085b
SHA1: 7594423c07ce57b7e649e926c455208854f68322
SHA256: c86abfd678a76d3b070d6399bc4fe76a1a44ccbbba1512476ba8f8ee890eac12
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
mapstruct-1.5.1.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mapstruct High
Vendor gradle artifactid mapstruct Highest
Vendor gradle groupid org.mapstruct Highest
Vendor jar package name mapstruct Highest
Vendor Manifest automatic-module-name org.mapstruct Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.mapstruct Medium
Vendor pom artifactid mapstruct Low
Vendor pom developer email gunnar@mapstruct.org Low
Vendor pom developer id filiphr Medium
Vendor pom developer id gunnarmorling Medium
Vendor pom developer name Filip Hrisafov Medium
Vendor pom developer name Gunnar Morling Medium
Vendor pom groupid org.mapstruct Highest
Vendor pom name MapStruct Core High
Vendor pom parent-artifactid mapstruct-parent Low
Vendor pom url http://mapstruct.org/mapstruct/ Highest
Product file name mapstruct High
Product gradle artifactid mapstruct Highest
Product jar package name mappers Highest
Product jar package name mapstruct Highest
Product Manifest automatic-module-name org.mapstruct Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name MapStruct Core Medium
Product Manifest bundle-symbolicname org.mapstruct Medium
Product pom artifactid mapstruct Highest
Product pom developer email gunnar@mapstruct.org Low
Product pom developer id filiphr Low
Product pom developer id gunnarmorling Low
Product pom developer name Filip Hrisafov Low
Product pom developer name Gunnar Morling Low
Product pom groupid org.mapstruct Highest
Product pom name MapStruct Core High
Product pom parent-artifactid mapstruct-parent Medium
Product pom url http://mapstruct.org/mapstruct/ Medium
Version gradle version 1.5.1.Final Highest
Version Manifest Bundle-Version 1.5.1.Final High
Version pom version 1.5.1.Final Highest
pkg:maven/org.mapstruct/mapstruct@1.5.1.Final
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT-classes.jar
Description:
Web application: mcp-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/a0fbaf94268ce25f9e4ac7a3f63a71ad60cb58e1/mcp-connector-0.0.1-main-SNAPSHOT-classes.jar
MD5: 29986d1d7e78f8fc17798b441767f375
SHA1: a0fbaf94268ce25f9e4ac7a3f63a71ad60cb58e1
SHA256: 44e364da31560489deb925da79e8debc6a5e0d623a6357be4b648af6126609d3
Referenced In Project/Scope: server-start:compileClasspath
mcp-connector-0.0.1-main-SNAPSHOT-classes.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mcp-connector High
Vendor gradle artifactid mcp-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Vendor pom artifactid mcp-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name mcp-connector High
Product gradle artifactid mcp-connector Highest
Product jar package name connector Low
Product jar package name mcp Low
Product jar package name transconnect Low
Product pom artifactid mcp-connector Highest
Product pom groupid io.transconnect.connector Highest
Version gradle version 0.0.1-main-SNAPSHOT Highest
Version pom version 0.0.1-main-SNAPSHOT Highest
pkg:maven/io.transconnect.connector/mcp-connector@0.0.1-main-SNAPSHOT
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war
Description:
Web application: mcp-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war
MD5: 09199b3d9ebe570592d8ac253eca9986
SHA1: 98f97fac1c708d6e1457b329a2aede959a140f6c
SHA256: 584dede15188e2073bcb6b7852574d7a2e8fadb3f88d284bb5995efd9d88d832
Referenced In Project/Scope: server-start:webapps
mcp-connector-0.0.1-main-SNAPSHOT.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mcp-connector High
Vendor gradle artifactid mcp-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid mcp-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name mcp-connector High
Product gradle artifactid mcp-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid mcp-connector Highest
Product pom groupid io.transconnect.connector Highest
Version gradle version 0.0.1-main-SNAPSHOT Highest
Version pom version 0.0.1-main-SNAPSHOT Highest
pkg:maven/io.transconnect.connector/mcp-connector@0.0.1-main-SNAPSHOT
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mcp-connector-0.0.1-main-SNAPSHOT.war: angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: asm-9.4.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/asm-9.4.jar
MD5: ffa64f03a23a4823d98703e6ce6ff397
SHA1: b4e0e2d2e023aa317b7cfcfc916377ea348e07d1
SHA256: 39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.4 High
Version Manifest Implementation-Version 9.4 High
mcp-connector-0.0.1-main-SNAPSHOT.war: checker-qual-3.43.0.jar
License:
MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/checker-qual-3.43.0.jar
MD5: 4f56e65c8f302ca8b4cb384c9b4a53b6
SHA1: 9425eee39e56b116d2b998b7c2cebcbd11a3c98b
SHA256: 3fbc2e98f05854c3df16df9abaa955b91b15b3ecac33623208ed6424640ef0f6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Version file version 3.43.0 High
Version Manifest Implementation-Version 3.43.0 High
mcp-connector-0.0.1-main-SNAPSHOT.war: error_prone_annotations-2.36.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/error_prone_annotations-2.36.0.jar
MD5: 0e48e5ba2cd0a8d8d09bad849b99f6a6
SHA1: 227d4d4957ccc3dc5761bd897e3a0ee587e750a7
SHA256: 77440e270b0bc9a249903c5a076c36a722c4886ca4f42675f2903a1c53ed61a5
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.36.0 High
Version Manifest Bundle-Version 2.36.0 High
Version pom version 2.36.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.36.0
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: failureaccess-1.0.2.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes are conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/failureaccess-1.0.2.jar
MD5: 3f75955b49b6758fd6d1e1bd9bf777b3
SHA1: c4a06a64e650562f30b7bf9aaec1bfed43aca12b
SHA256: 8a8f81cf9b359e3f6dfa691a1e776985c061ef2f223c9b2c80753e1b458e8064
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest automatic-module-name com.google.common.util.concurrent.internal Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest automatic-module-name com.google.common.util.concurrent.internal Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.2 High
Version Manifest Bundle-Version 1.0.2 High
Version pom parent-version 1.0.2 Low
Version pom version 1.0.2 Highest
pkg:maven/com.google.guava/failureaccess@1.0.2
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: guava-33.4.0-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/guava-33.4.0-jre.jar
MD5: 5732af16367192820c7bf177e9b29512
SHA1: 03fcc0a259f724c7de54a6a55ea7e26d3d5c0cac
SHA256: b918c98a7e44dbe94ebd9fe3e40cddaadb5a93e6a78eb6008b42df237241e538
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version pom version 33.4.0-jre Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: j2objc-annotations-3.0.0.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/j2objc-annotations-3.0.0.jar
MD5: f59529b29202a5baf37f491ea5ec8627
SHA1: 7399e65dd7e9ff3404f4535b2f017093bdb134c7
SHA256: 88241573467ddca44ffd4d74aa04c2bbfd11bf7c17e0c342c94c9de7a70a7c64
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor jar package name annotations Highest
Vendor jar package name google Highest
Vendor jar package name j2objc Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest multi-release true Low
Vendor pom artifactid j2objc-annotations Low
Vendor pom developer email tball@google.com Low
Vendor pom developer id tomball Medium
Vendor pom developer name Tom Ball Medium
Vendor pom developer org Google Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product jar package name annotations Highest
Product jar package name google Highest
Product jar package name j2objc Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest multi-release true Low
Product pom artifactid j2objc-annotations Highest
Product pom developer email tball@google.com Low
Product pom developer id tomball Low
Product pom developer name Tom Ball Low
Product pom developer org Google Low
Product pom developer org URL https://www.google.com Low
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 3.0.0 High
Version pom version 3.0.0 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@3.0.0
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: jackson-core-2.17.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jackson-core-2.17.1.jar
MD5: 9363584821290882417f1c3ceab784df
SHA1: 5e52a11644cd59a28ef79f02bddc2cc3bab45edb
SHA256: ddb26c8a1f1a84535e8213c48b35b253370434e3287b3cf15777856fc4e58ce6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
Related Dependencies
mcp-connector-0.0.1-main-SNAPSHOT.war: jackson-annotations-2.17.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jackson-annotations-2.17.1.jar
MD5: dbeffa5994a6234489a205fd7f33d9b9
SHA1: fca7ef6192c9ad05d07bc50da991bf937a84af3a
SHA256: fccad82e13172c0e4384db71577219c9b8631c0820f4b18daaa57016fb661c76
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.17.1
mcp-connector-0.0.1-main-SNAPSHOT.war: jackson-databind-2.17.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jackson-databind-2.17.1.jar
MD5: f0a1c37dc7d937f14e183d84f15c0f83
SHA1: 0524dcbcccdde7d45a679dfc333e4763feb09079
SHA256: b6ca2f7d5b1ab245cec5495ec339773d2d90554c48592590673fb18f4400a948
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: jackson-dataformat-yaml-2.17.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jackson-dataformat-yaml-2.17.1.jar
MD5: 3257d599754342666ba50b7eaed555b5
SHA1: b4c7b8a9ea3f398116a75c146b982b22afebc4ee
SHA256: 83f38459593bc10caeb1fa2653616813b1743b6bed67163c8ae8e5a4d32a5456
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: jackson-datatype-jsr310-2.17.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jackson-datatype-jsr310-2.17.1.jar
MD5: 9761d8656aeac7db968998100b91f36e
SHA1: 0969b0c3cb8c75d759e9a6c585c44c9b9f3a4f75
SHA256: 56765d55ac8cffdd757c1a534ec965e70b01176f64dfd7e70b0db34d8babc9fa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.17.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.17.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mcp-connector-0.0.1-main-SNAPSHOT.war: jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: jaxb-0.0.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jaxb-0.0.5.jar
MD5: 58907d82c17158efcb4ecc982038d5a6
SHA1: 3d2fed9de0741048183fb73afd0b279d139e6218
SHA256: 2f37b52321ae8220c03afdb98fe65c35ed0ce5eda890500808c67e829f1320c9
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name jaxb High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name jaxb Medium
Version file version 0.0.5 High
mcp-connector-0.0.1-main-SNAPSHOT.war: jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
Description:
An empty artifact that Guava depends on to signal that it is providing
ListenableFuture -- but is also available in a second "version" that
contains com.google.common.util.concurrent.ListenableFuture class, without
any other Guava classes. The idea is:
- If users want only ListenableFuture, they depend on listenablefuture-1.0.
- If users want all of Guava, they depend on guava, which, as of Guava
27.0, depends on
listenablefuture-9999.0-empty-to-avoid-conflict-with-guava. The 9999.0-...
version number is enough for some build systems (notably, Gradle) to select
that empty artifact over the "real" listenablefuture-1.0 -- avoiding a
conflict with the copy of ListenableFuture in guava itself. If users are
using an older version of Guava or a build system other than Gradle, they
may see class conflicts. If so, they can solve them by manually excluding
the listenablefuture artifact or manually forcing their build systems to
use 9999.0-....
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
MD5: d094c22570d65e132c19cea5d352e381
SHA1: b421526c5f297295adef1c886e5246c39d4ac629
SHA256: b372a037d4230aa57fbeffdef30fd6123f9c0c2db85d0aced00c91b974f33f99
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name listenablefuture High
Vendor pom artifactid listenablefuture Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava ListenableFuture only High
Vendor pom parent-artifactid guava-parent Low
Product file name listenablefuture High
Product pom artifactid listenablefuture Highest
Product pom groupid com.google.guava Highest
Product pom name Guava ListenableFuture only High
Product pom parent-artifactid guava-parent Medium
Version pom parent-version 9999.0-empty-to-avoid-conflict-with-guava Low
Version pom version 9999.0-empty-to-avoid-conflict-with-guava Highest
pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: mcp-0.10.0.jar
Description:
Java SDK implementation of the Model Context Protocol, enabling seamless integration with language models and AI tools
License:
MIT License: http://www.opensource.org/licenses/mit-license.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/mcp-0.10.0.jar
MD5: 543fd3020c41b17c10b94ea1f5d5d1ee
SHA1: 45c4f3282b18b8abbe1f20d07f79a894096a044c
SHA256: ee5b24c04a9432ef9495342f80f6dcaceb6fc2a907f535677be0331ea896ca6b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name mcp High
Vendor jar package name io Highest
Vendor jar package name modelcontextprotocol Highest
Vendor Manifest automatic-module-name io.modelcontextprotocol.sdk.mcp Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/modelcontextprotocol/java-sdk Low
Vendor Manifest bundle-symbolicname io.modelcontextprotocol.sdk.mcp Medium
Vendor pom artifactid mcp Low
Vendor pom developer name Christian Tzolov Medium
Vendor pom developer name Dariusz Jędrzejczyk Medium
Vendor pom groupid io.modelcontextprotocol.sdk Highest
Vendor pom name Java MCP SDK High
Vendor pom organization name Anthropic High
Vendor pom organization url https://www.anthropic.com Medium
Vendor pom url modelcontextprotocol/java-sdk Highest
Product file name mcp High
Product jar package name io Highest
Product jar package name modelcontextprotocol Highest
Product Manifest automatic-module-name io.modelcontextprotocol.sdk.mcp Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/modelcontextprotocol/java-sdk Low
Product Manifest Bundle-Name Bundle io.modelcontextprotocol.sdk : mcp Medium
Product Manifest bundle-symbolicname io.modelcontextprotocol.sdk.mcp Medium
Product Manifest Implementation-Title mcp High
Product pom artifactid mcp Highest
Product pom developer name Christian Tzolov Low
Product pom developer name Dariusz Jędrzejczyk Low
Product pom groupid io.modelcontextprotocol.sdk Highest
Product pom name Java MCP SDK High
Product pom organization name Anthropic Low
Product pom organization url https://www.anthropic.com Low
Product pom url modelcontextprotocol/java-sdk High
Version file version 0.10.0 High
Version Manifest Bundle-Version 0.10.0 High
Version Manifest Implementation-Version 0.10.0 High
Version pom version 0.10.0 Highest
pkg:maven/io.modelcontextprotocol.sdk/mcp@0.10.0
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: org.eclipse.persistence.core-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/org.eclipse.persistence.core-5.0.0-B10.jar
MD5: 0220aebe0d5d2e3e17212b4f170bc861
SHA1: 7ab1bff81e53437b06882cac903427164e047cc8
SHA256: be3b97f65e605c29b539db0c7adb134ec61413943368432705c4731965b1370a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.core High
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Vendor Manifest extension-name org.eclipse.persistence.core Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Vendor pom artifactid eclipse.persistence.core Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink Core High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.core High
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink Core Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Product Manifest extension-name org.eclipse.persistence.core Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Product pom artifactid eclipse.persistence.core Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink Core High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.core@5.0.0-B10
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: org.eclipse.persistence.moxy-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/org.eclipse.persistence.moxy-5.0.0-B10.jar
MD5: 550ec8c0a31fbc5b6d0cd63f75b7d897
SHA1: aede7488445daebad7fb1f7202593e0800e858db
SHA256: 6d040ff629d81d54a7d5f18e73370288126062db7325a87e13fc97bbe65f935a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.moxy High
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Vendor Manifest extension-name org.eclipse.persistence.moxy Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Vendor pom artifactid eclipse.persistence.moxy Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink MOXy High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.moxy High
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink MOXy Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Product Manifest extension-name org.eclipse.persistence.moxy Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Product pom artifactid eclipse.persistence.moxy Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink MOXy High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.moxy@5.0.0-B10
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: reactive-streams-1.0.4.jar
Description:
Reactive Streams API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/reactive-streams-1.0.4.jar
MD5: eda7978509c32d99166745cc144c99cd
SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7
SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactive-streams High
Vendor jar package name reactivestreams Highest
Vendor jar package name reactivestreams Low
Vendor Manifest automatic-module-name org.reactivestreams Medium
Vendor Manifest bundle-docurl http://reactive-streams.org Low
Vendor Manifest bundle-symbolicname reactive-streams Medium
Product file name reactive-streams High
Product jar package name reactivestreams Highest
Product Manifest automatic-module-name org.reactivestreams Medium
Product Manifest bundle-docurl http://reactive-streams.org Low
Product Manifest Bundle-Name reactive-streams-jvm Medium
Product Manifest bundle-symbolicname reactive-streams Medium
Version file name reactive-streams Medium
Version file version 1.0.4 High
Version Manifest Bundle-Version 1.0.4 High
mcp-connector-0.0.1-main-SNAPSHOT.war: reactor-core-3.7.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/reactor-core-3.7.0.jar
MD5: 6b7237c420323c50ed4bd509ab415782
SHA1: e98fd1c48144d43f48141b9ebd6723da3b88fb77
SHA256: 14aebad4882def1f88389656cf9b46177f6b090bb00a0707025d76aeacaaead2
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-core High
Vendor jar package name core Highest
Vendor jar package name core Low
Vendor jar package name publisher Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.core Medium
Vendor Manifest bundle-symbolicname io.projectreactor.reactor-core Medium
Vendor Manifest multi-release true Low
Product file name reactor-core High
Product jar package name core Highest
Product jar package name core Low
Product jar package name publisher Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.core Medium
Product Manifest Bundle-Name reactor-core Medium
Product Manifest bundle-symbolicname io.projectreactor.reactor-core Medium
Product Manifest Implementation-Title reactor-core High
Product Manifest multi-release true Low
Version file version 3.7.0 High
Version Manifest Implementation-Version 3.7.0 High
mcp-connector-0.0.1-main-SNAPSHOT.war: slf4j-api-2.0.16.jar
Description:
The slf4j API
License:
http://www.opensource.org/licenses/mit-license.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/slf4j-api-2.0.16.jar
MD5: c8de8f5d740584cb24b5652cfba8b3c4
SHA1: 0172931663a09a1fa515567af5fbef00897d3c04
SHA256: a12578dde1ba00bd9b816d388a0b879928d00bab3c83c240f7013bf4196c579a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.16 High
Version Manifest Bundle-Version 2.0.16 High
Version Manifest Implementation-Version 2.0.16 High
Version pom version 2.0.16 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.16
(Confidence :High)
mcp-connector-0.0.1-main-SNAPSHOT.war: snakeyaml-2.2.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/snakeyaml-2.2.jar
MD5: d78aacf5f2de5b52f1a327470efd1ad7
SHA1: 3af797a25458550a16bf89acc8e4ab2b7f2bfce0
SHA256: 1467931448a0817696ae2805b7b8b20bfb082652bf9c4efaed528930dc49389b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.2 High
Version pom version 2.2 Highest
mcp-connector-0.0.1-main-SNAPSHOT.war: war-connector-bridge-0.0.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/war-connector-bridge-0.0.5.jar
MD5: 87af672a44a655ee4b184be92b3cb4de
SHA1: 862d673e8b0dc2bd428dc4b9855e5d3ca077999f
SHA256: 66d0ab2b5c89624f0b132b0c29840a278266e5d1d23ef53afd1f42b03f25dee6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 0.0.5 High
mcp-connector-0.0.1-main-SNAPSHOT.war: yaml-descriptor-0.0.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/mcp-connector/0.0.1-main-SNAPSHOT/98f97fac1c708d6e1457b329a2aede959a140f6c/mcp-connector-0.0.1-main-SNAPSHOT.war/WEB-INF/lib/yaml-descriptor-0.0.5.jar
MD5: 8661638d96d1e7edce981bdf36601b25
SHA1: 76e8825e9a6ad6ed2368131c9b3f5bb32335862b
SHA256: db42cc5672f9df750f38c149c74a2ce1af4c321c048cfbdcc812e855d4394a20
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 0.0.5 High
metrics-core-4.2.26.jar
Description:
Metrics is a Java library which gives you unparalleled insight into what your code does in
production. Metrics provides a powerful toolkit of ways to measure the behavior of critical
components in your production environment.
License:
https://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.dropwizard.metrics/metrics-core/4.2.26/9cd762999669e726f694a3ac8f9d8a1400cdb332/metrics-core-4.2.26.jar
MD5: 5828504e260983cb9b266e3f117665fa
SHA1: 9cd762999669e726f694a3ac8f9d8a1400cdb332
SHA256: 9691fe898dd4fa5a4667b694e2e9f9ca6837c1e906f57627423121cf2552616e
Referenced In Project/Scope: server-start:webapps
metrics-core-4.2.26.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name metrics-core High
Vendor gradle artifactid metrics-core Highest
Vendor gradle groupid io.dropwizard.metrics Highest
Vendor jar package name codahale Highest
Vendor jar package name metrics Highest
Vendor Manifest automatic-module-name com.codahale.metrics Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-symbolicname io.dropwizard.metrics.core Medium
Vendor pom artifactid metrics-core Low
Vendor pom groupid io.dropwizard.metrics Highest
Vendor pom name Metrics Core High
Vendor pom parent-artifactid metrics-parent Low
Product file name metrics-core High
Product gradle artifactid metrics-core Highest
Product jar package name codahale Highest
Product jar package name metrics Highest
Product Manifest automatic-module-name com.codahale.metrics Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Bundle-Name Metrics Core Medium
Product Manifest bundle-symbolicname io.dropwizard.metrics.core Medium
Product Manifest Implementation-Title Metrics Core High
Product pom artifactid metrics-core Highest
Product pom groupid io.dropwizard.metrics Highest
Product pom name Metrics Core High
Product pom parent-artifactid metrics-parent Medium
Version file version 4.2.26 High
Version gradle version 4.2.26 Highest
Version Manifest Bundle-Version 4.2.26 High
Version Manifest Implementation-Version 4.2.26 High
Version pom version 4.2.26 Highest
pkg:maven/io.dropwizard.metrics/metrics-core@4.2.26
(Confidence :High)
metrics-json-4.2.26.jar
Description:
A set of Jackson modules which provide serializers for most Metrics classes.
License:
https://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.dropwizard.metrics/metrics-json/4.2.26/1eac3853bb964647b38d7e1d7b66e515443437d6/metrics-json-4.2.26.jar
MD5: b8bec5525792f024f6fc2530033f5703
SHA1: 1eac3853bb964647b38d7e1d7b66e515443437d6
SHA256: d4d7a60e081d26bf11643f49a345d2171754d2b2e77e58ce387f8d1932e57810
Referenced In Project/Scope: server-start:webapps
metrics-json-4.2.26.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name metrics-json High
Vendor gradle artifactid metrics-json Highest
Vendor gradle groupid io.dropwizard.metrics Highest
Vendor jar package name codahale Highest
Vendor jar package name json Highest
Vendor jar package name metrics Highest
Vendor Manifest automatic-module-name com.codahale.metrics.json Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-symbolicname io.dropwizard.metrics.json Medium
Vendor pom artifactid metrics-json Low
Vendor pom groupid io.dropwizard.metrics Highest
Vendor pom name Jackson Integration for Metrics High
Vendor pom parent-artifactid metrics-parent Low
Product file name metrics-json High
Product gradle artifactid metrics-json Highest
Product jar package name codahale Highest
Product jar package name json Highest
Product jar package name metrics Highest
Product Manifest automatic-module-name com.codahale.metrics.json Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Bundle-Name Jackson Integration for Metrics Medium
Product Manifest bundle-symbolicname io.dropwizard.metrics.json Medium
Product Manifest Implementation-Title Jackson Integration for Metrics High
Product pom artifactid metrics-json Highest
Product pom groupid io.dropwizard.metrics Highest
Product pom name Jackson Integration for Metrics High
Product pom parent-artifactid metrics-parent Medium
Version file version 4.2.26 High
Version gradle version 4.2.26 Highest
Version Manifest Bundle-Version 4.2.26 High
Version Manifest Implementation-Version 4.2.26 High
Version pom version 4.2.26 Highest
pkg:maven/io.dropwizard.metrics/metrics-json@4.2.26
(Confidence :High)
metrics-spi-2.26.30.jar
Description:
This is the base module for SDK metrics feature. It contains the interfaces used for metrics feature
that are used by other modules in the library.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/metrics-spi/2.26.30/ca05bd0dba086987020169f3a966d34120a983a9/metrics-spi-2.26.30.jar
MD5: 2873a76b4fea5ee11a010398e0ce55f7
SHA1: ca05bd0dba086987020169f3a966d34120a983a9
SHA256: 89f7de05b699d0034da182aa51928878a5444161ff8805c71774e8c6156c92d9
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
metrics-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name metrics-spi High
Vendor gradle artifactid metrics-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name metrics Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.metrics Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid metrics-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Metrics SPI High
Vendor pom parent-artifactid core Low
Product file name metrics-spi High
Product gradle artifactid metrics-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name metrics Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.metrics Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid metrics-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Metrics SPI High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
microprofile-openapi-api-4.0.2.jar
Description:
MicroProfile OpenAPI :: API
License:
Apache License, Version 2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.microprofile.openapi/microprofile-openapi-api/4.0.2/1df7fa8ebe14e6c22891213ffe55424de375d188/microprofile-openapi-api-4.0.2.jar
MD5: 06238e51072fcea0b02e9a47b8f3f956
SHA1: 1df7fa8ebe14e6c22891213ffe55424de375d188
SHA256: c6fca9913d7ecbdeb801d5e6c935988219f64a0eb8b17e23437ea0e01e7a10a9
Referenced In Project/Scope: server-start:runtimeClasspath
microprofile-openapi-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name microprofile-openapi-api High
Vendor gradle artifactid microprofile-openapi-api Highest
Vendor gradle groupid org.eclipse.microprofile.openapi Highest
Vendor jar package name eclipse Highest
Vendor jar package name microprofile Highest
Vendor jar package name openapi Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low
Vendor Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium
Vendor pom artifactid microprofile-openapi-api Low
Vendor pom groupid org.eclipse.microprofile.openapi Highest
Vendor pom name MicroProfile OpenAPI API High
Vendor pom parent-artifactid microprofile-openapi-parent Low
Product file name microprofile-openapi-api High
Product gradle artifactid microprofile-openapi-api Highest
Product jar package name eclipse Highest
Product jar package name microprofile Highest
Product jar package name openapi Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low
Product Manifest Bundle-Name MicroProfile OpenAPI Bundle Medium
Product Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium
Product pom artifactid microprofile-openapi-api Highest
Product pom groupid org.eclipse.microprofile.openapi Highest
Product pom name MicroProfile OpenAPI API High
Product pom parent-artifactid microprofile-openapi-parent Medium
Version file version 4.0.2 High
Version gradle version 4.0.2 Highest
Version Manifest Bundle-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/org.eclipse.microprofile.openapi/microprofile-openapi-api@4.0.2
(Confidence :High)
migbase64-2.2.jar
Description:
MiGBase64 is a very fast and small Base64 Codec written in Java
License:
Prior BSD License: http://en.wikipedia.org/wiki/BSD_licenses
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.brsanthu/migbase64/2.2/bcc14967d516e93c527897a6c531ba76b5751faa/migbase64-2.2.jar
MD5: da3ef3a9a9fa358ed789b37a3c780727
SHA1: bcc14967d516e93c527897a6c531ba76b5751faa
SHA256: 07224584b6227efbb815e96e3153945786e2a6b1a934620b6130331c2351c129
Referenced In Project/Scope: server-start:webapps
migbase64-2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name migbase64 High
Vendor gradle artifactid migbase64 Highest
Vendor gradle groupid com.brsanthu Highest
Vendor jar package name base64 Highest
Vendor jar package name migbase64 Highest
Vendor Manifest bundle-docurl http://sourceforge.net/projects/migbase64/ Low
Vendor Manifest bundle-symbolicname com.brsanthu.migbase64 Medium
Vendor Manifest Implementation-Vendor Mikael Grev High
Vendor Manifest Implementation-Vendor-Id com.brsanthu Medium
Vendor Manifest specification-vendor Mikael Grev Low
Vendor pom artifactid migbase64 Low
Vendor pom developer email http://sourceforge.net/u/mgrev/profile/ Low
Vendor pom developer name Mikael Grev Medium
Vendor pom developer org URL http://sourceforge.net/u/mgrev/profile/ Medium
Vendor pom groupid com.brsanthu Highest
Vendor pom name MiG Base64 High
Vendor pom organization name Mikael Grev High
Vendor pom organization url http://sourceforge.net/projects/migbase64/ Medium
Vendor pom url http://sourceforge.net/projects/migbase64/ Highest
Product file name migbase64 High
Product gradle artifactid migbase64 Highest
Product jar package name base64 Highest
Product jar package name migbase64 Highest
Product Manifest bundle-docurl http://sourceforge.net/projects/migbase64/ Low
Product Manifest Bundle-Name MiG Base64 Medium
Product Manifest bundle-symbolicname com.brsanthu.migbase64 Medium
Product Manifest Implementation-Title MiG Base64 High
Product Manifest specification-title MiG Base64 Medium
Product pom artifactid migbase64 Highest
Product pom developer email http://sourceforge.net/u/mgrev/profile/ Low
Product pom developer name Mikael Grev Low
Product pom developer org URL http://sourceforge.net/u/mgrev/profile/ Low
Product pom groupid com.brsanthu Highest
Product pom name MiG Base64 High
Product pom organization name Mikael Grev Low
Product pom organization url http://sourceforge.net/projects/migbase64/ Low
Product pom url http://sourceforge.net/projects/migbase64/ Medium
Version file version 2.2 High
Version gradle version 2.2 Highest
Version Manifest Implementation-Version 2.2 High
Version pom version 2.2 Highest
pkg:maven/com.brsanthu/migbase64@2.2
(Confidence :High)
mimepull-1.9.15.jar
Description:
Provides a streaming API to access attachments parts in a MIME message.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jvnet.mimepull/mimepull/1.9.15/60f9a7991ad9ec1a280db8deea216a91c10aae74/mimepull-1.9.15.jar
MD5: fdc35a1eae84c5a60c95d617551d4a06
SHA1: 60f9a7991ad9ec1a280db8deea216a91c10aae74
SHA256: b9f586bf8844b14a33e75fe7a4b94896dc80d80b732d128777e287af14c836fa
Referenced In Project/Scope: server-start:webapps
mimepull-1.9.15.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mimepull High
Vendor gradle artifactid mimepull Highest
Vendor gradle groupid org.jvnet.mimepull Highest
Vendor jar package name jvnet Highest
Vendor jar package name mimepull Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.jvnet.mimepull Medium
Vendor Manifest implementation-build-id 1.9.15 - 4d4312c Low
Vendor pom artifactid mimepull Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom groupid org.jvnet.mimepull Highest
Vendor pom name MIME streaming extension High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url eclipse-ee4j/metro-mimepull Highest
Product file name mimepull High
Product gradle artifactid mimepull Highest
Product jar package name jvnet Highest
Product jar package name mimepull Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name MIME streaming extension Medium
Product Manifest bundle-symbolicname org.jvnet.mimepull Medium
Product Manifest implementation-build-id 1.9.15 - 4d4312c Low
Product pom artifactid mimepull Highest
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer name Roman Grigoriadi Low
Product pom groupid org.jvnet.mimepull Highest
Product pom name MIME streaming extension High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url eclipse-ee4j/metro-mimepull High
Version file version 1.9.15 High
Version gradle version 1.9.15 Highest
Version Manifest Bundle-Version 1.9.15 High
Version Manifest implementation-build-id 1.9.15 Low
Version pom parent-version 1.9.15 Low
Version pom version 1.9.15 Highest
pkg:maven/org.jvnet.mimepull/mimepull@1.9.15
(Confidence :High)
cpe:2.3:a:4d:4d:1.9.15:*:*:*:*:*:*:*
(Confidence :Low)
suppress
mongodb-driver-core-5.6.4.jar
Description:
Shared components for the Synchronous and Reactive Streams implementations of the MongoDB Java Driver.
License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.mongodb/mongodb-driver-core/5.6.4/47c5265d901367c8a6ff52fecf9008402c42e6fe/mongodb-driver-core-5.6.4.jar
MD5: a65701beb53986d76326cc77fe210501
SHA1: 47c5265d901367c8a6ff52fecf9008402c42e6fe
SHA256: 7fc8f0b2bd7a2d090c67505ae171aa02edd7c316052a97bd5baca512a090de71
Referenced In Project/Scope: server-start:runtimeClasspath
mongodb-driver-core-5.6.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mongodb-driver-core High
Vendor gradle artifactid mongodb-driver-core Highest
Vendor gradle groupid org.mongodb Highest
Vendor jar package name internal Low
Vendor jar package name mongodb Highest
Vendor jar package name mongodb Low
Vendor Manifest automatic-module-name org.mongodb.driver.core Medium
Vendor Manifest bundle-symbolicname org.mongodb.driver-core Medium
Vendor pom artifactid mongodb-driver-core Low
Vendor pom developer name Various Medium
Vendor pom developer org MongoDB Medium
Vendor pom groupid org.mongodb Highest
Vendor pom name MongoDB Java Driver Core High
Vendor pom url https://www.mongodb.com/ Highest
Product file name mongodb-driver-core High
Product gradle artifactid mongodb-driver-core Highest
Product jar package name internal Low
Product jar package name mongodb Highest
Product Manifest automatic-module-name org.mongodb.driver.core Medium
Product Manifest Bundle-Name mongodb-driver-core Medium
Product Manifest bundle-symbolicname org.mongodb.driver-core Medium
Product pom artifactid mongodb-driver-core Highest
Product pom developer name Various Low
Product pom developer org MongoDB Low
Product pom groupid org.mongodb Highest
Product pom name MongoDB Java Driver Core High
Product pom url https://www.mongodb.com/ Medium
Version file version 5.6.4 High
Version gradle version 5.6.4 Highest
Version Manifest build-version 5.6.4 Medium
Version Manifest Bundle-Version 5.6.4 High
Version pom version 5.6.4 Highest
mongodb-driver-sync-5.6.4.jar
Description:
The MongoDB Synchronous Driver
License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.mongodb/mongodb-driver-sync/5.6.4/5d120bb2629edc77984875f6bfa3a4fe0489782e/mongodb-driver-sync-5.6.4.jar
MD5: 24f87203b8df09303de66457816e8d05
SHA1: 5d120bb2629edc77984875f6bfa3a4fe0489782e
SHA256: cffbfb0efe9813a42bcf88e24aa0ce3c184ce36a318fbd847dc9691e79cd911a
Referenced In Project/Scope: server-start:runtimeClasspath
mongodb-driver-sync-5.6.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name mongodb-driver-sync High
Vendor gradle artifactid mongodb-driver-sync Highest
Vendor gradle groupid org.mongodb Highest
Vendor jar package name client Highest
Vendor jar package name client Low
Vendor jar package name internal Low
Vendor jar package name mongodb Highest
Vendor jar package name mongodb Low
Vendor Manifest automatic-module-name org.mongodb.driver.sync.client Medium
Vendor Manifest bundle-symbolicname org.mongodb.driver-sync Medium
Vendor pom artifactid mongodb-driver-sync Low
Vendor pom developer name Various Medium
Vendor pom developer org MongoDB Medium
Vendor pom groupid org.mongodb Highest
Vendor pom name MongoDB Driver High
Vendor pom url https://www.mongodb.com/ Highest
Product file name mongodb-driver-sync High
Product gradle artifactid mongodb-driver-sync Highest
Product jar package name client Highest
Product jar package name client Low
Product jar package name internal Low
Product jar package name mongodb Highest
Product Manifest automatic-module-name org.mongodb.driver.sync.client Medium
Product Manifest Bundle-Name mongodb-driver-sync Medium
Product Manifest bundle-symbolicname org.mongodb.driver-sync Medium
Product pom artifactid mongodb-driver-sync Highest
Product pom developer name Various Low
Product pom developer org MongoDB Low
Product pom groupid org.mongodb Highest
Product pom name MongoDB Driver High
Product pom url https://www.mongodb.com/ Medium
Version file version 5.6.4 High
Version gradle version 5.6.4 Highest
Version Manifest build-version 5.6.4 Medium
Version Manifest Bundle-Version 5.6.4 High
Version pom version 5.6.4 Highest
pkg:maven/org.mongodb/mongodb-driver-sync@5.6.4
(Confidence :High)
neethi-3.2.0.jar
Description:
Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.neethi/neethi/3.2.0/4e409cf251f420f65130d458256f7be1ad68f055/neethi-3.2.0.jar
MD5: e6040db3584bfdbadd0515dbdba6b25a
SHA1: 4e409cf251f420f65130d458256f7be1ad68f055
SHA256: 6ed3c2cd20444972936c1f9b623862d1415592290ce1eb79e1cf1008f999aa3b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
neethi-3.2.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name neethi High
Vendor gradle artifactid neethi Highest
Vendor gradle groupid org.apache.neethi Highest
Vendor jar package name apache Highest
Vendor jar package name neethi Highest
Vendor jar package name policy Highest
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.neethi Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid neethi Low
Vendor pom developer email chatra@gmail.com Low
Vendor pom developer email dims@yahoo.com Low
Vendor pom developer email dkulp@apache.org Low
Vendor pom developer email sanjiva@opensource.lk Low
Vendor pom developer email sanka@apache.org Low
Vendor pom developer email veithen@apache.org Low
Vendor pom developer email werner.dittmann@siemens.com Low
Vendor pom developer id chatra Medium
Vendor pom developer id dims Medium
Vendor pom developer id dkulp Medium
Vendor pom developer id sanjiva Medium
Vendor pom developer id sanka Medium
Vendor pom developer id veithen Medium
Vendor pom developer id werner Medium
Vendor pom developer name Andreas Veithen Medium
Vendor pom developer name Chatra Nakkawita Medium
Vendor pom developer name Daniel Kulp Medium
Vendor pom developer name Davanum Srinivas Medium
Vendor pom developer name Dittmann, Werner Medium
Vendor pom developer name Sanjiva Weerawarana Medium
Vendor pom developer name Sanka Samaranayake Medium
Vendor pom developer org IBM Medium
Vendor pom developer org WSO2 Inc. Medium
Vendor pom groupid org.apache.neethi Highest
Vendor pom name Apache Neethi High
Vendor pom organization name The Apache Software Foundation High
Vendor pom organization url https://www.apache.org/ Medium
Vendor pom parent-artifactid apache Low
Vendor pom parent-groupid org.apache Medium
Vendor pom url https://ws.apache.org/neethi/ Highest
Product file name neethi High
Product gradle artifactid neethi Highest
Product jar package name apache Highest
Product jar package name neethi Highest
Product jar package name policy Highest
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache Neethi Medium
Product Manifest bundle-symbolicname org.apache.neethi Medium
Product Manifest Implementation-Title Apache Neethi High
Product Manifest specification-title Apache Neethi Medium
Product pom artifactid neethi Highest
Product pom developer email chatra@gmail.com Low
Product pom developer email dims@yahoo.com Low
Product pom developer email dkulp@apache.org Low
Product pom developer email sanjiva@opensource.lk Low
Product pom developer email sanka@apache.org Low
Product pom developer email veithen@apache.org Low
Product pom developer email werner.dittmann@siemens.com Low
Product pom developer id chatra Low
Product pom developer id dims Low
Product pom developer id dkulp Low
Product pom developer id sanjiva Low
Product pom developer id sanka Low
Product pom developer id veithen Low
Product pom developer id werner Low
Product pom developer name Andreas Veithen Low
Product pom developer name Chatra Nakkawita Low
Product pom developer name Daniel Kulp Low
Product pom developer name Davanum Srinivas Low
Product pom developer name Dittmann, Werner Low
Product pom developer name Sanjiva Weerawarana Low
Product pom developer name Sanka Samaranayake Low
Product pom developer org IBM Low
Product pom developer org WSO2 Inc. Low
Product pom groupid org.apache.neethi Highest
Product pom name Apache Neethi High
Product pom organization name The Apache Software Foundation Low
Product pom organization url https://www.apache.org/ Low
Product pom parent-artifactid apache Medium
Product pom parent-groupid org.apache Medium
Product pom url https://ws.apache.org/neethi/ Medium
Version file version 3.2.0 High
Version gradle version 3.2.0 Highest
Version Manifest Bundle-Version 3.2.0 High
Version Manifest Implementation-Version 3.2.0 High
Version pom parent-version 3.2.0 Low
Version pom version 3.2.0 Highest
CVE-2026-42402 suppress
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42403 suppress
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42404 suppress
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: HIGH (7.2)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
neethi-3.2.1.jar
Description:
Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities.
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.neethi/neethi/3.2.1/2d239fd19646201c6dfcc01f3d805b9158d92c94/neethi-3.2.1.jar
MD5: 6d100128ec1e1417687c4fc65cf925f1
SHA1: 2d239fd19646201c6dfcc01f3d805b9158d92c94
SHA256: 9aafe21e37e11bebd3bd5b55aa5e97da79eabdd2af19faf0992cf7887d8db5f0
Referenced In Project/Scope: server-start:webapps
neethi-3.2.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name neethi High
Vendor gradle artifactid neethi Highest
Vendor gradle groupid org.apache.neethi Highest
Vendor jar package name apache Highest
Vendor jar package name neethi Highest
Vendor jar package name policy Highest
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.neethi Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid neethi Low
Vendor pom developer email chatra@gmail.com Low
Vendor pom developer email dims@yahoo.com Low
Vendor pom developer email dkulp@apache.org Low
Vendor pom developer email sanjiva@opensource.lk Low
Vendor pom developer email sanka@apache.org Low
Vendor pom developer email veithen@apache.org Low
Vendor pom developer email werner.dittmann@siemens.com Low
Vendor pom developer id chatra Medium
Vendor pom developer id dims Medium
Vendor pom developer id dkulp Medium
Vendor pom developer id sanjiva Medium
Vendor pom developer id sanka Medium
Vendor pom developer id veithen Medium
Vendor pom developer id werner Medium
Vendor pom developer name Andreas Veithen Medium
Vendor pom developer name Chatra Nakkawita Medium
Vendor pom developer name Daniel Kulp Medium
Vendor pom developer name Davanum Srinivas Medium
Vendor pom developer name Dittmann, Werner Medium
Vendor pom developer name Sanjiva Weerawarana Medium
Vendor pom developer name Sanka Samaranayake Medium
Vendor pom developer org IBM Medium
Vendor pom developer org WSO2 Inc. Medium
Vendor pom groupid org.apache.neethi Highest
Vendor pom name Apache Neethi High
Vendor pom organization name The Apache Software Foundation High
Vendor pom organization url https://www.apache.org/ Medium
Vendor pom parent-artifactid apache Low
Vendor pom parent-groupid org.apache Medium
Vendor pom url https://ws.apache.org/neethi/ Highest
Product file name neethi High
Product gradle artifactid neethi Highest
Product jar package name apache Highest
Product jar package name neethi Highest
Product jar package name policy Highest
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache Neethi Medium
Product Manifest bundle-symbolicname org.apache.neethi Medium
Product Manifest Implementation-Title Apache Neethi High
Product Manifest specification-title Apache Neethi Medium
Product pom artifactid neethi Highest
Product pom developer email chatra@gmail.com Low
Product pom developer email dims@yahoo.com Low
Product pom developer email dkulp@apache.org Low
Product pom developer email sanjiva@opensource.lk Low
Product pom developer email sanka@apache.org Low
Product pom developer email veithen@apache.org Low
Product pom developer email werner.dittmann@siemens.com Low
Product pom developer id chatra Low
Product pom developer id dims Low
Product pom developer id dkulp Low
Product pom developer id sanjiva Low
Product pom developer id sanka Low
Product pom developer id veithen Low
Product pom developer id werner Low
Product pom developer name Andreas Veithen Low
Product pom developer name Chatra Nakkawita Low
Product pom developer name Daniel Kulp Low
Product pom developer name Davanum Srinivas Low
Product pom developer name Dittmann, Werner Low
Product pom developer name Sanjiva Weerawarana Low
Product pom developer name Sanka Samaranayake Low
Product pom developer org IBM Low
Product pom developer org WSO2 Inc. Low
Product pom groupid org.apache.neethi Highest
Product pom name Apache Neethi High
Product pom organization name The Apache Software Foundation Low
Product pom organization url https://www.apache.org/ Low
Product pom parent-artifactid apache Medium
Product pom parent-groupid org.apache Medium
Product pom url https://ws.apache.org/neethi/ Medium
Version file version 3.2.1 High
Version gradle version 3.2.1 Highest
Version Manifest Bundle-Version 3.2.1 High
Version Manifest Implementation-Version 3.2.1 High
Version pom parent-version 3.2.1 Low
Version pom version 3.2.1 Highest
CVE-2026-42402 suppress
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42403 suppress
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42404 suppress
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: HIGH (7.2)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
netty-buffer-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-buffer/4.1.126.Final/6141cd8f9b7def2d29b2ae6b433a751d6f20120e/netty-buffer-4.1.126.Final.jar
MD5: 80f12bc73a4906611c7b202d93626ca7
SHA1: 6141cd8f9b7def2d29b2ae6b433a751d6f20120e
SHA256: d741726adcc76107553092d456d0da5837daad39919c8a40df15327d7fa3296d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-buffer-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-buffer High
Vendor gradle artifactid netty-buffer Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name buffer Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.buffer Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.buffer Medium
Vendor Manifest implementation-url https://netty.io/netty-buffer/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-buffer Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Buffer High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-buffer High
Product gradle artifactid netty-buffer Highest
Product jar package name buffer Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.buffer Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Buffer Medium
Product Manifest bundle-symbolicname io.netty.buffer Medium
Product Manifest Implementation-Title Netty/Buffer High
Product Manifest implementation-url https://netty.io/netty-buffer/ Low
Product Manifest specification-title Netty/Buffer Medium
Product pom artifactid netty-buffer Highest
Product pom groupid io.netty Highest
Product pom name Netty/Buffer High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-buffer@4.1.126.Final
(Confidence :High)
netty-codec-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec/4.1.126.Final/b265a097073120638ef468eda9e5a1e04a2e09e9/netty-codec-4.1.126.Final.jar
MD5: 971941ee869ae1b09410a48142244d12
SHA1: b265a097073120638ef468eda9e5a1e04a2e09e9
SHA256: 8ebb8284cc76b26025d892ff8bc1a90cc4ae7492dae0e3794068cd8ebc452600
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-codec-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec High
Vendor gradle artifactid netty-codec Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec Medium
Vendor Manifest implementation-url https://netty.io/netty-codec/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec High
Product gradle artifactid netty-codec Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec Medium
Product Manifest bundle-symbolicname io.netty.codec Medium
Product Manifest Implementation-Title Netty/Codec High
Product Manifest implementation-url https://netty.io/netty-codec/ Low
Product Manifest specification-title Netty/Codec Medium
Product pom artifactid netty-codec Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-codec@4.1.126.Final
(Confidence :High)
netty-codec-http-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.126.Final/e8a7293c3f4891e7f6b0ede23bc808559dff0abd/netty-codec-http-4.1.126.Final.jar
MD5: 45cd0a79615257f803dc42e5a28d29f8
SHA1: e8a7293c3f4891e7f6b0ede23bc808559dff0abd
SHA256: 0a32369bbd7278f1066048fc0830f2a6df1f0f72de6ae7f5386976c4d2f6788f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-codec-http-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http High
Vendor gradle artifactid netty-codec-http Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http High
Product gradle artifactid netty-codec-http Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP Medium
Product Manifest bundle-symbolicname io.netty.codec-http Medium
Product Manifest Implementation-Title Netty/Codec/HTTP High
Product Manifest implementation-url https://netty.io/netty-codec-http/ Low
Product Manifest specification-title Netty/Codec/HTTP Medium
Product pom artifactid netty-codec-http Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-codec-http@4.1.126.Final
(Confidence :High)
netty-codec-http2-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-http2/4.1.126.Final/652d70562d88d4de20071e3e2f4963e02e68c74/netty-codec-http2-4.1.126.Final.jar
MD5: 952f1e0a27f4b9383f30274bd55eec8e
SHA1: 0652d70562d88d4de20071e3e2f4963e02e68c74
SHA256: bb5eb960f552d9b90a98c8bc40e40b89316294c1dd1e67b2728ad047f2da3bbe
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-codec-http2-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http2 High
Vendor gradle artifactid netty-codec-http2 Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http2 Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http2 Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP2 High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http2 High
Product gradle artifactid netty-codec-http2 Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP2 Medium
Product Manifest bundle-symbolicname io.netty.codec-http2 Medium
Product Manifest Implementation-Title Netty/Codec/HTTP2 High
Product Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Product Manifest specification-title Netty/Codec/HTTP2 Medium
Product pom artifactid netty-codec-http2 Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP2 High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-codec-http2@4.1.126.Final
(Confidence :High)
netty-codec-socks-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-socks/4.1.126.Final/6b3eca94ad8b00917c52187a8c48e48657a4ad1e/netty-codec-socks-4.1.126.Final.jar
MD5: 1a28b97638dbd9d0fc80c147cc3c3876
SHA1: 6b3eca94ad8b00917c52187a8c48e48657a4ad1e
SHA256: 1f1d56665f4793dbbadab34c604597a680f60425de0027434f9499c183da9df5
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-codec-socks-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-socks High
Vendor gradle artifactid netty-codec-socks Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.socks Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-socks Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-socks Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/Socks High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-socks High
Product gradle artifactid netty-codec-socks Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.socks Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/Socks Medium
Product Manifest bundle-symbolicname io.netty.codec-socks Medium
Product Manifest Implementation-Title Netty/Codec/Socks High
Product Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Product Manifest specification-title Netty/Codec/Socks Medium
Product pom artifactid netty-codec-socks Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/Socks High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-codec-socks@4.1.126.Final
(Confidence :High)
netty-common-4.1.126.Final.jar (shaded: org.jctools:jctools-core:4.0.5)
Description:
Java Concurrency Tools Core Library
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-common/4.1.126.Final/e600bd7cef9b2b151606529166534b99220ea149/netty-common-4.1.126.Final.jar/META-INF/maven/org.jctools/jctools-core/pom.xml
MD5: 5d5135397b920a7dcbca5c1fb0576cf2
SHA1: eaa05d6ad937464312a2681a3236c0e06602bbb7
SHA256: a69897b8ff0c2198b4b8cd7d4f93fde6d42b8e9dbfc95553585e27587b24e211
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jctools-core Low
Vendor pom groupid org.jctools Highest
Vendor pom name Java Concurrency Tools Core Library High
Vendor pom url JCTools Highest
Product pom artifactid jctools-core Highest
Product pom groupid org.jctools Highest
Product pom name Java Concurrency Tools Core Library High
Product pom url JCTools High
Version pom version 4.0.5 Highest
pkg:maven/org.jctools/jctools-core@4.0.5
(Confidence :High)
netty-common-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-common/4.1.126.Final/e600bd7cef9b2b151606529166534b99220ea149/netty-common-4.1.126.Final.jar
MD5: 227bc8a7f0f4e99159e4c63eadbb637a
SHA1: e600bd7cef9b2b151606529166534b99220ea149
SHA256: ac2b777562723a94962ea30a30d968fa5678455141ede64100b9d0530426db9c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-common-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-common High
Vendor gradle artifactid netty-common Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.common Medium
Vendor Manifest implementation-url https://netty.io/netty-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-common High
Product gradle artifactid netty-common Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Common Medium
Product Manifest bundle-symbolicname io.netty.common Medium
Product Manifest Implementation-Title Netty/Common High
Product Manifest implementation-url https://netty.io/netty-common/ Low
Product Manifest specification-title Netty/Common Medium
Product pom artifactid netty-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Common High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-common@4.1.126.Final
(Confidence :High)
netty-handler-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-handler/4.1.126.Final/9bd071585b16a9aa28caec956fd77a4375ff3193/netty-handler-4.1.126.Final.jar
MD5: 61dccb38a3443847dcf9785067b67233
SHA1: 9bd071585b16a9aa28caec956fd77a4375ff3193
SHA256: 1846e8e770288aab3a203a16f78e2515ddba0bf9df1c26665ceffc38c9fc875b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-handler-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler High
Vendor gradle artifactid netty-handler Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.handler Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler Medium
Vendor Manifest implementation-url https://netty.io/netty-handler/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler High
Product gradle artifactid netty-handler Highest
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.handler Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler Medium
Product Manifest bundle-symbolicname io.netty.handler Medium
Product Manifest Implementation-Title Netty/Handler High
Product Manifest implementation-url https://netty.io/netty-handler/ Low
Product Manifest specification-title Netty/Handler Medium
Product pom artifactid netty-handler Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-handler@4.1.126.Final
(Confidence :High)
netty-handler-proxy-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-handler-proxy/4.1.126.Final/567fbccddd46ce3793e1475bbaffc2038315bc35/netty-handler-proxy-4.1.126.Final.jar
MD5: f76c5d740a87169c8d93309f990f8d2f
SHA1: 567fbccddd46ce3793e1475bbaffc2038315bc35
SHA256: 7b715cbad91daf9cde48105e1ab5cc45e06b3b19523f536c2d27a3b908f6d41b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-handler-proxy-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler-proxy High
Vendor gradle artifactid netty-handler-proxy Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name proxy Highest
Vendor Manifest automatic-module-name io.netty.handler.proxy Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler-proxy Medium
Vendor Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler-proxy Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler/Proxy High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler-proxy High
Product gradle artifactid netty-handler-proxy Highest
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name proxy Highest
Product Manifest automatic-module-name io.netty.handler.proxy Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler/Proxy Medium
Product Manifest bundle-symbolicname io.netty.handler-proxy Medium
Product Manifest Implementation-Title Netty/Handler/Proxy High
Product Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Product Manifest specification-title Netty/Handler/Proxy Medium
Product pom artifactid netty-handler-proxy Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler/Proxy High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-handler-proxy@4.1.126.Final
(Confidence :High)
netty-nio-client-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/netty-nio-client/2.26.30/1d0671c21b5cf696213658baaf3cc4cc57393401/netty-nio-client-2.26.30.jar
MD5: 6c9f3804b515cab33890926665460826
SHA1: 1d0671c21b5cf696213658baaf3cc4cc57393401
SHA256: c4e800bd4e506fc4f4a5981708483c4307c9853849e8378a18a09e1e952c4a32
Referenced In Project/Scope: server-start:runtimeClasspath
netty-nio-client-2.26.30.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-nio-client High
Vendor gradle artifactid netty-nio-client Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name http Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.http.nio.netty Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid netty-nio-client Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: HTTP Clients :: Netty Non-Blocking I/O High
Vendor pom parent-artifactid http-clients Low
Product file name netty-nio-client High
Product gradle artifactid netty-nio-client Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name http Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.http.nio.netty Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid netty-nio-client Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: HTTP Clients :: Netty Non-Blocking I/O High
Product pom parent-artifactid http-clients Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
netty-resolver-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-resolver/4.1.126.Final/9e46079201a3f050670924d8b3326b3d4453763d/netty-resolver-4.1.126.Final.jar
MD5: 04867ccad29777970cd1b0d4cec07b98
SHA1: 9e46079201a3f050670924d8b3326b3d4453763d
SHA256: c66be4ca4e37c263af785253449024b7ef150093257490c208bdc1d774e2c6d7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-resolver-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver High
Vendor gradle artifactid netty-resolver Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver High
Product gradle artifactid netty-resolver Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver Medium
Product Manifest bundle-symbolicname io.netty.resolver Medium
Product Manifest Implementation-Title Netty/Resolver High
Product Manifest implementation-url https://netty.io/netty-resolver/ Low
Product Manifest specification-title Netty/Resolver Medium
Product pom artifactid netty-resolver Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-resolver@4.1.126.Final
(Confidence :High)
netty-transport-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport/4.1.126.Final/3078db67315cb25a87938da7e868b734413be15d/netty-transport-4.1.126.Final.jar
MD5: 9c3f4f52507b206c28e51e65bbcc6774
SHA1: 3078db67315cb25a87938da7e868b734413be15d
SHA256: 30065562b7708e88cdf7c3fd192be9083651be538676ba27c8631e255825f315
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-transport-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport High
Vendor gradle artifactid netty-transport Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport Medium
Vendor Manifest implementation-url https://netty.io/netty-transport/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport High
Product gradle artifactid netty-transport Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport Medium
Product Manifest bundle-symbolicname io.netty.transport Medium
Product Manifest Implementation-Title Netty/Transport High
Product Manifest implementation-url https://netty.io/netty-transport/ Low
Product Manifest specification-title Netty/Transport Medium
Product pom artifactid netty-transport Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-transport@4.1.126.Final
(Confidence :High)
netty-transport-classes-epoll-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-classes-epoll/4.1.126.Final/c518513a1c7bdaf67462a1062b873a04fbf2b157/netty-transport-classes-epoll-4.1.126.Final.jar
MD5: 123d48e51696efa02bfdbd0c83c04ac9
SHA1: c518513a1c7bdaf67462a1062b873a04fbf2b157
SHA256: d7e0684969dad68e224e4fbf3e8e0de6b5191b25d820f8d6ae05201c70b33654
Referenced In Project/Scope: server-start:runtimeClasspath
netty-transport-classes-epoll-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-epoll High
Vendor gradle artifactid netty-transport-classes-epoll Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name epoll Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-epoll High
Product gradle artifactid netty-transport-classes-epoll Highest
Product jar package name epoll Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/Epoll Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Product Manifest Implementation-Title Netty/Transport/Classes/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Product Manifest specification-title Netty/Transport/Classes/Epoll Medium
Product pom artifactid netty-transport-classes-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/Epoll High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-transport-classes-epoll@4.1.126.Final
(Confidence :High)
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-native-epoll/4.1.126.Final/53309e2477909db42957fac5b103b86fc709789c/netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
MD5: 90f058169bb47367be1268ec8d093acd
SHA1: 53309e2477909db42957fac5b103b86fc709789c
SHA256: 4ea5268f375d01f494dad06ba45f47953d5c4648a16f1b89c8a04358064d3690
Referenced In Project/Scope: server-start:runtimeClasspath
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-epoll High
Vendor gradle artifactid netty-transport-native-epoll Highest
Vendor gradle groupid io.netty Highest
Vendor Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-epoll Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-epoll High
Product gradle artifactid netty-transport-native-epoll Highest
Product Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Epoll Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Product Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-epoll Low
Product Manifest Implementation-Title Netty/Transport/Native/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/Epoll Medium
Product pom artifactid netty-transport-native-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Epoll High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-transport-native-epoll@4.1.126.Final
(Confidence :High)
netty-transport-native-unix-common-4.1.126.Final.jar
Description:
Static library which contains common unix utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-native-unix-common/4.1.126.Final/fd579d0e8f9f6509d201920a35f51aa49e638f5e/netty-transport-native-unix-common-4.1.126.Final.jar
MD5: 090afea4551d0c22d4b538723133c97a
SHA1: fd579d0e8f9f6509d201920a35f51aa49e638f5e
SHA256: b6578df0ad9092f4e846d34976a5f887b067ebaa71307eb90653d3a1898c1f5f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
netty-transport-native-unix-common-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-unix-common High
Vendor gradle artifactid netty-transport-native-unix-common Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name unix Highest
Vendor Manifest automatic-module-name io.netty.transport.unix.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-unix-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Unix/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-unix-common High
Product gradle artifactid netty-transport-native-unix-common Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name unix Highest
Product Manifest automatic-module-name io.netty.transport.unix.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Unix/Common Medium
Product Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Product Manifest Implementation-Title Netty/Transport/Native/Unix/Common High
Product Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Product Manifest specification-title Netty/Transport/Native/Unix/Common Medium
Product pom artifactid netty-transport-native-unix-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Unix/Common High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
pkg:maven/io.netty/netty-transport-native-unix-common@4.1.126.Final
(Confidence :High)
okhttp-4.12.0.jar
Description:
Square’s meticulous HTTP client for Java and Kotlin.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.squareup.okhttp3/okhttp/4.12.0/2f4525d4a200e97e1b87449c2cd9bd2e25b7e8cd/okhttp-4.12.0.jar
MD5: 6acba053af88fed87e710c6c29911d7c
SHA1: 2f4525d4a200e97e1b87449c2cd9bd2e25b7e8cd
SHA256: b1050081b14bb7a3a7e55a4d3ef01b5dcfabc453b4573a4fc019767191d5f4e0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
okhttp-4.12.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name okhttp High
Vendor gradle artifactid okhttp Highest
Vendor gradle groupid com.squareup.okhttp3 Highest
Vendor jar package name internal Low
Vendor jar package name okhttp3 Highest
Vendor jar package name okhttp3 Low
Vendor Manifest automatic-module-name okhttp3 Medium
Vendor pom artifactid okhttp Low
Vendor pom developer name Square, Inc. Medium
Vendor pom groupid com.squareup.okhttp3 Highest
Vendor pom name okhttp High
Vendor pom url https://square.github.io/okhttp/ Highest
Product file name okhttp High
Product gradle artifactid okhttp Highest
Product jar package name internal Low
Product jar package name okhttp3 Highest
Product Manifest automatic-module-name okhttp3 Medium
Product pom artifactid okhttp Highest
Product pom developer name Square, Inc. Low
Product pom groupid com.squareup.okhttp3 Highest
Product pom name okhttp High
Product pom url https://square.github.io/okhttp/ Medium
Version file version 4.12.0 High
Version gradle version 4.12.0 Highest
Version pom version 4.12.0 Highest
okio-jvm-3.6.0.jar
Description:
A modern I/O library for Android, Java, and Kotlin Multiplatform.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.squareup.okio/okio-jvm/3.6.0/5600569133b7bdefe1daf9ec7f4abeb6d13e1786/okio-jvm-3.6.0.jar
MD5: 26370180ff99a7e8a12dcaac2a70cc6e
SHA1: 5600569133b7bdefe1daf9ec7f4abeb6d13e1786
SHA256: 67543f0736fc422ae927ed0e504b98bc5e269fda0d3500579337cb713da28412
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
okio-jvm-3.6.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name okio-jvm High
Vendor gradle artifactid okio-jvm Highest
Vendor gradle groupid com.squareup.okio Highest
Vendor jar package name okio Highest
Vendor jar package name okio Low
Vendor Manifest automatic-module-name okio Medium
Vendor Manifest bundle-symbolicname com.squareup.okio Medium
Vendor pom artifactid okio-jvm Low
Vendor pom developer id square Medium
Vendor pom developer name Square, Inc. Medium
Vendor pom groupid com.squareup.okio Highest
Vendor pom name okio High
Vendor pom url square/okio/ Highest
Product file name okio-jvm High
Product gradle artifactid okio-jvm Highest
Product jar package name okio Highest
Product Manifest automatic-module-name okio Medium
Product Manifest Bundle-Name com.squareup.okio Medium
Product Manifest bundle-symbolicname com.squareup.okio Medium
Product pom artifactid okio-jvm Highest
Product pom developer id square Low
Product pom developer name Square, Inc. Low
Product pom groupid com.squareup.okio Highest
Product pom name okio High
Product pom url square/okio/ High
Version file version 3.6.0 High
Version gradle version 3.6.0 Highest
Version Manifest Bundle-Version 3.6.0 High
Version pom version 3.6.0 Highest
opensaml-core-api-5.1.3.jar
Description:
Core API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-core-api/5.1.3/a9f6ed7d41f2917da7ab3c885962b9623a2577e1/opensaml-core-api-5.1.3.jar
MD5: 0f7a3f40de07544c2be6ef6e6ff65530
SHA1: a9f6ed7d41f2917da7ab3c885962b9623a2577e1
SHA256: e8c7884f1885d7b4143e6259f8ca98551ac12e5f684f8e136667ddb7b840f170
Referenced In Project/Scope: server-start:webapps
opensaml-core-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-core-api High
Vendor gradle artifactid opensaml-core-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name core Highest
Vendor jar package name opensaml Highest
Vendor Manifest automatic-module-name org.opensaml.core Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor manifest: org/opensaml/core/ Implementation-Vendor opensaml.org Medium
Vendor pom artifactid opensaml-core-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Core API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-core-api High
Product gradle artifactid opensaml-core-api Highest
Product hint analyzer product opensaml Highest
Product jar package name core Highest
Product jar package name opensaml Highest
Product Manifest automatic-module-name org.opensaml.core Medium
Product Manifest build-jdk-spec 17 Low
Product manifest: org/opensaml/core/ Implementation-Title opensaml-core-api Medium
Product pom artifactid opensaml-core-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Core API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version manifest: org/opensaml/core/ Implementation-Version 5.1.3 Medium
Version pom version 5.1.3 Highest
opensaml-core-impl-5.1.3.jar
Description:
Core Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-core-impl/5.1.3/e76e3d970d49196ccec9edfbb65bff79f1c3e45a/opensaml-core-impl-5.1.3.jar
MD5: 032f97b7e0196072d5179d0cd7c6b686
SHA1: e76e3d970d49196ccec9edfbb65bff79f1c3e45a
SHA256: 66f4145b8db04a351aa2640a0be7f0e677aa290fe2ce9006dfdeba9db3137dc2
Referenced In Project/Scope: server-start:webapps
opensaml-core-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-core-impl High
Vendor gradle artifactid opensaml-core-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name core Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor Manifest automatic-module-name org.opensaml.core.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor manifest: org/opensaml/core/ Implementation-Vendor opensaml.org Medium
Vendor pom artifactid opensaml-core-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Core Implementation High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-core-impl High
Product gradle artifactid opensaml-core-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name core Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product Manifest automatic-module-name org.opensaml.core.impl Medium
Product Manifest build-jdk-spec 17 Low
Product manifest: org/opensaml/core/ Implementation-Title opensaml-core-impl Medium
Product pom artifactid opensaml-core-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Core Implementation High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version manifest: org/opensaml/core/ Implementation-Version 5.1.3 Medium
Version pom version 5.1.3 Highest
opensaml-messaging-api-5.1.3.jar
Description:
Messaging API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-messaging-api/5.1.3/5cf3b4e06294405c0f96b24ef0829e1b5390ca08/opensaml-messaging-api-5.1.3.jar
MD5: a419196bb5f712b1e7868b9d697f764e
SHA1: 5cf3b4e06294405c0f96b24ef0829e1b5390ca08
SHA256: 299f17b256b1a9e121e99d6087f43bb9e5a51e3eca744a176caaad6cafbf646e
Referenced In Project/Scope: server-start:webapps
opensaml-messaging-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-messaging-api High
Vendor gradle artifactid opensaml-messaging-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name messaging Highest
Vendor jar package name opensaml Highest
Vendor Manifest automatic-module-name org.opensaml.messaging Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-messaging-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Messaging API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-messaging-api High
Product gradle artifactid opensaml-messaging-api Highest
Product hint analyzer product opensaml Highest
Product jar package name messaging Highest
Product jar package name opensaml Highest
Product Manifest automatic-module-name org.opensaml.messaging Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-messaging-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Messaging API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-profile-api-5.1.3.jar
Description:
Profile API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-profile-api/5.1.3/609b50480026ce743c22d34968a7d463e1814bc9/opensaml-profile-api-5.1.3.jar
MD5: 5e931a70684ec7853b0f0c0a11a6f676
SHA1: 609b50480026ce743c22d34968a7d463e1814bc9
SHA256: cf2e14a088d985296aa0d1d4cd28f2f7146883af6e525b6fb4758e7f93836f28
Referenced In Project/Scope: server-start:webapps
opensaml-profile-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-profile-api High
Vendor gradle artifactid opensaml-profile-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name profile Highest
Vendor Manifest automatic-module-name org.opensaml.profile Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-profile-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Profile API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-profile-api High
Product gradle artifactid opensaml-profile-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name profile Highest
Product Manifest automatic-module-name org.opensaml.profile Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-profile-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Profile API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-saml-api-5.1.3.jar
Description:
SAML Provider API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-saml-api/5.1.3/2f78adf32794b73a6180098d5606a71976c81927/opensaml-saml-api-5.1.3.jar
MD5: 401e2183db1f68336bee6980f21564d7
SHA1: 2f78adf32794b73a6180098d5606a71976c81927
SHA256: 06f41f275c70ac3f18ceb27835a679fa6dd75794b721edd581a999601366d39c
Referenced In Project/Scope: server-start:webapps
opensaml-saml-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-saml-api High
Vendor gradle artifactid opensaml-saml-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name saml Highest
Vendor Manifest automatic-module-name org.opensaml.saml Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-saml-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SAML Provider API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-saml-api High
Product gradle artifactid opensaml-saml-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name saml Highest
Product Manifest automatic-module-name org.opensaml.saml Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-saml-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SAML Provider API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-saml-impl-5.1.3.jar
Description:
SAML Provider Implementations
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-saml-impl/5.1.3/c15a7246ba516cd1850b97df949900e79251cdc3/opensaml-saml-impl-5.1.3.jar
MD5: c9d4a20fadf612f85c8ef431b9f83023
SHA1: c15a7246ba516cd1850b97df949900e79251cdc3
SHA256: fcb6fb1624d9dd6bb8215115908b598ece23f96359002ffb29d3318d4b260cfa
Referenced In Project/Scope: server-start:webapps
opensaml-saml-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-saml-impl High
Vendor gradle artifactid opensaml-saml-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor jar package name saml Highest
Vendor Manifest automatic-module-name org.opensaml.saml.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-saml-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SAML Provider Implementations High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-saml-impl High
Product gradle artifactid opensaml-saml-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product jar package name saml Highest
Product Manifest automatic-module-name org.opensaml.saml.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-saml-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SAML Provider Implementations High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-security-api-5.1.3.jar
Description:
Security API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-security-api/5.1.3/939888451a4853a10c7bc65829ab4772abb34711/opensaml-security-api-5.1.3.jar
MD5: a1908cd25275c258198a018e345f0726
SHA1: 939888451a4853a10c7bc65829ab4772abb34711
SHA256: 5195a94d892dce73a0be12278d3e4a5fb292bb24f85757836f2d8e12be21f7a9
Referenced In Project/Scope: server-start:webapps
opensaml-security-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-security-api High
Vendor gradle artifactid opensaml-security-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name security Highest
Vendor Manifest automatic-module-name org.opensaml.security Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-security-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Security API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-security-api High
Product gradle artifactid opensaml-security-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name security Highest
Product Manifest automatic-module-name org.opensaml.security Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-security-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Security API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-security-impl-5.1.3.jar
Description:
Security Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-security-impl/5.1.3/1d56490eb9777cbaf7a7001ff16320d85596f363/opensaml-security-impl-5.1.3.jar
MD5: 63485e3c2fc1b0403bb3be6f2e138512
SHA1: 1d56490eb9777cbaf7a7001ff16320d85596f363
SHA256: 387653fa5f7e26e9da78aa40c89fcf284c84ae7d5f06297208bbb37796a1c477
Referenced In Project/Scope: server-start:webapps
opensaml-security-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-security-impl High
Vendor gradle artifactid opensaml-security-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor jar package name security Highest
Vendor Manifest automatic-module-name org.opensaml.security.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-security-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Security Implementation High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-security-impl High
Product gradle artifactid opensaml-security-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product jar package name security Highest
Product Manifest automatic-module-name org.opensaml.security.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-security-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Security Implementation High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-soap-api-5.1.3.jar
Description:
SOAP Provider API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-soap-api/5.1.3/4c7dca7687746330c8ef7fd74c899cfd123fe458/opensaml-soap-api-5.1.3.jar
MD5: 7d4da7d096dbbf1530a0405db785a86b
SHA1: 4c7dca7687746330c8ef7fd74c899cfd123fe458
SHA256: eb7a5193cc3191bc90894aa60df7ceb938ea6fcc39365abc876f40d6a0aaddf7
Referenced In Project/Scope: server-start:webapps
opensaml-soap-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-soap-api High
Vendor gradle artifactid opensaml-soap-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name soap Highest
Vendor Manifest automatic-module-name org.opensaml.soap Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-soap-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SOAP Provider API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-soap-api High
Product gradle artifactid opensaml-soap-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name soap Highest
Product Manifest automatic-module-name org.opensaml.soap Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-soap-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SOAP Provider API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-soap-impl-5.1.3.jar
Description:
SOAP Provider Implementations
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-soap-impl/5.1.3/d49ad07da6646ebd4f1a36678a04bec0a6a3eb08/opensaml-soap-impl-5.1.3.jar
MD5: 7c826197d7763353334a62908c31b3de
SHA1: d49ad07da6646ebd4f1a36678a04bec0a6a3eb08
SHA256: a97553577686f0863ff55bdb8c5d79731796cedf80bdafaa26721de06b26c6d7
Referenced In Project/Scope: server-start:webapps
opensaml-soap-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-soap-impl High
Vendor gradle artifactid opensaml-soap-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor jar package name soap Highest
Vendor Manifest automatic-module-name org.opensaml.soap.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-soap-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SOAP Provider Implementations High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-soap-impl High
Product gradle artifactid opensaml-soap-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product jar package name soap Highest
Product Manifest automatic-module-name org.opensaml.soap.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-soap-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SOAP Provider Implementations High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-storage-api-5.1.3.jar
Description:
Storage API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-storage-api/5.1.3/e3de5ca194127d62bb6b8dbb1f502f24f4fd884f/opensaml-storage-api-5.1.3.jar
MD5: 4a45a16512372250a513e02f0d7b4274
SHA1: e3de5ca194127d62bb6b8dbb1f502f24f4fd884f
SHA256: 02eb63ccd6ef4e6768249cee642f4d4c5e749af85a6bd3cb0fcd0dc2c2e709a0
Referenced In Project/Scope: server-start:webapps
opensaml-storage-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-storage-api High
Vendor gradle artifactid opensaml-storage-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name storage Highest
Vendor Manifest automatic-module-name org.opensaml.storage Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-storage-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: Storage API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-storage-api High
Product gradle artifactid opensaml-storage-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name storage Highest
Product Manifest automatic-module-name org.opensaml.storage Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-storage-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: Storage API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xacml-api-5.1.3.jar
Description:
XACML Provider API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xacml-api/5.1.3/207a4b80f16fa424e41fbb89525f5db8f537c440/opensaml-xacml-api-5.1.3.jar
MD5: d7e1dfa687f952146a43e85683fab7a3
SHA1: 207a4b80f16fa424e41fbb89525f5db8f537c440
SHA256: dddb00d9670c0c4e660a989eed513225709a4ee99caca3f0a67cbadeb7bb5714
Referenced In Project/Scope: server-start:webapps
opensaml-xacml-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xacml-api High
Vendor gradle artifactid opensaml-xacml-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name xacml Highest
Vendor Manifest automatic-module-name org.opensaml.xacml Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xacml-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: XACML Provider API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xacml-api High
Product gradle artifactid opensaml-xacml-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name xacml Highest
Product Manifest automatic-module-name org.opensaml.xacml Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xacml-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: XACML Provider API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xacml-impl-5.1.3.jar
Description:
XACML Provider Implementations
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xacml-impl/5.1.3/3f8cded3a3c24d12b150878c6fdcdb28322f506c/opensaml-xacml-impl-5.1.3.jar
MD5: c17291910cf432f840ee060bc750913c
SHA1: 3f8cded3a3c24d12b150878c6fdcdb28322f506c
SHA256: 95b6af88800ae43f2099248b289c735fe31a2a26c61d2f6d48db67c39f3fc946
Referenced In Project/Scope: server-start:webapps
opensaml-xacml-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xacml-impl High
Vendor gradle artifactid opensaml-xacml-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor jar package name provider Highest
Vendor jar package name xacml Highest
Vendor Manifest automatic-module-name org.opensaml.xacml.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xacml-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: XACML Provider Implementations High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xacml-impl High
Product gradle artifactid opensaml-xacml-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product jar package name provider Highest
Product jar package name xacml Highest
Product Manifest automatic-module-name org.opensaml.xacml.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xacml-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: XACML Provider Implementations High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xacml-saml-api-5.1.3.jar
Description:
SAML XACML Profile API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xacml-saml-api/5.1.3/847b38b9e9d2193026f63756e98b2745ab39ab32/opensaml-xacml-saml-api-5.1.3.jar
MD5: 5d69f30bfb720f424084174116a5a86a
SHA1: 847b38b9e9d2193026f63756e98b2745ab39ab32
SHA256: a81c15db1ba582d0e8f81e430c8d6f25938447be137a254950e4fe8e5f7a0939
Referenced In Project/Scope: server-start:webapps
opensaml-xacml-saml-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xacml-saml-api High
Vendor gradle artifactid opensaml-xacml-saml-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name profile Highest
Vendor jar package name saml Highest
Vendor jar package name xacml Highest
Vendor Manifest automatic-module-name org.opensaml.xacml.profile.saml Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xacml-saml-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SAML XACML Profile API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xacml-saml-api High
Product gradle artifactid opensaml-xacml-saml-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name profile Highest
Product jar package name saml Highest
Product jar package name xacml Highest
Product Manifest automatic-module-name org.opensaml.xacml.profile.saml Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xacml-saml-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SAML XACML Profile API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xacml-saml-impl-5.1.3.jar
Description:
SAML XACML Profile Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xacml-saml-impl/5.1.3/aa29845d6f767b9c90c6dd5216212623b7e2d058/opensaml-xacml-saml-impl-5.1.3.jar
MD5: ce5c6cab683349c65d27f43c934035e4
SHA1: aa29845d6f767b9c90c6dd5216212623b7e2d058
SHA256: d3f887a00b3bab6878adc090ae29d9a17bd245601c05bbf898b4d0bdbf461276
Referenced In Project/Scope: server-start:webapps
opensaml-xacml-saml-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xacml-saml-impl High
Vendor gradle artifactid opensaml-xacml-saml-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name profile Highest
Vendor jar package name saml Highest
Vendor jar package name xacml Highest
Vendor Manifest automatic-module-name org.opensaml.xacml.profile.saml.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xacml-saml-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: SAML XACML Profile Implementation High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xacml-saml-impl High
Product gradle artifactid opensaml-xacml-saml-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name profile Highest
Product jar package name saml Highest
Product jar package name xacml Highest
Product Manifest automatic-module-name org.opensaml.xacml.profile.saml.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xacml-saml-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: SAML XACML Profile Implementation High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xmlsec-api-5.1.3.jar
Description:
XML Security API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xmlsec-api/5.1.3/34b716d65bd1df1baa3f7446c316d34d88560f3c/opensaml-xmlsec-api-5.1.3.jar
MD5: b49185507918bb1e2bd692b9dda6d0f8
SHA1: 34b716d65bd1df1baa3f7446c316d34d88560f3c
SHA256: dd67d633f42a09a4439af08345b1ac822dff2bb0baa8a1eccd36fa9febab48a0
Referenced In Project/Scope: server-start:webapps
opensaml-xmlsec-api-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xmlsec-api High
Vendor gradle artifactid opensaml-xmlsec-api Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name opensaml Highest
Vendor jar package name xmlsec Highest
Vendor Manifest automatic-module-name org.opensaml.xmlsec Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xmlsec-api Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: XML Security API High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xmlsec-api High
Product gradle artifactid opensaml-xmlsec-api Highest
Product hint analyzer product opensaml Highest
Product jar package name opensaml Highest
Product jar package name xmlsec Highest
Product Manifest automatic-module-name org.opensaml.xmlsec Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xmlsec-api Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: XML Security API High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opensaml-xmlsec-impl-5.1.3.jar
Description:
XML Security Implementation
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.opensaml/opensaml-xmlsec-impl/5.1.3/72687ef61ec398f0944c66073375b42829a2a81b/opensaml-xmlsec-impl-5.1.3.jar
MD5: 62c7d1a210219be67a47f0c4a846dcd8
SHA1: 72687ef61ec398f0944c66073375b42829a2a81b
SHA256: db9c0e506d75e1633eccfa10017540d7590bf02b4baa3b4e8521f2012cf1b149
Referenced In Project/Scope: server-start:webapps
opensaml-xmlsec-impl-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opensaml-xmlsec-impl High
Vendor gradle artifactid opensaml-xmlsec-impl Highest
Vendor gradle groupid org.opensaml Highest
Vendor hint analyzer vendor shibboleth Highest
Vendor jar package name impl Highest
Vendor jar package name opensaml Highest
Vendor jar package name xmlsec Highest
Vendor Manifest automatic-module-name org.opensaml.xmlsec.impl Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid opensaml-xmlsec-impl Low
Vendor pom groupid org.opensaml Highest
Vendor pom name OpenSAML :: XML Security Implementation High
Vendor pom parent-artifactid opensaml-parent Low
Product file name opensaml-xmlsec-impl High
Product gradle artifactid opensaml-xmlsec-impl Highest
Product hint analyzer product opensaml Highest
Product jar package name impl Highest
Product jar package name opensaml Highest
Product jar package name xmlsec Highest
Product Manifest automatic-module-name org.opensaml.xmlsec.impl Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid opensaml-xmlsec-impl Highest
Product pom groupid org.opensaml Highest
Product pom name OpenSAML :: XML Security Implementation High
Product pom parent-artifactid opensaml-parent Medium
Version file version 5.1.3 High
Version gradle version 5.1.3 Highest
Version pom version 5.1.3 Highest
opentelemetry-api-1.44.1.jar
Description:
OpenTelemetry API
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.opentelemetry/opentelemetry-api/1.44.1/17115247ee4d6119a2c1d7d1a934a561788eb6b4/opentelemetry-api-1.44.1.jar
MD5: 89df0d23c4697e35acf403ce4d8c858b
SHA1: 17115247ee4d6119a2c1d7d1a934a561788eb6b4
SHA256: 097e2e71c8b8c813f4a13176baafbbbb124b1253f5c9fffd110bc2add74ace93
Referenced In Project/Scope: server-start:runtimeClasspath
opentelemetry-api-1.44.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opentelemetry-api High
Vendor gradle artifactid opentelemetry-api Highest
Vendor gradle groupid io.opentelemetry Highest
Vendor jar package name api Highest
Vendor jar package name api Low
Vendor jar package name io Highest
Vendor jar package name io Low
Vendor jar package name opentelemetry Highest
Vendor jar package name opentelemetry Low
Vendor Manifest automatic-module-name io.opentelemetry.api Medium
Vendor pom artifactid opentelemetry-api Low
Vendor pom developer id opentelemetry Medium
Vendor pom developer name OpenTelemetry Medium
Vendor pom groupid io.opentelemetry Highest
Vendor pom name OpenTelemetry Java High
Vendor pom url open-telemetry/opentelemetry-java Highest
Product file name opentelemetry-api High
Product gradle artifactid opentelemetry-api Highest
Product jar package name api Highest
Product jar package name api Low
Product jar package name io Highest
Product jar package name opentelemetry Highest
Product jar package name opentelemetry Low
Product Manifest automatic-module-name io.opentelemetry.api Medium
Product Manifest Implementation-Title all High
Product pom artifactid opentelemetry-api Highest
Product pom developer id opentelemetry Low
Product pom developer name OpenTelemetry Low
Product pom groupid io.opentelemetry Highest
Product pom name OpenTelemetry Java High
Product pom url open-telemetry/opentelemetry-java High
Version file version 1.44.1 High
Version gradle version 1.44.1 Highest
Version Manifest Implementation-Version 1.44.1 High
Version pom version 1.44.1 Highest
opentelemetry-context-1.44.1.jar
Description:
OpenTelemetry Context (Incubator)
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.opentelemetry/opentelemetry-context/1.44.1/940ee86bb63502c6d3a54976d39c00f983fe4c81/opentelemetry-context-1.44.1.jar
MD5: 3db904e4b8212c1abe07b87ae095d745
SHA1: 940ee86bb63502c6d3a54976d39c00f983fe4c81
SHA256: 006b3f7c3880356a86f02c40eedeba124f226a2f145fe904cc1b7def0088bab0
Referenced In Project/Scope: server-start:runtimeClasspath
opentelemetry-context-1.44.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name opentelemetry-context High
Vendor gradle artifactid opentelemetry-context Highest
Vendor gradle groupid io.opentelemetry Highest
Vendor jar package name context Highest
Vendor jar package name context Low
Vendor jar package name io Highest
Vendor jar package name io Low
Vendor jar package name opentelemetry Highest
Vendor jar package name opentelemetry Low
Vendor Manifest automatic-module-name io.opentelemetry.context Medium
Vendor pom artifactid opentelemetry-context Low
Vendor pom developer id opentelemetry Medium
Vendor pom developer name OpenTelemetry Medium
Vendor pom groupid io.opentelemetry Highest
Vendor pom name OpenTelemetry Java High
Vendor pom url open-telemetry/opentelemetry-java Highest
Product file name opentelemetry-context High
Product gradle artifactid opentelemetry-context Highest
Product jar package name context Highest
Product jar package name context Low
Product jar package name io Highest
Product jar package name opentelemetry Highest
Product jar package name opentelemetry Low
Product Manifest automatic-module-name io.opentelemetry.context Medium
Product Manifest Implementation-Title context High
Product pom artifactid opentelemetry-context Highest
Product pom developer id opentelemetry Low
Product pom developer name OpenTelemetry Low
Product pom groupid io.opentelemetry Highest
Product pom name OpenTelemetry Java High
Product pom url open-telemetry/opentelemetry-java High
Version file version 1.44.1 High
Version gradle version 1.44.1 Highest
Version Manifest Implementation-Version 1.44.1 High
Version pom version 1.44.1 Highest
org.eclipse.paho.client.mqttv3-1.2.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.eclipse.paho/org.eclipse.paho.client.mqttv3/1.2.5/1546cfc794449c39ad569853843a930104fdc297/org.eclipse.paho.client.mqttv3-1.2.5.jar
MD5: eb09d20835460ad2de7b6d46e77ad113
SHA1: 1546cfc794449c39ad569853843a930104fdc297
SHA256: 59914287adac506a28d5e8172eed262a22605f3df4d426b9d92f41dae2448185
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
org.eclipse.paho.client.mqttv3-1.2.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.paho.client.mqttv3 High
Vendor gradle artifactid org.eclipse.paho.client.mqttv3 Highest
Vendor gradle groupid org.eclipse.paho Highest
Vendor jar package name client Highest
Vendor jar package name eclipse Highest
Vendor jar package name mqttv3 Highest
Vendor jar package name paho Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-localization bundle Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-symbolicname org.eclipse.paho.client.mqttv3 Medium
Vendor pom artifactid eclipse.paho.client.mqttv3 Low
Vendor pom groupid org.eclipse.paho Highest
Vendor pom parent-artifactid java-parent Low
Product file name org.eclipse.paho.client.mqttv3 High
Product gradle artifactid org.eclipse.paho.client.mqttv3 Highest
Product jar package name client Highest
Product jar package name eclipse Highest
Product jar package name mqttv3 Highest
Product jar package name paho Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-localization bundle Low
Product Manifest Bundle-Name org.eclipse.paho.client.mqttv3 Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest bundle-symbolicname org.eclipse.paho.client.mqttv3 Medium
Product pom artifactid eclipse.paho.client.mqttv3 Highest
Product pom groupid org.eclipse.paho Highest
Product pom parent-artifactid java-parent Medium
Version file version 1.2.5 High
Version gradle version 1.2.5 Highest
Version Manifest Bundle-Version 1.2.5 High
Version pom version 1.2.5 Highest
CVE-2025-10543 suppress
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak into the message body in a PUBLISH packet).
The issue arises because the length of the data passed in was converted from an int64/int32 (depending upon CPU) to an int16 without checks for overflows. The int16 length was then written, followed by the data (e.g. topic). This meant that when the data (e.g. topic) was over 65535 bytes then the amount of data written exceeds what the length field indicates. This could lead to a corrupt packet, or mean that the excess data leaks into another field (e.g. topic leaks into message body).
CWE-197 Numeric Truncation Error, CWE-681 Incorrect Conversion between Numeric Types
CVSSv4:
Base Score: MEDIUM (6.3)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
org.jacoco.agent-0.8.12.jar
Description:
JaCoCo Agent
License:
https://www.eclipse.org/legal/epl-2.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.agent/0.8.12/4f24f7fc6d471fcbad4ce0c9bf3f5ea8f79675d6/org.jacoco.agent-0.8.12.jar
MD5: 3a9cf378b3e5027d1438a2a179cc834e
SHA1: 4f24f7fc6d471fcbad4ce0c9bf3f5ea8f79675d6
SHA256: ab29507b750d325bbaf7ea094860fff26d27170038d8ee5f00c3074489f14637
Referenced In Projects/Scopes:
server-start:jacocoAnt
server-start:jacocoAgent
org.jacoco.agent-0.8.12.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name org.jacoco.agent High
Vendor gradle artifactid org.jacoco.agent Highest
Vendor gradle groupid org.jacoco Highest
Vendor jar package name agent Highest
Vendor jar package name jacoco Highest
Vendor Manifest automatic-module-name org.jacoco.agent Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.jacoco.agent Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom artifactid jacoco.agent Low
Vendor pom groupid org.jacoco Highest
Vendor pom name JaCoCo :: Agent High
Vendor pom parent-artifactid org.jacoco.build Low
Product file name org.jacoco.agent High
Product gradle artifactid org.jacoco.agent Highest
Product jar package name agent Highest
Product jar package name jacoco Highest
Product Manifest automatic-module-name org.jacoco.agent Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Bundle-Name JaCoCo Agent Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.jacoco.agent Medium
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product pom artifactid jacoco.agent Highest
Product pom groupid org.jacoco Highest
Product pom name JaCoCo :: Agent High
Product pom parent-artifactid org.jacoco.build Medium
Version file version 0.8.12 High
Version gradle version 0.8.12 Highest
Version pom version 0.8.12 Highest
pkg:maven/org.jacoco/org.jacoco.agent@0.8.12
(Confidence :High)
org.jacoco.agent-0.8.12.jar: jacocoagent.jar (shaded: org.jacoco:org.jacoco.agent.rt:0.8.12)
Description:
JaCoCo Java Agent
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.agent/0.8.12/4f24f7fc6d471fcbad4ce0c9bf3f5ea8f79675d6/org.jacoco.agent-0.8.12.jar/jacocoagent.jar/META-INF/maven/org.jacoco/org.jacoco.agent.rt/pom.xml
MD5: e5cfab1bb3dfee9c3a2c0841ad333991
SHA1: c96eeafd2dc5707874f9502f0e39f9c9a668680a
SHA256: e54f3c1dca002620c515e72b7133fb158ecb84be429bf4e375a145233c53cc44
Referenced In Projects/Scopes:
server-start:jacocoAnt
server-start:jacocoAgent
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jacoco.agent.rt Low
Vendor pom groupid org.jacoco Highest
Vendor pom name JaCoCo :: Agent RT High
Vendor pom parent-artifactid org.jacoco.build Low
Product pom artifactid jacoco.agent.rt Highest
Product pom groupid org.jacoco Highest
Product pom name JaCoCo :: Agent RT High
Product pom parent-artifactid org.jacoco.build Medium
Version pom version 0.8.12 Highest
pkg:maven/org.jacoco/org.jacoco.agent.rt@0.8.12
(Confidence :High)
org.jacoco.agent-0.8.12.jar: jacocoagent.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.agent/0.8.12/4f24f7fc6d471fcbad4ce0c9bf3f5ea8f79675d6/org.jacoco.agent-0.8.12.jar/jacocoagent.jar
MD5: 3860bd17fba8612f6b99ef736391755c
SHA1: 2bec6efe140e3a38a81607181476a4016ef2c613
SHA256: 115e8e6e6593ca3a9892dfef695df4d487c706e59e71e64dc0ab95716ee02622
Referenced In Projects/Scopes:
server-start:jacocoAnt
server-start:jacocoAgent
Evidence
Type Source Name Value Confidence
Vendor file name jacocoagent High
Vendor jar package name agent Highest
Vendor jar package name agent Low
Vendor jar package name jacoco Highest
Vendor jar package name jacoco Low
Vendor jar package name rt Highest
Vendor jar package name rt Low
Vendor Manifest automatic-module-name org.jacoco.agent.rt Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest Implementation-Vendor Mountainminds GmbH & Co. KG High
Product file name jacocoagent High
Product jar package name agent Highest
Product jar package name agent Low
Product jar package name internal_aeaf9ab Low
Product jar package name jacoco Highest
Product jar package name rt Highest
Product jar package name rt Low
Product Manifest automatic-module-name org.jacoco.agent.rt Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title JaCoCo Java Agent High
Version Manifest build-jdk-spec 17 Low
Version Manifest Implementation-Version 0.8.12 High
org.jacoco.ant-0.8.12.jar
Description:
JaCoCo Ant Tasks
License:
https://www.eclipse.org/legal/epl-2.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.ant/0.8.12/67765683a5880f9604e4a7329f5c4ff888ade13b/org.jacoco.ant-0.8.12.jar
MD5: 230ad8f7c5a4cba55cbd75acf13a77eb
SHA1: 67765683a5880f9604e4a7329f5c4ff888ade13b
SHA256: 43f81e03dd6f5190aecb88a6236b694adade484b0402447c320fc6e94d685f41
Referenced In Project/Scope: server-start:jacocoAnt
org.jacoco.ant-0.8.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name org.jacoco.ant High
Vendor gradle artifactid org.jacoco.ant Highest
Vendor gradle groupid org.jacoco Highest
Vendor jar package name ant Highest
Vendor jar package name jacoco Highest
Vendor Manifest automatic-module-name org.jacoco.ant Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.jacoco.ant Medium
Vendor pom artifactid jacoco.ant Low
Vendor pom groupid org.jacoco Highest
Vendor pom name JaCoCo :: Ant High
Vendor pom parent-artifactid org.jacoco.build Low
Product file name org.jacoco.ant High
Product gradle artifactid org.jacoco.ant Highest
Product jar package name ant Highest
Product jar package name jacoco Highest
Product Manifest automatic-module-name org.jacoco.ant Medium
Product Manifest Bundle-Name JaCoCo Ant Tasks Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.jacoco.ant Medium
Product pom artifactid jacoco.ant Highest
Product pom groupid org.jacoco Highest
Product pom name JaCoCo :: Ant High
Product pom parent-artifactid org.jacoco.build Medium
Version file version 0.8.12 High
Version gradle version 0.8.12 Highest
Version pom version 0.8.12 Highest
pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
(Confidence :High)
org.jacoco.core-0.8.12.jar
Description:
JaCoCo Core
License:
https://www.eclipse.org/legal/epl-2.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.core/0.8.12/c2a45bd054bbacfe9998cbbf1a49010c62e48cbc/org.jacoco.core-0.8.12.jar
MD5: b48b0f4d9cf937450de8d2f6b920dcce
SHA1: c2a45bd054bbacfe9998cbbf1a49010c62e48cbc
SHA256: fca26db37c0c5fbd5dc4985237eb82866df9799d5082af899475a73f91f5b035
Referenced In Project/Scope: server-start:jacocoAnt
org.jacoco.core-0.8.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
Evidence
Type Source Name Value Confidence
Vendor file name org.jacoco.core High
Vendor gradle artifactid org.jacoco.core Highest
Vendor gradle groupid org.jacoco Highest
Vendor jar package name core Highest
Vendor jar package name jacoco Highest
Vendor Manifest automatic-module-name org.jacoco.core Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.jacoco.core Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom artifactid jacoco.core Low
Vendor pom groupid org.jacoco Highest
Vendor pom name JaCoCo :: Core High
Vendor pom parent-artifactid org.jacoco.build Low
Product file name org.jacoco.core High
Product gradle artifactid org.jacoco.core Highest
Product jar package name core Highest
Product jar package name jacoco Highest
Product Manifest automatic-module-name org.jacoco.core Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Bundle-Name JaCoCo Core Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.jacoco.core Medium
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product pom artifactid jacoco.core Highest
Product pom groupid org.jacoco Highest
Product pom name JaCoCo :: Core High
Product pom parent-artifactid org.jacoco.build Medium
Version file version 0.8.12 High
Version gradle version 0.8.12 Highest
Version pom version 0.8.12 Highest
pkg:maven/org.jacoco/org.jacoco.core@0.8.12
(Confidence :High)
org.jacoco.report-0.8.12.jar
Description:
JaCoCo Report
License:
https://www.eclipse.org/legal/epl-2.0/
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.report/0.8.12/d3df59a453cbc44c939f74868fb6c82127290c0c/org.jacoco.report-0.8.12.jar
MD5: 2dcdcd05335135386a65225161468581
SHA1: d3df59a453cbc44c939f74868fb6c82127290c0c
SHA256: f9c79ad66a66a0337c57849ad1287a2ab23b9b232d35314443e5ec49e6e3d20f
Referenced In Project/Scope: server-start:jacocoAnt
org.jacoco.report-0.8.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.jacoco/org.jacoco.ant@0.8.12
Evidence
Type Source Name Value Confidence
Vendor file name org.jacoco.report High
Vendor gradle artifactid org.jacoco.report Highest
Vendor gradle groupid org.jacoco Highest
Vendor jar package name jacoco Highest
Vendor jar package name report Highest
Vendor Manifest automatic-module-name org.jacoco.report Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.jacoco.report Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom artifactid jacoco.report Low
Vendor pom groupid org.jacoco Highest
Vendor pom name JaCoCo :: Report High
Vendor pom parent-artifactid org.jacoco.build Low
Product file name org.jacoco.report High
Product gradle artifactid org.jacoco.report Highest
Product jar package name jacoco Highest
Product jar package name report Highest
Product Manifest automatic-module-name org.jacoco.report Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Bundle-Name JaCoCo Report Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.jacoco.report Medium
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product pom artifactid jacoco.report Highest
Product pom groupid org.jacoco Highest
Product pom name JaCoCo :: Report High
Product pom parent-artifactid org.jacoco.build Medium
Version file version 0.8.12 High
Version gradle version 0.8.12 Highest
Version pom version 0.8.12 Highest
pkg:maven/org.jacoco/org.jacoco.report@0.8.12
(Confidence :High)
org.jacoco.report-0.8.12.jar: prettify.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.report/0.8.12/d3df59a453cbc44c939f74868fb6c82127290c0c/org.jacoco.report-0.8.12.jar/org/jacoco/report/internal/html/resources/prettify.js
MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb
SHA1: 290093755739da933c180ae7e7ebf283724dad1d
SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68
Referenced In Project/Scope: server-start:jacocoAnt
Evidence
Type Source Name Value Confidence
org.jacoco.report-0.8.12.jar: sort.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jacoco/org.jacoco.report/0.8.12/d3df59a453cbc44c939f74868fb6c82127290c0c/org.jacoco.report-0.8.12.jar/org/jacoco/report/internal/html/resources/sort.js
MD5: 0fe5c11816ae800b28ca4ee3ae18f11e
SHA1: a1102da743eefea675407c73aaf4502b2e971966
SHA256: 4342217c32c77bc9998246f3a83ab61dfb99120f5293ef0aeb0b16bd6273cd02
Referenced In Project/Scope: server-start:jacocoAnt
Evidence
Type Source Name Value Confidence
osci12-2.4.1.jar (shaded: de.osci.osciBibliothek:osci-bibliothek:2.4.1)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.osci/osci12/2.4.1/6efb982512c03f3f1981d9225cc7fa591ab9c070/osci12-2.4.1.jar/META-INF/maven/de.osci.osciBibliothek/osci-bibliothek/pom.xml
MD5: f44fda13fcdd6d6c68a9c39817677653
SHA1: 9dc360b4ad6a0c043a941bdef8a18afc503f35ff
SHA256: 8a4e85fa20f5ea31ffdf5a2bad3f7cc2d4211b23c9e84ef48412e017012fb70a
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid osci-bibliothek Low
Vendor pom groupid de.osci.osciBibliothek Highest
Vendor pom parent-artifactid osciBibliothek Low
Product pom artifactid osci-bibliothek Highest
Product pom groupid de.osci.osciBibliothek Highest
Product pom parent-artifactid osciBibliothek Medium
Version pom version 2.4.1 Highest
pkg:maven/de.osci.osciBibliothek/osci-bibliothek@2.4.1
(Confidence :High)
osci12-2.4.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.osci/osci12/2.4.1/6efb982512c03f3f1981d9225cc7fa591ab9c070/osci12-2.4.1.jar
MD5: c41ae17268a0da3dea69a2c31c702c39
SHA1: 6efb982512c03f3f1981d9225cc7fa591ab9c070
SHA256: 9909a358cddf382c3638bca15021f5561ba4abd85c853b7042366c49fa0c9a99
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
osci12-2.4.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name osci12 High
Vendor gradle artifactid osci12 Highest
Vendor gradle groupid de.osci Highest
Vendor jar package name de Highest
Vendor jar package name de Low
Vendor jar package name osci Low
Vendor jar package name osci12 Low
Vendor Manifest build-date 2023-10-12T11:23:29Z Low
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest implementation-url http://www.governikus.com Low
Vendor Manifest Implementation-Vendor Governikus GmbH & Co. KG High
Vendor Manifest Implementation-Vendor-Id de.governikus Medium
Vendor Manifest specification-vendor Governikus GmbH & Co. KG Low
Vendor pom artifactid osci12 Low
Vendor pom groupid de.osci Highest
Product file name osci12 High
Product gradle artifactid osci12 Highest
Product jar package name osci Highest
Product jar package name osci Low
Product jar package name osci12 Low
Product Manifest build-date 2023-10-12T11:23:29Z Low
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Implementation-Title osci-bibliothek High
Product Manifest implementation-url http://www.governikus.com Low
Product Manifest specification-title osci-bibliothek Medium
Product pom artifactid osci12 Highest
Product pom groupid de.osci Highest
Version file version 2.4.1 High
Version gradle version 2.4.1 Highest
Version Manifest Implementation-Version 2.4.1 High
Version pom version 2.4.1 Highest
pkg:maven/de.osci/osci12@2.4.1
(Confidence :High)
osgi-resource-locator-1.0.3.jar
Description:
Used by various API providers that rely on META-INF/services mechanism to locate providers.
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.hk2/osgi-resource-locator/1.0.3/de3b21279df7e755e38275137539be5e2c80dd58/osgi-resource-locator-1.0.3.jar
MD5: e7e82b82118c5387ae45f7bf3892909b
SHA1: de3b21279df7e755e38275137539be5e2c80dd58
SHA256: aab5d7849f7cfcda2cc7c541ba1bd365151d42276f151c825387245dfde3dd74
Referenced In Project/Scope: server-start:webapps
osgi-resource-locator-1.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name osgi-resource-locator High
Vendor gradle artifactid osgi-resource-locator Highest
Vendor gradle groupid org.glassfish.hk2 Highest
Vendor jar package name glassfish Highest
Vendor jar package name hk2 Highest
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.hk2.osgi-resource-locator Medium
Vendor pom artifactid osgi-resource-locator Low
Vendor pom developer id ss141213 Medium
Vendor pom developer name Sahoo Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom groupid org.glassfish.hk2 Highest
Vendor pom name OSGi resource locator High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name osgi-resource-locator High
Product gradle artifactid osgi-resource-locator Highest
Product jar package name glassfish Highest
Product jar package name hk2 Highest
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name OSGi resource locator Medium
Product Manifest bundle-symbolicname org.glassfish.hk2.osgi-resource-locator Medium
Product pom artifactid osgi-resource-locator Highest
Product pom developer id ss141213 Low
Product pom developer name Sahoo Low
Product pom developer org Oracle Corporation Low
Product pom groupid org.glassfish.hk2 Highest
Product pom name OSGi resource locator High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 1.0.3 High
Version gradle version 1.0.3 Highest
Version Manifest Bundle-Version 1.0.3 High
Version pom parent-version 1.0.3 Low
Version pom version 1.0.3 Highest
pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.3
(Confidence :High)
pcap4j-core-1.8.2.jar
Description:
The core module of Pcap4J.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.pcap4j/pcap4j-core/1.8.2/41ea7a197f1ddd2dc4a267276f900187e6642c61/pcap4j-core-1.8.2.jar
MD5: d4a4114ecf9a5e818eec76bcb66cc322
SHA1: 41ea7a197f1ddd2dc4a267276f900187e6642c61
SHA256: 3153208d0212ed818705802fe44e851aec5063a4527075a66043f71c7363160a
Referenced In Project/Scope: server-start:runtimeClasspath
pcap4j-core-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name pcap4j-core High
Vendor gradle artifactid pcap4j-core Highest
Vendor gradle groupid org.pcap4j Highest
Vendor jar package name core Highest
Vendor jar package name packet Low
Vendor jar package name pcap4j Highest
Vendor jar package name pcap4j Low
Vendor pom artifactid pcap4j-core Low
Vendor pom groupid org.pcap4j Highest
Vendor pom name Pcap4J Core High
Vendor pom parent-artifactid pcap4j Low
Product file name pcap4j-core High
Product gradle artifactid pcap4j-core Highest
Product jar package name core Highest
Product jar package name packet Low
Product jar package name pcap4j Highest
Product pom artifactid pcap4j-core Highest
Product pom groupid org.pcap4j Highest
Product pom name Pcap4J Core High
Product pom parent-artifactid pcap4j Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version pom version 1.8.2 Highest
pkg:maven/org.pcap4j/pcap4j-core@1.8.2
(Confidence :High)
pcap4j-packetfactory-static-1.8.2.jar
Description:
Static implementations of Pcap4J packet factory.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.pcap4j/pcap4j-packetfactory-static/1.8.2/7e1ebc403dcfbb6e6f9d11e6f156285178f4cff5/pcap4j-packetfactory-static-1.8.2.jar
MD5: 5712ddc3fb992dfdbdcbef274657068f
SHA1: 7e1ebc403dcfbb6e6f9d11e6f156285178f4cff5
SHA256: 5946006b70d5811cbef1e5808f8d51b4f22a725fecb48274b87a668d3c9b1237
Referenced In Project/Scope: server-start:runtimeClasspath
pcap4j-packetfactory-static-1.8.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name pcap4j-packetfactory-static High
Vendor gradle artifactid pcap4j-packetfactory-static Highest
Vendor gradle groupid org.pcap4j Highest
Vendor jar package name factory Highest
Vendor jar package name factory Low
Vendor jar package name packet Highest
Vendor jar package name packet Low
Vendor jar package name pcap4j Highest
Vendor jar package name pcap4j Low
Vendor pom artifactid pcap4j-packetfactory-static Low
Vendor pom groupid org.pcap4j Highest
Vendor pom name Pcap4J Static Packet Factory High
Vendor pom parent-artifactid pcap4j Low
Product file name pcap4j-packetfactory-static High
Product gradle artifactid pcap4j-packetfactory-static Highest
Product jar package name factory Highest
Product jar package name factory Low
Product jar package name packet Highest
Product jar package name packet Low
Product jar package name pcap4j Highest
Product jar package name statik Low
Product pom artifactid pcap4j-packetfactory-static Highest
Product pom groupid org.pcap4j Highest
Product pom name Pcap4J Static Packet Factory High
Product pom parent-artifactid pcap4j Medium
Version file version 1.8.2 High
Version gradle version 1.8.2 Highest
Version pom version 1.8.2 Highest
pkg:maven/org.pcap4j/pcap4j-packetfactory-static@1.8.2
(Confidence :High)
pdfbox-2.0.27.jar
Description:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.pdfbox/pdfbox/2.0.27/416a9dfce3714116bfdf793b15368df04266845f/pdfbox-2.0.27.jar
MD5: ddd46402b1692eed9e5c73b4a94c45d8
SHA1: 416a9dfce3714116bfdf793b15368df04266845f
SHA256: a25ad2a0be6b0bf9eb0e972abd09c34c0e797a3ce2a980d5ff035ff4cf078037
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
pdfbox-2.0.27.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name pdfbox High
Vendor gradle artifactid pdfbox Highest
Vendor gradle groupid org.apache.pdfbox Highest
Vendor jar package name apache Highest
Vendor jar package name pdfbox Highest
Vendor Manifest automatic-module-name org.apache.pdfbox Medium
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium
Vendor Manifest implementation-url https://www.apache.org/pdfbox-parent/pdfbox/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid pdfbox Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor pom name Apache PDFBox High
Vendor pom parent-artifactid pdfbox-parent Low
Product file name pdfbox High
Product gradle artifactid pdfbox Highest
Product jar package name apache Highest
Product jar package name pdfbox Highest
Product Manifest automatic-module-name org.apache.pdfbox Medium
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product Manifest Bundle-Name Apache PDFBox Medium
Product Manifest bundle-symbolicname org.apache.pdfbox Medium
Product Manifest Implementation-Title Apache PDFBox High
Product Manifest implementation-url https://www.apache.org/pdfbox-parent/pdfbox/ Low
Product Manifest specification-title Apache PDFBox Medium
Product pom artifactid pdfbox Highest
Product pom groupid org.apache.pdfbox Highest
Product pom name Apache PDFBox High
Product pom parent-artifactid pdfbox-parent Medium
Version file version 2.0.27 High
Version gradle version 2.0.27 Highest
Version Manifest Bundle-Version 2.0.27 High
Version Manifest Implementation-Version 2.0.27 High
Version pom version 2.0.27 Highest
CVE-2026-23907 suppress
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should
review it to ensure that the extraction path is acceptable. The example
has been changed accordingly, now the initial path and the extraction
paths are converted into canonical paths and it is verified that
extraction path contains the initial path. The documentation has also
been adjusted.
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33929 suppress
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.
Users are recommended to update to version 2.0.37 or 3.0.8 once
available. Until then, they should apply the fix provided in GitHub PR
427.
The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. "/home/ABCDEF".
Users who have copied this example into their production code should apply the mentioned change. The example
has been changed accordingly and is available in the project repository.
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: MEDIUM (4.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
ph-collection-9.5.3.jar
Description:
Special Java 1.8+ Library with extended collection related functionality
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.helger/ph-collection/9.5.3/90e10b9eda9ad8cd01537b93b5658afd07f75845/ph-collection-9.5.3.jar
MD5: 0bccb9086fcf9641cbdb3a9f9dda4dc7
SHA1: 90e10b9eda9ad8cd01537b93b5658afd07f75845
SHA256: 92ed1bdae6af22f30573c3cf680bbb83976aa57737719c8ac8505170d1888ee5
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ph-collection-9.5.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ph-collection High
Vendor gradle artifactid ph-collection Highest
Vendor gradle groupid com.helger Highest
Vendor jar package name collection Highest
Vendor jar package name helger Highest
Vendor Manifest automatic-module-name com.helger.collection Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://www.helger.com Low
Vendor Manifest bundle-symbolicname com.helger.ph-collection Medium
Vendor Manifest Implementation-Vendor Philip Helger High
Vendor pom artifactid ph-collection Low
Vendor pom developer email ph(at)helger.com Low
Vendor pom developer id philip Medium
Vendor pom developer name Philip Helger Medium
Vendor pom groupid com.helger Highest
Vendor pom name ph-collection High
Vendor pom organization name Philip Helger High
Vendor pom organization url http://www.helger.com Medium
Vendor pom parent-artifactid ph-commons-parent-pom Low
Vendor pom url phax/ph-commons/ph-collection Highest
Product file name ph-collection High
Product gradle artifactid ph-collection Highest
Product jar package name collection Highest
Product jar package name helger Highest
Product Manifest automatic-module-name com.helger.collection Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://www.helger.com Low
Product Manifest Bundle-Name ph-collection Medium
Product Manifest bundle-symbolicname com.helger.ph-collection Medium
Product Manifest Implementation-Title ph-collection High
Product pom artifactid ph-collection Highest
Product pom developer email ph(at)helger.com Low
Product pom developer id philip Low
Product pom developer name Philip Helger Low
Product pom groupid com.helger Highest
Product pom name ph-collection High
Product pom organization name Philip Helger Low
Product pom organization url http://www.helger.com Low
Product pom parent-artifactid ph-commons-parent-pom Medium
Product pom url phax/ph-commons/ph-collection High
Version file version 9.5.3 High
Version gradle version 9.5.3 Highest
Version Manifest Bundle-Version 9.5.3 High
Version Manifest Implementation-Version 9.5.3 High
Version pom version 9.5.3 Highest
pkg:maven/com.helger/ph-collection@9.5.3
(Confidence :High)
ph-commons-9.5.3.jar
Description:
Java 1.8+ Library with tons of utility classes required in all projects
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.helger/ph-commons/9.5.3/14b497d03f66a2d667e080b6a12000d562569ca4/ph-commons-9.5.3.jar
MD5: df4a5aed8ab52a62393bc0ae1da5fd56
SHA1: 14b497d03f66a2d667e080b6a12000d562569ca4
SHA256: 4cdb29e214e524b76a88b142bd5f26ffd433bbd67ea94d948ed340c37d48b7a6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ph-commons-9.5.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ph-commons High
Vendor gradle artifactid ph-commons Highest
Vendor gradle groupid com.helger Highest
Vendor jar package name commons Highest
Vendor jar package name helger Highest
Vendor Manifest automatic-module-name com.helger.commons Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://www.helger.com Low
Vendor Manifest bundle-symbolicname com.helger.ph-commons Medium
Vendor Manifest Implementation-Vendor Philip Helger High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.equals.IEqualsImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.hashcode.IHashCodeImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.serialize.convert.ISerializationConverterRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.thirdparty.IThirdPartyModuleProviderSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.typeconvert.ITypeConverterRegistrarSPI" Low
Vendor pom artifactid ph-commons Low
Vendor pom developer email ph(at)helger.com Low
Vendor pom developer id philip Medium
Vendor pom developer name Philip Helger Medium
Vendor pom groupid com.helger Highest
Vendor pom name ph-commons High
Vendor pom organization name Philip Helger High
Vendor pom organization url http://www.helger.com Medium
Vendor pom parent-artifactid ph-commons-parent-pom Low
Vendor pom url phax/ph-commons/ph-commons Highest
Product file name ph-commons High
Product gradle artifactid ph-commons Highest
Product jar package name commons Highest
Product jar package name convert Highest
Product jar package name equals Highest
Product jar package name hashcode Highest
Product jar package name helger Highest
Product jar package name http Highest
Product jar package name iequalsimplementationregistrarspi Highest
Product jar package name ihashcodeimplementationregistrarspi Highest
Product jar package name ithirdpartymoduleproviderspi Highest
Product jar package name itypeconverterregistrarspi Highest
Product jar package name serialize Highest
Product jar package name thirdparty Highest
Product jar package name typeconvert Highest
Product Manifest automatic-module-name com.helger.commons Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://www.helger.com Low
Product Manifest Bundle-Name ph-commons Medium
Product Manifest bundle-symbolicname com.helger.ph-commons Medium
Product Manifest Implementation-Title ph-commons High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.equals.IEqualsImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.hashcode.IHashCodeImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.serialize.convert.ISerializationConverterRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.thirdparty.IThirdPartyModuleProviderSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.typeconvert.ITypeConverterRegistrarSPI" Low
Product pom artifactid ph-commons Highest
Product pom developer email ph(at)helger.com Low
Product pom developer id philip Low
Product pom developer name Philip Helger Low
Product pom groupid com.helger Highest
Product pom name ph-commons High
Product pom organization name Philip Helger Low
Product pom organization url http://www.helger.com Low
Product pom parent-artifactid ph-commons-parent-pom Medium
Product pom url phax/ph-commons/ph-commons High
Version file version 9.5.3 High
Version gradle version 9.5.3 Highest
Version Manifest Bundle-Version 9.5.3 High
Version Manifest Implementation-Version 9.5.3 High
Version pom version 9.5.3 Highest
pkg:maven/com.helger/ph-commons@9.5.3
(Confidence :High)
ph-jaxb-9.5.3.jar
Description:
Special Java 1.8+ Library with extended JAXB support
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.helger/ph-jaxb/9.5.3/5502ac6becf016e7208b50147df3ec9a20a7d25f/ph-jaxb-9.5.3.jar
MD5: 2c81bba0c8be441c34e58da3a7d1fe13
SHA1: 5502ac6becf016e7208b50147df3ec9a20a7d25f
SHA256: d7dc12a9ab60fdff97164d96126642557a381906af563304862dcbf56c775024
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ph-jaxb-9.5.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ph-jaxb High
Vendor gradle artifactid ph-jaxb Highest
Vendor gradle groupid com.helger Highest
Vendor jar package name helger Highest
Vendor jar package name jaxb Highest
Vendor Manifest automatic-module-name com.helger.jaxb Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://www.helger.com Low
Vendor Manifest bundle-symbolicname com.helger.ph-jaxb Medium
Vendor Manifest Implementation-Vendor Philip Helger High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.equals.IEqualsImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.hashcode.IHashCodeImplementationRegistrarSPI" Low
Vendor pom artifactid ph-jaxb Low
Vendor pom developer email ph(at)helger.com Low
Vendor pom developer id philip Medium
Vendor pom developer name Philip Helger Medium
Vendor pom groupid com.helger Highest
Vendor pom name ph-jaxb High
Vendor pom organization name Philip Helger High
Vendor pom organization url http://www.helger.com Medium
Vendor pom parent-artifactid ph-commons-parent-pom Low
Vendor pom url phax/ph-commons/ph-jaxb Highest
Product file name ph-jaxb High
Product gradle artifactid ph-jaxb Highest
Product jar package name helger Highest
Product jar package name jaxb Highest
Product Manifest automatic-module-name com.helger.jaxb Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://www.helger.com Low
Product Manifest Bundle-Name ph-jaxb Medium
Product Manifest bundle-symbolicname com.helger.ph-jaxb Medium
Product Manifest Implementation-Title ph-jaxb High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.equals.IEqualsImplementationRegistrarSPI",osgi.serviceloader;osgi.serviceloader="com.helger.commons.hashcode.IHashCodeImplementationRegistrarSPI" Low
Product pom artifactid ph-jaxb Highest
Product pom developer email ph(at)helger.com Low
Product pom developer id philip Low
Product pom developer name Philip Helger Low
Product pom groupid com.helger Highest
Product pom name ph-jaxb High
Product pom organization name Philip Helger Low
Product pom organization url http://www.helger.com Low
Product pom parent-artifactid ph-commons-parent-pom Medium
Product pom url phax/ph-commons/ph-jaxb High
Version file version 9.5.3 High
Version gradle version 9.5.3 Highest
Version Manifest Bundle-Version 9.5.3 High
Version Manifest Implementation-Version 9.5.3 High
Version pom version 9.5.3 Highest
pkg:maven/com.helger/ph-jaxb@9.5.3
(Confidence :High)
ph-schematron-5.6.5.jar
Description:
Library for validating XML documents with Schematron
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.helger/ph-schematron/5.6.5/99c2597059f34ae75fb227702bf2c67808249150/ph-schematron-5.6.5.jar
MD5: 01b2fcfe64c3b651bf7d599005629591
SHA1: 99c2597059f34ae75fb227702bf2c67808249150
SHA256: 7709f024fe5064034f12179ff45b618e413c80bfe66da7a485ca005a64ac9ba8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ph-schematron-5.6.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ph-schematron High
Vendor gradle artifactid ph-schematron Highest
Vendor gradle groupid com.helger Highest
Vendor jar package name helger Highest
Vendor jar package name schematron Highest
Vendor Manifest automatic-module-name com.helger.schematron Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://www.helger.com Low
Vendor Manifest bundle-symbolicname com.helger.ph-schematron Medium
Vendor Manifest Implementation-Vendor Philip Helger High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.thirdparty.IThirdPartyModuleProviderSPI" Low
Vendor pom artifactid ph-schematron Low
Vendor pom developer email ph(at)helger.com Low
Vendor pom developer id philip Medium
Vendor pom developer name Philip Helger Medium
Vendor pom groupid com.helger Highest
Vendor pom name ph-schematron High
Vendor pom organization name Philip Helger High
Vendor pom organization url http://www.helger.com Medium
Vendor pom parent-artifactid ph-schematron-parent-pom Low
Vendor pom url phax/ph-schematron/ph-schematron Highest
Product file name ph-schematron High
Product gradle artifactid ph-schematron Highest
Product jar package name helger Highest
Product jar package name schematron Highest
Product Manifest automatic-module-name com.helger.schematron Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://www.helger.com Low
Product Manifest Bundle-Name ph-schematron Medium
Product Manifest bundle-symbolicname com.helger.ph-schematron Medium
Product Manifest Implementation-Title ph-schematron High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.commons.thirdparty.IThirdPartyModuleProviderSPI" Low
Product pom artifactid ph-schematron Highest
Product pom developer email ph(at)helger.com Low
Product pom developer id philip Low
Product pom developer name Philip Helger Low
Product pom groupid com.helger Highest
Product pom name ph-schematron High
Product pom organization name Philip Helger Low
Product pom organization url http://www.helger.com Low
Product pom parent-artifactid ph-schematron-parent-pom Medium
Product pom url phax/ph-schematron/ph-schematron High
Version file version 5.6.5 High
Version gradle version 5.6.5 Highest
Version Manifest Bundle-Version 5.6.5 High
Version Manifest Implementation-Version 5.6.5 High
Version pom version 5.6.5 Highest
pkg:maven/com.helger/ph-schematron@5.6.5
(Confidence :High)
ph-xml-9.5.3.jar
Description:
Java 1.8+ Library with XML handling routines
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.helger/ph-xml/9.5.3/52ed46218290a1cf5aae3828b8047cfc5f7cfa8c/ph-xml-9.5.3.jar
MD5: 4f66b4633e886ece2f88cf86ddceb0f1
SHA1: 52ed46218290a1cf5aae3828b8047cfc5f7cfa8c
SHA256: 2b0091cec2ac3f1553b52f64b501dea0b07a5d6ae0ac1ca49217d37543bd05fa
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
ph-xml-9.5.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name ph-xml High
Vendor gradle artifactid ph-xml Highest
Vendor gradle groupid com.helger Highest
Vendor jar package name helger Highest
Vendor jar package name xml Highest
Vendor Manifest automatic-module-name com.helger.xml Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://www.helger.com Low
Vendor Manifest bundle-symbolicname com.helger.ph-xml Medium
Vendor Manifest Implementation-Vendor Philip Helger High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.xml.microdom.convert.IMicroTypeConverterRegistrarSPI" Low
Vendor pom artifactid ph-xml Low
Vendor pom developer email ph(at)helger.com Low
Vendor pom developer id philip Medium
Vendor pom developer name Philip Helger Medium
Vendor pom groupid com.helger Highest
Vendor pom name ph-xml High
Vendor pom organization name Philip Helger High
Vendor pom organization url http://www.helger.com Medium
Vendor pom parent-artifactid ph-commons-parent-pom Low
Vendor pom url phax/ph-commons/ph-xml Highest
Product file name ph-xml High
Product gradle artifactid ph-xml Highest
Product jar package name convert Highest
Product jar package name helger Highest
Product jar package name microdom Highest
Product jar package name xml Highest
Product Manifest automatic-module-name com.helger.xml Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://www.helger.com Low
Product Manifest Bundle-Name ph-xml Medium
Product Manifest bundle-symbolicname com.helger.ph-xml Medium
Product Manifest Implementation-Title ph-xml High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="com.helger.xml.microdom.convert.IMicroTypeConverterRegistrarSPI" Low
Product pom artifactid ph-xml Highest
Product pom developer email ph(at)helger.com Low
Product pom developer id philip Low
Product pom developer name Philip Helger Low
Product pom groupid com.helger Highest
Product pom name ph-xml High
Product pom organization name Philip Helger Low
Product pom organization url http://www.helger.com Low
Product pom parent-artifactid ph-commons-parent-pom Medium
Product pom url phax/ph-commons/ph-xml High
Version file version 9.5.3 High
Version gradle version 9.5.3 Highest
Version Manifest Bundle-Version 9.5.3 High
Version Manifest Implementation-Version 9.5.3 High
Version pom version 9.5.3 Highest
pkg:maven/com.helger/ph-xml@9.5.3
(Confidence :High)
plc4j-api-0.13.1.jar
Description:
Central API Module.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-api/0.13.1/d10d0f9d0336924add33bac58da572f598efb97d/plc4j-api-0.13.1.jar
MD5: 382f142fe65b15fa2ae19a0ae6b57f3b
SHA1: d10d0f9d0336924add33bac58da572f598efb97d
SHA256: a6914cfa605db12007495be47aaca49ce5abbc8682045c5258706b8365847096
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
plc4j-api-0.13.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-api High
Vendor gradle artifactid plc4j-api Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name api Highest
Vendor jar package name plc4x Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-api Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid plc4j-api Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: API High
Vendor pom parent-artifactid plc4j Low
Product file name plc4j-api High
Product gradle artifactid plc4j-api Highest
Product jar package name apache Highest
Product jar package name api Highest
Product jar package name plc4x Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: API Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-api Medium
Product Manifest Implementation-Title PLC4J: API High
Product Manifest specification-title PLC4J: API Medium
Product pom artifactid plc4j-api Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: API High
Product pom parent-artifactid plc4j Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-driver-modbus-0.13.1.jar
Description:
Implementation of a PLC4X driver for the Modbus protocol.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-driver-modbus/0.13.1/a809151aac4206c9f0e3f0bc3841686188247031/plc4j-driver-modbus-0.13.1.jar
MD5: 3160329cb3531551b2111f87c5439d3f
SHA1: a809151aac4206c9f0e3f0bc3841686188247031
SHA256: c2396650c12339b43c22a51b69ac546542bc037945dc6d8a4a0eea9d90085c10
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-driver-modbus-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-driver-modbus High
Vendor gradle artifactid plc4j-driver-modbus Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name modbus Highest
Vendor jar package name plc4x Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-modbus Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid plc4j-driver-modbus Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Driver: Modbus High
Vendor pom parent-artifactid plc4j-drivers Low
Product file name plc4j-driver-modbus High
Product gradle artifactid plc4j-driver-modbus Highest
Product jar package name apache Highest
Product jar package name modbus Highest
Product jar package name plc4x Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Driver: Modbus Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-modbus Medium
Product Manifest Implementation-Title PLC4J: Driver: Modbus High
Product Manifest specification-title PLC4J: Driver: Modbus Medium
Product pom artifactid plc4j-driver-modbus Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Driver: Modbus High
Product pom parent-artifactid plc4j-drivers Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-driver-opcua-0.13.1.jar
Description:
Implementation of a PLC4X driver able to speak with devices using the OPC UA protocol.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-driver-opcua/0.13.1/c7a03d748fc9271bae53408622af2a21c18a2681/plc4j-driver-opcua-0.13.1.jar
MD5: 9879f511872a6271a932ffb30bef57ba
SHA1: c7a03d748fc9271bae53408622af2a21c18a2681
SHA256: 7c1c1acfcac2f5a57b64e69b187eaf4ac3eb434116311563600cd21169986216
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-driver-opcua-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-driver-opcua High
Vendor gradle artifactid plc4j-driver-opcua Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name opcua Highest
Vendor jar package name plc4x Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-opcua Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid plc4j-driver-opcua Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Driver: OPC UA High
Vendor pom parent-artifactid plc4j-drivers Low
Product file name plc4j-driver-opcua High
Product gradle artifactid plc4j-driver-opcua Highest
Product jar package name apache Highest
Product jar package name opcua Highest
Product jar package name plc4x Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Driver: OPC UA Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-opcua Medium
Product Manifest Implementation-Title PLC4J: Driver: OPC UA High
Product Manifest specification-title PLC4J: Driver: OPC UA Medium
Product pom artifactid plc4j-driver-opcua Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Driver: OPC UA High
Product pom parent-artifactid plc4j-drivers Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-driver-s7-0.13.1.jar
Description:
Implementation of a PLC4X driver for the classic Step7 S7 protocol.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-driver-s7/0.13.1/81081ab54696f78ca67138da412c381fdee816c4/plc4j-driver-s7-0.13.1.jar
MD5: 3ee1ff1d84d7b52505cf4bd309eee2ef
SHA1: 81081ab54696f78ca67138da412c381fdee816c4
SHA256: 7be84d58e3f06666df63ed64e55821153bf663c3d4c5855d846a7617b0dcc89a
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-driver-s7-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-driver-s7 High
Vendor gradle artifactid plc4j-driver-s7 Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name plc4x Highest
Vendor jar package name s7 Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-s7 Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest spi-consumer * Low
Vendor pom artifactid plc4j-driver-s7 Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Driver: S7 High
Vendor pom parent-artifactid plc4j-drivers Low
Product file name plc4j-driver-s7 High
Product gradle artifactid plc4j-driver-s7 Highest
Product jar package name apache Highest
Product jar package name plc4x Highest
Product jar package name s7 Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Driver: S7 Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-driver-s7 Medium
Product Manifest Implementation-Title PLC4J: Driver: S7 High
Product Manifest specification-title PLC4J: Driver: S7 Medium
Product Manifest spi-consumer * Low
Product pom artifactid plc4j-driver-s7 Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Driver: S7 High
Product pom parent-artifactid plc4j-drivers Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-spi-0.13.1.jar
Description:
Internal API Module.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-spi/0.13.1/265dbf39b0585e668f6d216adac6bc749112ca97/plc4j-spi-0.13.1.jar
MD5: 52b382681cbd61779b762cda31712f95
SHA1: 265dbf39b0585e668f6d216adac6bc749112ca97
SHA256: 6117f5cb5ec35493717ac450237f881ef60d80c62e2b4d5746e4b95108fd9481
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-spi-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-spi High
Vendor gradle artifactid plc4j-spi Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name plc4x Highest
Vendor jar package name spi Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-spi Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest spi-consumer * Low
Vendor Manifest spi-provider * Low
Vendor pom artifactid plc4j-spi Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: SPI High
Vendor pom parent-artifactid plc4j Low
Product file name plc4j-spi High
Product gradle artifactid plc4j-spi Highest
Product jar package name apache Highest
Product jar package name plc4x Highest
Product jar package name spi Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: SPI Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-spi Medium
Product Manifest Implementation-Title PLC4J: SPI High
Product Manifest specification-title PLC4J: SPI Medium
Product Manifest spi-consumer * Low
Product Manifest spi-provider * Low
Product pom artifactid plc4j-spi Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: SPI High
Product pom parent-artifactid plc4j Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-transport-tcp-0.13.1.jar
Description:
Base classes needed to implement plc4x drivers based on TCP connections.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-transport-tcp/0.13.1/757c995b142279b6802d08b51ad5e4ba5b0f42be/plc4j-transport-tcp-0.13.1.jar
MD5: 6ed9e9b2b86b019356e48ddfc28bc92c
SHA1: 757c995b142279b6802d08b51ad5e4ba5b0f42be
SHA256: bd34b79592d8f0c0d111a521917d976d2d861e1e6690d37a6971cc98df229d43
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-transport-tcp-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-transport-tcp High
Vendor gradle artifactid plc4j-transport-tcp Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name plc4x Highest
Vendor jar package name transport Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-transport-tcp Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest spi-provider * Low
Vendor pom artifactid plc4j-transport-tcp Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Transports: TCP High
Vendor pom parent-artifactid plc4j-transports Low
Product file name plc4j-transport-tcp High
Product gradle artifactid plc4j-transport-tcp Highest
Product jar package name apache Highest
Product jar package name plc4x Highest
Product jar package name transport Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Transports: TCP Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-transport-tcp Medium
Product Manifest Implementation-Title PLC4J: Transports: TCP High
Product Manifest specification-title PLC4J: Transports: TCP Medium
Product Manifest spi-provider * Low
Product pom artifactid plc4j-transport-tcp Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Transports: TCP High
Product pom parent-artifactid plc4j-transports Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-utils-pcap-shared-0.13.1.jar
Description:
Classes shared between all PCAP related channels.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-utils-pcap-shared/0.13.1/40460a6a1f4e7e49976c2e38255f025121973fa7/plc4j-utils-pcap-shared-0.13.1.jar
MD5: 4234e2cc4e352985a7a3a5c8a6e5a877
SHA1: 40460a6a1f4e7e49976c2e38255f025121973fa7
SHA256: 7b2c7e95618f60c61030ea86d51879ed557a301f92d7661846693eb33b4ab3db
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-utils-pcap-shared-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-utils-pcap-shared High
Vendor gradle artifactid plc4j-utils-pcap-shared Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name plc4x Highest
Vendor jar package name utils Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-utils-pcap-shared Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid plc4j-utils-pcap-shared Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Utils: Pcap (Shared) High
Vendor pom parent-artifactid plc4j-utils Low
Product file name plc4j-utils-pcap-shared High
Product gradle artifactid plc4j-utils-pcap-shared Highest
Product jar package name apache Highest
Product jar package name plc4x Highest
Product jar package name utils Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Utils: Pcap (Shared) Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-utils-pcap-shared Medium
Product Manifest Implementation-Title PLC4J: Utils: Pcap (Shared) High
Product Manifest specification-title PLC4J: Utils: Pcap (Shared) Medium
Product pom artifactid plc4j-utils-pcap-shared Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Utils: Pcap (Shared) High
Product pom parent-artifactid plc4j-utils Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
plc4j-utils-raw-sockets-0.13.1.jar
Description:
An implementation of a Netty Channel that allows implementing protocols below the TCP and UCP level.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.plc4x/plc4j-utils-raw-sockets/0.13.1/9f09d3b4cff1223f4695fbf271e0bab5d5d1d994/plc4j-utils-raw-sockets-0.13.1.jar
MD5: 57eb6d743db0ed70893ef7a68b7ee008
SHA1: 9f09d3b4cff1223f4695fbf271e0bab5d5d1d994
SHA256: 0df7bd6b03ebcb5d019deb1a3610d46a386fc96e2807ec112bb4e9bdca9566ed
Referenced In Project/Scope: server-start:runtimeClasspath
plc4j-utils-raw-sockets-0.13.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name plc4j-utils-raw-sockets High
Vendor gradle artifactid plc4j-utils-raw-sockets Highest
Vendor gradle groupid org.apache.plc4x Highest
Vendor jar package name apache Highest
Vendor jar package name plc4x Highest
Vendor jar package name utils Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.plc4x.plc4j-utils-raw-sockets Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid plc4j-utils-raw-sockets Low
Vendor pom groupid org.apache.plc4x Highest
Vendor pom name PLC4J: Utils: Raw-Sockets High
Vendor pom parent-artifactid plc4j-utils Low
Product file name plc4j-utils-raw-sockets High
Product gradle artifactid plc4j-utils-raw-sockets Highest
Product jar package name apache Highest
Product jar package name plc4x Highest
Product jar package name utils Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name PLC4J: Utils: Raw-Sockets Medium
Product Manifest bundle-symbolicname org.apache.plc4x.plc4j-utils-raw-sockets Medium
Product Manifest Implementation-Title PLC4J: Utils: Raw-Sockets High
Product Manifest specification-title PLC4J: Utils: Raw-Sockets Medium
Product pom artifactid plc4j-utils-raw-sockets Highest
Product pom groupid org.apache.plc4x Highest
Product pom name PLC4J: Utils: Raw-Sockets High
Product pom parent-artifactid plc4j-utils Medium
Version file version 0.13.1 High
Version gradle version 0.13.1 Highest
Version Manifest Bundle-Version 0.13.1 High
Version Manifest Implementation-Version 0.13.1 High
Version pom version 0.13.1 Highest
poi-4.1.2.jar
Description:
Apache POI - Java API To Access Microsoft Format Files
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.poi/poi/4.1.2/964bf41cf68bce08e4ef6b2279b559fdf8d454f4/poi-4.1.2.jar
MD5: e9a7c049c62c41c70354669bcd448212
SHA1: 964bf41cf68bce08e4ef6b2279b559fdf8d454f4
SHA256: ab1612406541968434044b2defad58aa8b657cad073baa22a04faaf9d7fb9d1c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
poi-4.1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name poi High
Vendor gradle artifactid poi Highest
Vendor gradle groupid org.apache.poi Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name poi Highest
Vendor jar package name poi Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid poi Low
Vendor pom groupid org.apache.poi Highest
Vendor pom name Apache POI High
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom url http://poi.apache.org/ Highest
Product file name poi High
Product gradle artifactid poi Highest
Product jar package name apache Highest
Product jar package name poi Highest
Product jar package name poi Low
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product pom artifactid poi Highest
Product pom groupid org.apache.poi Highest
Product pom name Apache POI High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom url http://poi.apache.org/ Medium
Version file version 4.1.2 High
Version gradle version 4.1.2 Highest
Version Manifest Implementation-Version 4.1.2 High
Version pom version 4.1.2 Highest
CVE-2022-26336 suppress
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CWE-20 Improper Input Validation, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-31672 suppress
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry.
This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file.
Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.
CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
poi-ooxml-4.1.2.jar
Description:
Apache POI - Java API To Access Microsoft Format Files
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.poi/poi-ooxml/4.1.2/87d9a22aa9a7dd26e80c360e709f7ee02e32ab3b/poi-ooxml-4.1.2.jar
MD5: c0aa71b597560d29c1d17f7c2adbdff0
SHA1: 87d9a22aa9a7dd26e80c360e709f7ee02e32ab3b
SHA256: 0aaaeeee3f5831b036b7053f8048b0f83aa9fa8897771ffd871ddfc84653eba1
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
poi-ooxml-4.1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name poi-ooxml High
Vendor gradle artifactid poi-ooxml Highest
Vendor gradle groupid org.apache.poi Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name poi Highest
Vendor jar package name poi Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid poi-ooxml Low
Vendor pom groupid org.apache.poi Highest
Vendor pom name Apache POI High
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom url http://poi.apache.org/ Highest
Product file name poi-ooxml High
Product gradle artifactid poi-ooxml Highest
Product jar package name apache Highest
Product jar package name poi Highest
Product jar package name poi Low
Product jar package name usermodel Low
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product pom artifactid poi-ooxml Highest
Product pom groupid org.apache.poi Highest
Product pom name Apache POI High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom url http://poi.apache.org/ Medium
Version file version 4.1.2 High
Version gradle version 4.1.2 Highest
Version Manifest Implementation-Version 4.1.2 High
Version pom version 4.1.2 Highest
CVE-2022-26336 suppress
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CWE-20 Improper Input Validation, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-31672 suppress
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry.
This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file.
Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.
CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
poi-ooxml-schemas-4.1.2.jar
Description:
Apache POI - Java API To Access Microsoft Format Files
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.poi/poi-ooxml-schemas/4.1.2/550cc22a598c0b0a51d1f55f8371e83c1229802d/poi-ooxml-schemas-4.1.2.jar
MD5: 381222563bf1fc4e9c2528acee7f8bf5
SHA1: 550cc22a598c0b0a51d1f55f8371e83c1229802d
SHA256: b4c579f34c377008ec16a5a784539b73776a1dcedf15196f88a80f1b208d9bb2
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
poi-ooxml-schemas-4.1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name poi-ooxml-schemas High
Vendor gradle artifactid poi-ooxml-schemas Highest
Vendor gradle groupid org.apache.poi Highest
Vendor jar package name openxmlformats Low
Vendor jar package name schemas Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid poi-ooxml-schemas Low
Vendor pom groupid org.apache.poi Highest
Vendor pom name Apache POI High
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom url http://poi.apache.org/ Highest
Product file name poi-ooxml-schemas High
Product gradle artifactid poi-ooxml-schemas Highest
Product jar package name schemas Low
Product jar package name x2006 Low
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product pom artifactid poi-ooxml-schemas Highest
Product pom groupid org.apache.poi Highest
Product pom name Apache POI High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom url http://poi.apache.org/ Medium
Version file version 4.1.2 High
Version gradle version 4.1.2 Highest
Version Manifest Implementation-Version 4.1.2 High
Version pom version 4.1.2 Highest
CVE-2022-26336 suppress
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CWE-20 Improper Input Validation, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-31672 suppress
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry.
This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file.
Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.
CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
poi-scratchpad-4.1.2.jar
Description:
Apache POI - Java API To Access Microsoft Format Files
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.poi/poi-scratchpad/4.1.2/1be379e91d3d3fb0cd11425451acdbfb0d2264e7/poi-scratchpad-4.1.2.jar
MD5: 39953af9153a7559a37af717bd34bd8f
SHA1: 1be379e91d3d3fb0cd11425451acdbfb0d2264e7
SHA256: 4ad6a0579a0a216ff951a80f11c648792268189591fe86015b9d197d650424f3
Referenced In Project/Scope: server-start:runtimeClasspath
poi-scratchpad-4.1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name poi-scratchpad High
Vendor gradle artifactid poi-scratchpad Highest
Vendor gradle groupid org.apache.poi Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name poi Highest
Vendor jar package name poi Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid poi-scratchpad Low
Vendor pom groupid org.apache.poi Highest
Vendor pom name Apache POI High
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom url http://poi.apache.org/ Highest
Product file name poi-scratchpad High
Product gradle artifactid poi-scratchpad Highest
Product jar package name apache Highest
Product jar package name poi Highest
Product jar package name poi Low
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product pom artifactid poi-scratchpad Highest
Product pom groupid org.apache.poi Highest
Product pom name Apache POI High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://www.apache.org/ Low
Product pom url http://poi.apache.org/ Medium
Version file version 4.1.2 High
Version gradle version 4.1.2 Highest
Version Manifest Implementation-Version 4.1.2 High
Version pom version 4.1.2 Highest
CVE-2022-26336 suppress
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CWE-20 Improper Input Validation, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-31672 suppress
Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry.
This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file.
Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.
CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
postgresql-42.7.11.jar
Description:
Java JDBC driver for PostgreSQL database
License:
BSD-2-Clause: https://jdbc.postgresql.org/about/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.postgresql/postgresql/42.7.11/4c21cdd1b3938f400703716d37c4e8ca4d332808/postgresql-42.7.11.jar
MD5: b969f87f07d6434bd77cdc5e440da49a
SHA1: 4c21cdd1b3938f400703716d37c4e8ca4d332808
SHA256: 1981b31d3993c58702783c1cddf10a34e48c1f413d70ff1cb6def0a143484647
Referenced In Project/Scope: server-start:runtimeClasspath
postgresql-42.7.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name postgresql High
Vendor gradle artifactid postgresql Highest
Vendor gradle groupid org.postgresql Highest
Vendor jar package name jdbc Highest
Vendor jar package name org Highest
Vendor jar package name postgresql Highest
Vendor jar package name postgresql Low
Vendor Manifest automatic-module-name org.postgresql.jdbc Medium
Vendor Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low
Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low
Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium
Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High
Vendor Manifest Implementation-Vendor-Id org.postgresql Medium
Vendor Manifest multi-release true Low
Vendor Manifest provide-capability osgi.service;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver";effective:=active Low
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor pom artifactid postgresql Low
Vendor pom developer id bokken Medium
Vendor pom developer id davecramer Medium
Vendor pom developer id jurka Medium
Vendor pom developer id oliver Medium
Vendor pom developer id ringerc Medium
Vendor pom developer id sehrope Medium
Vendor pom developer id vlsi Medium
Vendor pom developer name Brett Okken Medium
Vendor pom developer name Craig Ringer Medium
Vendor pom developer name Dave Cramer Medium
Vendor pom developer name Kris Jurka Medium
Vendor pom developer name Oliver Jowett Medium
Vendor pom developer name Sehrope Sarkuni Medium
Vendor pom developer name Vladimir Sitnikov Medium
Vendor pom groupid org.postgresql Highest
Vendor pom name PostgreSQL JDBC Driver High
Vendor pom organization name PostgreSQL Global Development Group High
Vendor pom organization url https://jdbc.postgresql.org/ Medium
Vendor pom url https://jdbc.postgresql.org Highest
Product file name postgresql High
Product gradle artifactid postgresql Highest
Product hint analyzer product pgjdbc Highest
Product hint analyzer product postgresql_jdbc_driver Highest
Product jar package name driver Highest
Product jar package name jdbc Highest
Product jar package name org Highest
Product jar package name osgi Highest
Product jar package name postgresql Highest
Product Manifest automatic-module-name org.postgresql.jdbc Medium
Product Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low
Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low
Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium
Product Manifest bundle-symbolicname org.postgresql.jdbc Medium
Product Manifest Implementation-Title PostgreSQL JDBC Driver High
Product Manifest multi-release true Low
Product Manifest provide-capability osgi.service;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver";effective:=active Low
Product Manifest specification-title JDBC Medium
Product pom artifactid postgresql Highest
Product pom developer id bokken Low
Product pom developer id davecramer Low
Product pom developer id jurka Low
Product pom developer id oliver Low
Product pom developer id ringerc Low
Product pom developer id sehrope Low
Product pom developer id vlsi Low
Product pom developer name Brett Okken Low
Product pom developer name Craig Ringer Low
Product pom developer name Dave Cramer Low
Product pom developer name Kris Jurka Low
Product pom developer name Oliver Jowett Low
Product pom developer name Sehrope Sarkuni Low
Product pom developer name Vladimir Sitnikov Low
Product pom groupid org.postgresql Highest
Product pom name PostgreSQL JDBC Driver High
Product pom organization name PostgreSQL Global Development Group Low
Product pom organization url https://jdbc.postgresql.org/ Low
Product pom url https://jdbc.postgresql.org Medium
Version file version 42.7.11 High
Version gradle version 42.7.11 Highest
Version Manifest Bundle-Version 42.7.11 High
Version Manifest Implementation-Version 42.7.11 High
Version pom version 42.7.11 Highest
pkg:maven/org.postgresql/postgresql@42.7.11
(Confidence :High)
cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.7.11:*:*:*:*:*:*:*
(Confidence :Low)
suppress
profiles-2.26.30.jar
Description:
Profile module allows loading information from AWS configuration and credentials files.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/profiles/2.26.30/850fd9af12bb4d7eb17333ec3bad15a1dbb39ce2/profiles-2.26.30.jar
MD5: 01d60669f513c857eb512eb03ccc6b65
SHA1: 850fd9af12bb4d7eb17333ec3bad15a1dbb39ce2
SHA256: 8072b72423164b147ed6fd6752c4f8b286b5a0d4bfacfd4386f6172a38aabc49
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
profiles-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name profiles High
Vendor gradle artifactid profiles Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name profiles Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.profiles Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid profiles Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Profiles High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name profiles High
Product gradle artifactid profiles Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name profiles Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.profiles Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid profiles Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Profiles High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
protocol-core-2.26.30.jar
Description:
The AWS SDK for Java - module holds the core protocol classes
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/protocol-core/2.26.30/82121695ff6768096adfa6b1c9f589caf5770e05/protocol-core-2.26.30.jar
MD5: 0dd9242faaee1e2a700569b3c14047ea
SHA1: 82121695ff6768096adfa6b1c9f589caf5770e05
SHA256: 4a3b9f390b2a8f1cf350cb5709e0a48714ebd61a062e759d650d9128b4c64afe
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
protocol-core-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name protocol-core High
Vendor gradle artifactid protocol-core Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name protocols Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.protocols.core Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid protocol-core Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Core :: Protocols :: Protocol Core High
Vendor pom parent-artifactid protocols Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name protocol-core High
Product gradle artifactid protocol-core Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name protocols Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.protocols.core Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid protocol-core Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Core :: Protocols :: Protocol Core High
Product pom parent-artifactid protocols Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
prov-1.58.0.0.jar
Description:
Spongy Castle is a package-rename (org.bouncycastle.* to org.spongycastle.*) of Bouncy Castle
intended for the Android platform. Android unfortunately ships with a stripped-down version of
Bouncy Castle, which prevents easy upgrades - Spongy Castle overcomes this and provides a full,
up-to-date version of the Bouncy Castle cryptographic libs.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.madgag.spongycastle/prov/1.58.0.0/2e2c2f624ed91eb40e690e3596c98439b1b50f2a/prov-1.58.0.0.jar
MD5: 52f241c3ee194e3465d07df7aa811952
SHA1: 2e2c2f624ed91eb40e690e3596c98439b1b50f2a
SHA256: 092fd09e7006b0814980513b013d4c2b3ffd24a49a635ab4b2d204bb51af1727
Referenced In Project/Scope: server-start:runtimeClasspath
prov-1.58.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name prov High
Vendor gradle artifactid prov Highest
Vendor gradle groupid com.madgag.spongycastle Highest
Vendor jar package name jcajce Low
Vendor jar package name provider Low
Vendor jar package name spongycastle Low
Vendor pom artifactid prov Low
Vendor pom developer id rtyley Medium
Vendor pom developer name Roberto Tyley Medium
Vendor pom groupid com.madgag.spongycastle Highest
Vendor pom name Spongy Castle High
Vendor pom url http://rtyley.github.io/spongycastle/ Highest
Product file name prov High
Product gradle artifactid prov Highest
Product jar package name jcajce Low
Product jar package name provider Low
Product pom artifactid prov Highest
Product pom developer id rtyley Low
Product pom developer name Roberto Tyley Low
Product pom groupid com.madgag.spongycastle Highest
Product pom name Spongy Castle High
Product pom url http://rtyley.github.io/spongycastle/ Medium
Version file version 1.58.0.0 High
Version gradle version 1.58.0.0 Highest
Version pom version 1.58.0.0 Highest
pkg:maven/com.madgag.spongycastle/prov@1.58.0.0
(Confidence :High)
reactive-streams-1.0.4.jar
Description:
Reactive Streams API
License:
MIT-0: https://spdx.org/licenses/MIT-0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.reactivestreams/reactive-streams/1.0.4/3864a1320d97d7b045f729a326e1e077661f31b7/reactive-streams-1.0.4.jar
MD5: eda7978509c32d99166745cc144c99cd
SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7
SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
reactive-streams-1.0.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name reactive-streams High
Vendor gradle artifactid reactive-streams Highest
Vendor gradle groupid org.reactivestreams Highest
Vendor jar package name reactivestreams Highest
Vendor jar package name reactivestreams Low
Vendor Manifest automatic-module-name org.reactivestreams Medium
Vendor Manifest bundle-docurl http://reactive-streams.org Low
Vendor Manifest bundle-symbolicname reactive-streams Medium
Vendor pom artifactid reactive-streams Low
Vendor pom developer id reactive-streams-sig Medium
Vendor pom developer name Reactive Streams SIG Medium
Vendor pom groupid org.reactivestreams Highest
Vendor pom name reactive-streams High
Vendor pom url http://www.reactive-streams.org/ Highest
Product file name reactive-streams High
Product gradle artifactid reactive-streams Highest
Product jar package name reactivestreams Highest
Product Manifest automatic-module-name org.reactivestreams Medium
Product Manifest bundle-docurl http://reactive-streams.org Low
Product Manifest Bundle-Name reactive-streams-jvm Medium
Product Manifest bundle-symbolicname reactive-streams Medium
Product pom artifactid reactive-streams Highest
Product pom developer id reactive-streams-sig Low
Product pom developer name Reactive Streams SIG Low
Product pom groupid org.reactivestreams Highest
Product pom name reactive-streams High
Product pom url http://www.reactive-streams.org/ Medium
Version file version 1.0.4 High
Version gradle version 1.0.4 Highest
Version Manifest Bundle-Version 1.0.4 High
Version pom version 1.0.4 Highest
pkg:maven/org.reactivestreams/reactive-streams@1.0.4
(Confidence :High)
regions-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/regions/2.26.30/a9bc327804c0314bff7aaa213924317f3d508b3f/regions-2.26.30.jar
MD5: 2b3da2bdaa63e66a39fd70c90c02d066
SHA1: a9bc327804c0314bff7aaa213924317f3d508b3f
SHA256: 3972d21caa5a5e749d929f9c17616feaa6f4ea5b8a063592ad6babc2b85eb5d8
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
regions-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name regions High
Vendor gradle artifactid regions Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name regions Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.regions Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid regions Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Regions High
Vendor pom parent-artifactid core Low
Product file name regions High
Product gradle artifactid regions Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name regions Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.regions Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid regions Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Regions High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
relaxng-datatype-2.3.6.jar
Description:
RelaxNG Datatype library.
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind.external/relaxng-datatype/2.3.6/387d313f5ca5187a14ad7012b46016401afa04ac/relaxng-datatype-2.3.6.jar
MD5: 6759ca81b245658e14338cb62ea1cab7
SHA1: 387d313f5ca5187a14ad7012b46016401afa04ac
SHA256: 1eac743a1be788635698af150928160540ae880acaa57ba2043cea33057976a2
Referenced In Project/Scope: server-start:runtimeClasspath
relaxng-datatype-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name relaxng-datatype High
Vendor gradle artifactid relaxng-datatype Highest
Vendor gradle groupid com.sun.xml.bind.external Highest
Vendor jar package name datatype Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.bind.external.relaxng-datatype Medium
Vendor Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor pom artifactid relaxng-datatype Low
Vendor pom groupid com.sun.xml.bind.external Highest
Vendor pom name RelaxNG Datatype High
Vendor pom parent-artifactid jaxb-external-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name relaxng-datatype High
Product gradle artifactid relaxng-datatype Highest
Product jar package name datatype Highest
Product jar package name sun Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name RelaxNG Datatype Medium
Product Manifest bundle-symbolicname com.sun.xml.bind.external.relaxng-datatype Medium
Product Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Product Manifest Implementation-Title RelaxNG Datatype High
Product pom artifactid relaxng-datatype Highest
Product pom groupid com.sun.xml.bind.external Highest
Product pom name RelaxNG Datatype High
Product pom parent-artifactid jaxb-external-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest Bundle-Version 2.3.6 High
Version Manifest implementation-build-id 2.3.6 Low
Version Manifest Implementation-Version 2.3.6 High
Version pom version 2.3.6 Highest
pkg:maven/com.sun.xml.bind.external/relaxng-datatype@2.3.6
(Confidence :High)
rest-server-1.1.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect/rest-server/1.1.0/66e6f4597e26d8744894cbbd1cefba41a0595e4d/rest-server-1.1.0.jar
MD5: ef0a753db9f130726166b464e29620cd
SHA1: 66e6f4597e26d8744894cbbd1cefba41a0595e4d
SHA256: 16eb587c8fbfe44986590d8540da8477730d508556ed46c53d54a223023061c6
Referenced In Project/Scope: server-start:webapps
rest-server-1.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name rest-server High
Vendor gradle artifactid rest-server Highest
Vendor gradle groupid io.transconnect Highest
Vendor jar package name io Low
Vendor jar package name server Low
Vendor jar package name transconnect Low
Vendor pom artifactid rest-server Low
Vendor pom groupid io.transconnect Highest
Product file name rest-server High
Product gradle artifactid rest-server Highest
Product jar package name api Low
Product jar package name server Low
Product jar package name transconnect Low
Product pom artifactid rest-server Highest
Product pom groupid io.transconnect Highest
Version file version 1.1.0 High
Version gradle version 1.1.0 Highest
Version pom version 1.1.0 Highest
pkg:maven/io.transconnect/rest-server@1.1.0
(Confidence :High)
retries-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/retries/2.26.30/971ff53092bb5fbcf6ffc4b31efed9734e4e161b/retries-2.26.30.jar
MD5: e938688d51f34e75496f60fce3b57f35
SHA1: 971ff53092bb5fbcf6ffc4b31efed9734e4e161b
SHA256: fc36adcf6ff198cc6a6cb11e82782df48bc3ff608d8ce50fc80260d451093664
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
retries-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name retries High
Vendor gradle artifactid retries Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name retries Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.retries Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid retries Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Retries High
Vendor pom parent-artifactid core Low
Product file name retries High
Product gradle artifactid retries Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name retries Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.retries Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid retries Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Retries High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
retries-spi-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/retries-spi/2.26.30/ad09d2d109ccc5ab35668e28897df3fd0d5b129e/retries-spi-2.26.30.jar
MD5: e5bf7d09b4078893659d7fcab2e0f14c
SHA1: ad09d2d109ccc5ab35668e28897df3fd0d5b129e
SHA256: fd4eedc4694d87956e796e7bb492ee4db787be18215460ebebda54a20d0f8f5e
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
retries-spi-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name retries-spi High
Vendor gradle artifactid retries-spi Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name retries Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.retries.api Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid retries-spi Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Retries API High
Vendor pom parent-artifactid core Low
Product file name retries-spi High
Product gradle artifactid retries-spi Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name retries Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.retries.api Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid retries-spi Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Retries API High
Product pom parent-artifactid core Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
retrofit-3.0.0.jar
Description:
A type-safe HTTP client for Android and Java.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.squareup.retrofit2/retrofit/3.0.0/c0cdf6d243c5187732134129fda05a74f9197874/retrofit-3.0.0.jar
MD5: 624b533e1f8ab3e8c52646e89a0503f5
SHA1: c0cdf6d243c5187732134129fda05a74f9197874
SHA256: 69c6a2d3451b6df9549a93fab744094ebf07a4b0ce4f453d6c8f575ef0fec9a1
Referenced In Project/Scope: server-start:runtimeClasspath
retrofit-3.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name retrofit High
Vendor gradle artifactid retrofit Highest
Vendor gradle groupid com.squareup.retrofit2 Highest
Vendor jar package name retrofit2 Highest
Vendor jar package name retrofit2 Low
Vendor Manifest automatic-module-name retrofit2 Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid retrofit Low
Vendor pom developer id square Medium
Vendor pom developer name Square, Inc. Medium
Vendor pom groupid com.squareup.retrofit2 Highest
Vendor pom name Retrofit High
Vendor pom url square/retrofit Highest
Product file name retrofit High
Product gradle artifactid retrofit Highest
Product jar package name retrofit2 Highest
Product Manifest automatic-module-name retrofit2 Medium
Product Manifest multi-release true Low
Product pom artifactid retrofit Highest
Product pom developer id square Low
Product pom developer name Square, Inc. Low
Product pom groupid com.squareup.retrofit2 Highest
Product pom name Retrofit High
Product pom url square/retrofit High
Version file version 3.0.0 High
Version gradle version 3.0.0 Highest
Version pom version 3.0.0 Highest
rngom-2.3.6.jar
Description:
RNGOM is a RelaxNG Object model library (XSOM for RelaxNG).
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.bind.external/rngom/2.3.6/c7deab451abfb2bf648344862d6f441f8c60edb2/rngom-2.3.6.jar
MD5: 6fd73f97be0d61c78d9006ed9ee677cd
SHA1: c7deab451abfb2bf648344862d6f441f8c60edb2
SHA256: 4a1ea44a51f4f07cde6a46255ebb4aefdb3e5db1a5553fc3401fa7d130965baf
Referenced In Project/Scope: server-start:runtimeClasspath
rngom-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name rngom High
Vendor gradle artifactid rngom Highest
Vendor gradle groupid com.sun.xml.bind.external Highest
Vendor jar package name rngom Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.bind.external.rngom Medium
Vendor Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor pom artifactid rngom Low
Vendor pom groupid com.sun.xml.bind.external Highest
Vendor pom name RNGOM High
Vendor pom parent-artifactid jaxb-external-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name rngom High
Product gradle artifactid rngom Highest
Product jar package name rngom Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name RNGOM Medium
Product Manifest bundle-symbolicname com.sun.xml.bind.external.rngom Medium
Product Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Product Manifest Implementation-Title RNGOM High
Product pom artifactid rngom Highest
Product pom groupid com.sun.xml.bind.external Highest
Product pom name RNGOM High
Product pom parent-artifactid jaxb-external-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest Bundle-Version 2.3.6 High
Version Manifest implementation-build-id 2.3.6 Low
Version Manifest Implementation-Version 2.3.6 High
Version pom version 2.3.6 Highest
pkg:maven/com.sun.xml.bind.external/rngom@2.3.6
(Confidence :High)
rxjava-2.2.5.jar
Description:
Reactive Extensions for Java
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.reactivex.rxjava2/rxjava/2.2.5/11ec7126adf26d2259e9239563dab9aa3e3812b2/rxjava-2.2.5.jar
MD5: f9a4eef5d811f6e1a90a573af567bc87
SHA1: 11ec7126adf26d2259e9239563dab9aa3e3812b2
SHA256: 73310cb477df582c3ee8677af6ded4b03ec496b23112cceaf749f7732c39f878
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
rxjava-2.2.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name rxjava High
Vendor gradle artifactid rxjava Highest
Vendor gradle groupid io.reactivex.rxjava2 Highest
Vendor jar package name internal Low
Vendor jar package name io Highest
Vendor jar package name io Low
Vendor jar package name reactivex Highest
Vendor jar package name reactivex Low
Vendor Manifest automatic-module-name io.reactivex.rxjava2 Medium
Vendor Manifest bundle-docurl https://github.com/ReactiveX/RxJava Low
Vendor Manifest bundle-symbolicname io.reactivex.rxjava2.rxjava Medium
Vendor Manifest eclipse-extensibleapi true Low
Vendor pom artifactid rxjava Low
Vendor pom developer email akarnokd@gmail.com Low
Vendor pom developer id akarnokd Medium
Vendor pom developer name David Karnok Medium
Vendor pom groupid io.reactivex.rxjava2 Highest
Vendor pom name RxJava High
Vendor pom url ReactiveX/RxJava Highest
Product file name rxjava High
Product gradle artifactid rxjava Highest
Product jar package name internal Low
Product jar package name io Highest
Product jar package name operators Low
Product jar package name reactivex Highest
Product jar package name reactivex Low
Product Manifest automatic-module-name io.reactivex.rxjava2 Medium
Product Manifest bundle-docurl https://github.com/ReactiveX/RxJava Low
Product Manifest Bundle-Name rxjava Medium
Product Manifest bundle-symbolicname io.reactivex.rxjava2.rxjava Medium
Product Manifest eclipse-extensibleapi true Low
Product pom artifactid rxjava Highest
Product pom developer email akarnokd@gmail.com Low
Product pom developer id akarnokd Low
Product pom developer name David Karnok Low
Product pom groupid io.reactivex.rxjava2 Highest
Product pom name RxJava High
Product pom url ReactiveX/RxJava High
Version file version 2.2.5 High
Version gradle version 2.2.5 Highest
Version Manifest Bundle-Version 2.2.5 High
Version pom version 2.2.5 Highest
pkg:maven/io.reactivex.rxjava2/rxjava@2.2.5
(Confidence :High)
s3-2.26.30.jar
Description:
The AWS Java SDK for Amazon S3 module holds the client classes that are used for communicating with
Amazon Simple Storage Service
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/s3/2.26.30/bd402af42a8c3afc19e7a1fc725e30c8155495cb/s3-2.26.30.jar
MD5: 61eeaf05a3295c32b2333a854ee4fc58
SHA1: bd402af42a8c3afc19e7a1fc725e30c8155495cb
SHA256: 1567c896dcce112d02ffb6f998348fbba5ddda8cf7b03e8a3e637ec22c4bacae
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
s3-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name s3 High
Vendor gradle artifactid s3 Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name services Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.services.s3 Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid s3 Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Services :: Amazon S3 High
Vendor pom parent-artifactid services Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name s3 High
Product gradle artifactid s3 Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name services Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.services.s3 Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid s3 Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Services :: Amazon S3 High
Product pom parent-artifactid services Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
saaj-impl-3.0.4.jar
Description:
Implementation of Jakarta SOAP with Attachments Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.sun.xml.messaging.saaj/saaj-impl/3.0.4/20e94bac120c14b7a0aa32c0821bab62515fd7dd/saaj-impl-3.0.4.jar
MD5: 431f6e2296a8961892995aa5ff82f522
SHA1: 20e94bac120c14b7a0aa32c0821bab62515fd7dd
SHA256: a5e4766febf01e384e1803bc30b658e82403d0fac6f0cfee4edfc1ad1e21a908
Referenced In Project/Scope: server-start:webapps
saaj-impl-3.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name saaj-impl High
Vendor gradle artifactid saaj-impl Highest
Vendor gradle groupid com.sun.xml.messaging.saaj Highest
Vendor jar package name messaging Highest
Vendor jar package name saaj Highest
Vendor jar package name sun Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname com.sun.xml.messaging.saaj.impl Medium
Vendor Manifest implementation-build-id 3.0.4 - fc1a51b Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.MessageFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SAAJMetaFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SOAPConnectionFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SOAPFactory" Low
Vendor pom artifactid saaj-impl Low
Vendor pom groupid com.sun.xml.messaging.saaj Highest
Vendor pom name Jakarta SOAP Implementation High
Vendor pom parent-artifactid metro-saaj Low
Product file name saaj-impl High
Product gradle artifactid saaj-impl Highest
Product jar package name messaging Highest
Product jar package name saaj Highest
Product jar package name sun Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta SOAP Implementation Medium
Product Manifest bundle-symbolicname com.sun.xml.messaging.saaj.impl Medium
Product Manifest implementation-build-id 3.0.4 - fc1a51b Low
Product Manifest Implementation-Title Jakarta SOAP Implementation High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.MessageFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SAAJMetaFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SOAPConnectionFactory",osgi.serviceloader;osgi.serviceloader="jakarta.xml.soap.SOAPFactory" Low
Product pom artifactid saaj-impl Highest
Product pom groupid com.sun.xml.messaging.saaj Highest
Product pom name Jakarta SOAP Implementation High
Product pom parent-artifactid metro-saaj Medium
Version file version 3.0.4 High
Version gradle version 3.0.4 Highest
Version Manifest Bundle-Version 3.0.4 High
Version Manifest implementation-build-id 3.0.4 Low
Version Manifest Implementation-Version 3.0.4 High
Version pom version 3.0.4 Highest
pkg:maven/com.sun.xml.messaging.saaj/saaj-impl@3.0.4
(Confidence :High)
sample-connector-1.0.0-classes.jar
Description:
Sample connector implementation demonstrating TRANSCONNECT Connector SDK usage
License:
MIT License: https://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/8b455f512e2b04294fab25bf4d226a025cce6c43/sample-connector-1.0.0-classes.jar
MD5: 9e65e5c3fca6ce5ffbf8420bc854b423
SHA1: 8b455f512e2b04294fab25bf4d226a025cce6c43
SHA256: 0413bb266f556aad6969e581e614005ac1d239971327221825dff52a6db4a01c
Referenced In Project/Scope: server-start:compileClasspath
sample-connector-1.0.0-classes.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sample-connector High
Vendor gradle artifactid sample-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Vendor pom artifactid sample-connector Low
Vendor pom developer email development@transconnect.io Low
Vendor pom developer id TCDEV Medium
Vendor pom developer name TRANSCONNECT Development Team Medium
Vendor pom groupid io.transconnect.connector Highest
Vendor pom name sample-connector High
Vendor pom url https://www.transconnect.io/ Highest
Product file name sample-connector High
Product gradle artifactid sample-connector Highest
Product jar package name connector Low
Product jar package name sample Low
Product jar package name transconnect Low
Product pom artifactid sample-connector Highest
Product pom developer email development@transconnect.io Low
Product pom developer id TCDEV Low
Product pom developer name TRANSCONNECT Development Team Low
Product pom groupid io.transconnect.connector Highest
Product pom name sample-connector High
Product pom url https://www.transconnect.io/ Medium
Version file version 1.0.0 High
Version gradle version 1.0.0 Highest
Version pom version 1.0.0 Highest
pkg:maven/io.transconnect.connector/sample-connector@1.0.0
(Confidence :High)
sample-connector-1.0.0.war
Description:
Sample connector implementation demonstrating TRANSCONNECT Connector SDK usage
License:
MIT License: https://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war
MD5: 8c39b46729e1d7515a90f6c14c8a4bf3
SHA1: 81c18d39e081f6dcee21b342e420bd53380fb77c
SHA256: 8de841f15cb31d72b3b988ae4471acf9d175efa6ae2cb99202ac972aabb1c2fb
Referenced In Project/Scope: server-start:webapps
sample-connector-1.0.0.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sample-connector High
Vendor gradle artifactid sample-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid sample-connector Low
Vendor pom developer email development@transconnect.io Low
Vendor pom developer id TCDEV Medium
Vendor pom developer name TRANSCONNECT Development Team Medium
Vendor pom groupid io.transconnect.connector Highest
Vendor pom name sample-connector High
Vendor pom url https://www.transconnect.io/ Highest
Product file name sample-connector High
Product gradle artifactid sample-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid sample-connector Highest
Product pom developer email development@transconnect.io Low
Product pom developer id TCDEV Low
Product pom developer name TRANSCONNECT Development Team Low
Product pom groupid io.transconnect.connector Highest
Product pom name sample-connector High
Product pom url https://www.transconnect.io/ Medium
Version file version 1.0.0 High
Version gradle version 1.0.0 Highest
Version pom version 1.0.0 Highest
pkg:maven/io.transconnect.connector/sample-connector@1.0.0
(Confidence :High)
sample-connector-1.0.0.war: angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
sample-connector-1.0.0.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sample-connector-1.0.0.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sample-connector-1.0.0.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
sample-connector-1.0.0.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sample-connector-1.0.0.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sample-connector-1.0.0.war: angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
sample-connector-1.0.0.war: asm-9.4.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/asm-9.4.jar
MD5: ffa64f03a23a4823d98703e6ce6ff397
SHA1: b4e0e2d2e023aa317b7cfcfc916377ea348e07d1
SHA256: 39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.4 High
Version Manifest Implementation-Version 9.4 High
sample-connector-1.0.0.war: jackson-core-2.17.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jackson-core-2.17.1.jar
MD5: 9363584821290882417f1c3ceab784df
SHA1: 5e52a11644cd59a28ef79f02bddc2cc3bab45edb
SHA256: ddb26c8a1f1a84535e8213c48b35b253370434e3287b3cf15777856fc4e58ce6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
Related Dependencies
sample-connector-1.0.0.war: jackson-annotations-2.17.1.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jackson-annotations-2.17.1.jar
MD5: dbeffa5994a6234489a205fd7f33d9b9
SHA1: fca7ef6192c9ad05d07bc50da991bf937a84af3a
SHA256: fccad82e13172c0e4384db71577219c9b8631c0820f4b18daaa57016fb661c76
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.17.1
sample-connector-1.0.0.war: jackson-databind-2.17.1.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jackson-databind-2.17.1.jar
MD5: f0a1c37dc7d937f14e183d84f15c0f83
SHA1: 0524dcbcccdde7d45a679dfc333e4763feb09079
SHA256: b6ca2f7d5b1ab245cec5495ec339773d2d90554c48592590673fb18f4400a948
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
sample-connector-1.0.0.war: jackson-dataformat-yaml-2.17.1.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jackson-dataformat-yaml-2.17.1.jar
MD5: 3257d599754342666ba50b7eaed555b5
SHA1: b4c7b8a9ea3f398116a75c146b982b22afebc4ee
SHA256: 83f38459593bc10caeb1fa2653616813b1743b6bed67163c8ae8e5a4d32a5456
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
sample-connector-1.0.0.war: jackson-datatype-jsr310-2.17.1.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jackson-datatype-jsr310-2.17.1.jar
MD5: 9761d8656aeac7db968998100b91f36e
SHA1: 0969b0c3cb8c75d759e9a6c585c44c9b9f3a4f75
SHA256: 56765d55ac8cffdd757c1a534ec965e70b01176f64dfd7e70b0db34d8babc9fa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.17.1 High
Version Manifest Bundle-Version 2.17.1 High
Version Manifest Implementation-Version 2.17.1 High
Version pom version 2.17.1 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.17.1
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.17.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sample-connector-1.0.0.war: jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
sample-connector-1.0.0.war: jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
sample-connector-1.0.0.war: jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
sample-connector-1.0.0.war: jaxb-1.0.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/jaxb-1.0.0.jar
MD5: 5923f351324850c8719489c386b4c1a4
SHA1: a7b7b982636ca59327f1fbb89e784dd7fe5ec332
SHA256: 48487fc796d30d1eacdef22c88c487bfc29edf9ef4515f1d96701f09a53d36e8
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name jaxb High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name jaxb Medium
Version file version 1.0.0 High
sample-connector-1.0.0.war: org.eclipse.persistence.core-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/org.eclipse.persistence.core-5.0.0-B10.jar
MD5: 0220aebe0d5d2e3e17212b4f170bc861
SHA1: 7ab1bff81e53437b06882cac903427164e047cc8
SHA256: be3b97f65e605c29b539db0c7adb134ec61413943368432705c4731965b1370a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.core High
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Vendor Manifest extension-name org.eclipse.persistence.core Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Vendor pom artifactid eclipse.persistence.core Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink Core High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.core High
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink Core Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Product Manifest extension-name org.eclipse.persistence.core Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Product pom artifactid eclipse.persistence.core Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink Core High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.core@5.0.0-B10
(Confidence :High)
sample-connector-1.0.0.war: org.eclipse.persistence.moxy-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/org.eclipse.persistence.moxy-5.0.0-B10.jar
MD5: 550ec8c0a31fbc5b6d0cd63f75b7d897
SHA1: aede7488445daebad7fb1f7202593e0800e858db
SHA256: 6d040ff629d81d54a7d5f18e73370288126062db7325a87e13fc97bbe65f935a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.moxy High
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Vendor Manifest extension-name org.eclipse.persistence.moxy Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Vendor pom artifactid eclipse.persistence.moxy Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink MOXy High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.moxy High
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink MOXy Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Product Manifest extension-name org.eclipse.persistence.moxy Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Product pom artifactid eclipse.persistence.moxy Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink MOXy High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.moxy@5.0.0-B10
(Confidence :High)
sample-connector-1.0.0.war: proxy-properties-1.0.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/proxy-properties-1.0.0.jar
MD5: 9595b898fe44466f7aa495851f91cfe4
SHA1: 06277732b71c188e76f27bde3f3497ccd7000507
SHA256: 4ed25a44fbcfd8170bde3eb20e133e0fa176955c93eea5282ad1f5715f24c99e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name proxy-properties High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name proxy-properties High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name proxy-properties Medium
Version file version 1.0.0 High
sample-connector-1.0.0.war: snakeyaml-2.2.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/snakeyaml-2.2.jar
MD5: d78aacf5f2de5b52f1a327470efd1ad7
SHA1: 3af797a25458550a16bf89acc8e4ab2b7f2bfce0
SHA256: 1467931448a0817696ae2805b7b8b20bfb082652bf9c4efaed528930dc49389b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.2 High
Version pom version 2.2 Highest
sample-connector-1.0.0.war: war-connector-bridge-1.0.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/war-connector-bridge-1.0.0.jar
MD5: ab17d5182030cc412f08bac948f4d51f
SHA1: a8cafc84288a8af989fba9dbabfd5c16cb32b550
SHA256: 78e2c8a04eb7f82bade7b0e89e8bb8337107bfc82911bf520c8d53d524bb2a34
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 1.0.0 High
sample-connector-1.0.0.war: yaml-descriptor-1.0.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sample-connector/1.0.0/81c18d39e081f6dcee21b342e420bd53380fb77c/sample-connector-1.0.0.war/WEB-INF/lib/yaml-descriptor-1.0.0.jar
MD5: 9a1a03955eb465d5ba252e4ee0cb9296
SHA1: 582f1e10bd10fe32b8ca4f5adc342f83ebb19e78
SHA256: 4e7691a6b0e844e33c72401442f75501d76741f1775fe3849c62fcf0b9583fb9
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 1.0.0 High
sardine-5.10.jar
Description:
An easy to use WebDAV client for Java
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.github.lookfirst/sardine/5.10/2fbf02cc994e61b3fdb32aa347cfaf9778f45b21/sardine-5.10.jar
MD5: f916cbc2b7bdd52ade41c294d0aed578
SHA1: 2fbf02cc994e61b3fdb32aa347cfaf9778f45b21
SHA256: d958ae956832c3379d5a3fa8a4793c83cc79a896baac2434b876d70d86c27dbf
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
sardine-5.10.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sardine High
Vendor gradle artifactid sardine Highest
Vendor gradle groupid com.github.lookfirst Highest
Vendor jar package name github Highest
Vendor jar package name sardine Highest
Vendor Manifest implementation-url https://github.com/lookfirst/sardine Low
Vendor Manifest Implementation-Vendor-Id com.github.lookfirst Medium
Vendor pom artifactid sardine Low
Vendor pom developer email latchkey@gmail.com Low
Vendor pom developer email post@iterate.ch Low
Vendor pom developer id iterate Medium
Vendor pom developer id lookfirst Medium
Vendor pom developer name David Kocher Medium
Vendor pom developer name Jon Stevens Medium
Vendor pom developer org iterate GmbH Medium
Vendor pom groupid com.github.lookfirst Highest
Vendor pom name Sardine WebDAV client High
Vendor pom url lookfirst/sardine Highest
Product file name sardine High
Product gradle artifactid sardine Highest
Product jar package name github Highest
Product jar package name sardine Highest
Product Manifest Implementation-Title Sardine WebDAV client High
Product Manifest implementation-url https://github.com/lookfirst/sardine Low
Product Manifest specification-title Sardine WebDAV client Medium
Product pom artifactid sardine Highest
Product pom developer email latchkey@gmail.com Low
Product pom developer email post@iterate.ch Low
Product pom developer id iterate Low
Product pom developer id lookfirst Low
Product pom developer name David Kocher Low
Product pom developer name Jon Stevens Low
Product pom developer org iterate GmbH Low
Product pom groupid com.github.lookfirst Highest
Product pom name Sardine WebDAV client High
Product pom url lookfirst/sardine High
Version file version 5.10 High
Version gradle version 5.10 Highest
Version Manifest Implementation-Version 5.10 High
Version pom version 5.10 Highest
pkg:maven/com.github.lookfirst/sardine@5.10
(Confidence :High)
sdk-client-5.1.0-116.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.prosys.ua/sdk-client/5.1.0-116/47382e5aac7f18a1603a167aac633148a97b51b/sdk-client-5.1.0-116.jar
MD5: 7a7ca96e590da47a1bbd4a0f322b180c
SHA1: 047382e5aac7f18a1603a167aac633148a97b51b
SHA256: 6999dce46f800e58fe2ee172b032c119175ffd1302634f9dbb0bad516f98b925
Referenced In Project/Scope: server-start:runtimeClasspath
sdk-client-5.1.0-116.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sdk-client High
Vendor gradle artifactid sdk-client Highest
Vendor gradle groupid com.prosys.ua Highest
Vendor jar package name prosysopc Highest
Vendor jar package name prosysopc Low
Vendor jar package name ua Highest
Vendor jar package name ua Low
Vendor Manifest automatic-module-name com.prosysopc.ua Medium
Vendor pom artifactid sdk-client Low
Vendor pom groupid com.prosys.ua Highest
Product file name sdk-client High
Product gradle artifactid sdk-client Highest
Product jar package name prosysopc Highest
Product jar package name ua Highest
Product jar package name ua Low
Product Manifest automatic-module-name com.prosysopc.ua Medium
Product pom artifactid sdk-client Highest
Product pom groupid com.prosys.ua Highest
Version gradle version 5.1.0-116 Highest
Version pom version 5.1.0-116 Highest
pkg:maven/com.prosys.ua/sdk-client@5.1.0-116
(Confidence :High)
sdk-core-2.26.30.jar
Description:
The AWS SDK for Java - SDK Core runtime module holds the classes that are used by the individual service
clients to interact with
Amazon Web Services. Users need to depend on aws-java-sdk artifact for accessing individual client classes.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/sdk-core/2.26.30/50abd5caeb49a08964041bd9904ac01ee50c3110/sdk-core-2.26.30.jar
MD5: f22f3ed70fabf6fa46369ab3534b6af2
SHA1: 50abd5caeb49a08964041bd9904ac01ee50c3110
SHA256: 02684191deb25a4d39b64216efaa85319c198e96f36d7f7c08f248adcbf506fa
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
sdk-core-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sdk-core High
Vendor gradle artifactid sdk-core Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name core Highest
Vendor jar package name software Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.core Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid sdk-core Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: SDK Core High
Vendor pom parent-artifactid core Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name sdk-core High
Product gradle artifactid sdk-core Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name core Highest
Product jar package name software Highest
Product Manifest automatic-module-name software.amazon.awssdk.core Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid sdk-core Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: SDK Core High
Product pom parent-artifactid core Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
serializer-2.7.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xalan/serializer/2.7.3/1aa6259987888f49fdbebb1aa1a88e0f54a44f6f/serializer-2.7.3.jar
MD5: 21697a2d50f03bfd93ccf7636f8118d3
SHA1: 1aa6259987888f49fdbebb1aa1a88e0f54a44f6f
SHA256: 5f6804bacdfdb3ccc52d2538536fab8986696d61559b081054a420c653806667
Referenced In Project/Scope: server-start:runtimeClasspath
serializer-2.7.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name serializer High
Vendor gradle artifactid serializer Highest
Vendor gradle groupid xalan Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name serializer Low
Vendor jar package name xml Low
Vendor manifest: org/apache/xml/serializer/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xml/serializer/utils/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid serializer Low
Vendor pom groupid xalan Highest
Product file name serializer High
Product gradle artifactid serializer Highest
Product jar package name apache Highest
Product jar package name serializer Highest
Product jar package name serializer Low
Product jar package name utils Highest
Product jar package name xml Highest
Product jar package name xml Low
Product manifest: org/apache/xml/serializer/ Implementation-Title org.apache.xml.serializer Medium
Product manifest: org/apache/xml/serializer/ Specification-Title XSL Transformations (XSLT), at http://www.w3.org/TR/xslt Medium
Product manifest: org/apache/xml/serializer/utils/ Implementation-Title org.apache.xml.serializer.utils Medium
Product pom artifactid serializer Highest
Product pom groupid xalan Highest
Version file version 2.7.3 High
Version gradle version 2.7.3 Highest
Version manifest: org/apache/xml/serializer/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/xml/serializer/utils/ Implementation-Version 2.7.3 Medium
Version pom version 2.7.3 Highest
pkg:maven/xalan/serializer@2.7.3
(Confidence :High)
sharepoint-online-connector-0.9.4-classes.jar
Description:
Web application: sharepoint-online-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/2474412cbb1aaf0b924bb139713b13c574f73d7b/sharepoint-online-connector-0.9.4-classes.jar
MD5: 5383f5254a1b0899f3d9f4524d2f1d9f
SHA1: 2474412cbb1aaf0b924bb139713b13c574f73d7b
SHA256: 780be262a2ce061b06f0ecafef1dae23d5aae0d6c7bb307242b201dc37fc2cbc
Referenced In Project/Scope: server-start:compileClasspath
sharepoint-online-connector-0.9.4-classes.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sharepoint-online-connector High
Vendor gradle artifactid sharepoint-online-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name io Low
Vendor jar package name message Low
Vendor jar package name transconnect Low
Vendor pom artifactid sharepoint-online-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name sharepoint-online-connector High
Product gradle artifactid sharepoint-online-connector Highest
Product jar package name connector Low
Product jar package name message Low
Product jar package name transconnect Low
Product pom artifactid sharepoint-online-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.4 High
Version gradle version 0.9.4 Highest
Version pom version 0.9.4 Highest
pkg:maven/io.transconnect.connector/sharepoint-online-connector@0.9.4
(Confidence :High)
sharepoint-online-connector-0.9.4.war
Description:
Web application: sharepoint-online-connector
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war
MD5: 0dcf6af38ec66fbabfbdcc05385450ff
SHA1: 4345fb71be8bf878916835e7b99d225041448fb8
SHA256: 5b981aacfb9ec28eb94dc11734fccc78804beb8ec0135f6f8374170841650a76
Referenced In Project/Scope: server-start:webapps
sharepoint-online-connector-0.9.4.war is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server-start@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sharepoint-online-connector High
Vendor gradle artifactid sharepoint-online-connector Highest
Vendor gradle groupid io.transconnect.connector Highest
Vendor jar package name classes Low
Vendor jar package name io Low
Vendor jar package name web-inf Low
Vendor pom artifactid sharepoint-online-connector Low
Vendor pom groupid io.transconnect.connector Highest
Product file name sharepoint-online-connector High
Product gradle artifactid sharepoint-online-connector Highest
Product jar package name classes Low
Product jar package name io Low
Product jar package name transconnect Low
Product pom artifactid sharepoint-online-connector Highest
Product pom groupid io.transconnect.connector Highest
Version file version 0.9.4 High
Version gradle version 0.9.4 Highest
Version pom version 0.9.4 Highest
pkg:maven/io.transconnect.connector/sharepoint-online-connector@0.9.4
(Confidence :High)
sharepoint-online-connector-0.9.4.war: angus-activation-2.0.2.jar
Description:
Implementation
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-activation High
Vendor jar package name activation Highest
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname angus-activation Medium
Vendor Manifest extension-name org.eclipse.angus Medium
Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid angus-activation Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Activation Registries High
Vendor pom parent-artifactid angus-activation-project Low
Product file name angus-activation High
Product jar package name activation Highest
Product jar package name angus Highest
Product jar package name eclipse Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Activation Registries Medium
Product Manifest bundle-symbolicname angus-activation Medium
Product Manifest extension-name org.eclipse.angus Medium
Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low
Product Manifest Implementation-Title Angus Activation Registries High
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid angus-activation Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Activation Registries High
Product pom parent-artifactid angus-activation-project Medium
Version file version 2.0.2 High
Version Manifest Bundle-Version 2.0.2 High
Version pom version 2.0.2 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.2
(Confidence :High)
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:angus-core:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: b00ad1f3322ed736d6eb717441a20f0d
SHA1: bab276e894997c88c72a981691a57d5e81762128
SHA256: 87a6b385eb4df03ff2ffeb750af3858efc2a90d056f46990ae359505d59a66ab
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid angus-core Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Core High
Vendor pom parent-artifactid all Low
Product pom artifactid angus-core Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Core High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/angus-core@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:imap:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/imap/pom.xml
MD5: c920e46a1ca1efea40ae8a6886beda7c
SHA1: 3d47f9345b5c2467969815646fd114c3b08f108f
SHA256: 7a397cec3d2d1bf26c8bd7df77dd5d0caa57af718976290e7bc3d7fca2c42917
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid imap Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail imap provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid imap Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail imap provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/imap@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: 0711b1e4cbb2e1b50e7f17e3428f7ae6
SHA1: b51bb90174f0e2a47662e5cd5127b9bf0845e6f9
SHA256: ba3ab28c7633eba0503755d160d0e09b244bf4ed58ec1b89bc8ff891eaecebea
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid logging-mailhandler Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail logging handler High
Vendor pom parent-artifactid all Low
Product pom artifactid logging-mailhandler Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail logging handler High
Product pom parent-artifactid all Medium
Version pom version 2.0.4 Highest
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:pop3:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xml
MD5: af34e8ae164e4f64dfca8f725e0f0105
SHA1: 9d0a63878e71486ca6bfe4da1219352bf2ff4b45
SHA256: ac0712407bab89e2fef06ec09d455221bee73606f03811ae1a412774ab143792
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid pop3 Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail pop3 provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid pop3 Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail pop3 provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/pop3@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar (shaded: org.eclipse.angus:smtp:2.0.4)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xml
MD5: 1ac1221625342393598ca07f164f7d74
SHA1: 14c27147014f1e749253c9d9a12975490759cf64
SHA256: 8d7f154fa84b483de7e118563cbe3461479b20c2f149ec7099e6b6be69083128
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smtp Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail smtp provider High
Vendor pom parent-artifactid providers Low
Product pom artifactid smtp Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail smtp provider High
Product pom parent-artifactid providers Medium
Version pom version 2.0.4 Highest
pkg:maven/org.eclipse.angus/smtp@2.0.4
(Confidence :High)
cpe:2.3:a:eclipse:angus_mail:2.0.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: angus-mail-2.0.4.jar
Description:
Angus Mail Provider
License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/angus-mail-2.0.4.jar
MD5: 5e39c666abac5e0c7837894606af28b8
SHA1: 80a49d6e187788d17a23b05e375bad75f56a4a92
SHA256: 87301865584bad9170662b3eeef0350aaafea4522483e38e54ae87dc3df3e958
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name angus-mail High
Vendor jar package name angus Highest
Vendor jar package name eclipse Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Vendor pom artifactid angus-mail Low
Vendor pom groupid org.eclipse.angus Highest
Vendor pom name Angus Mail Provider High
Vendor pom parent-artifactid all Low
Product file name angus-mail High
Product jar package name angus Highest
Product jar package name eclipse Highest
Product jar package name mail Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Angus Mail Provider Medium
Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium
Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.mail.util.StreamProvider",osgi.serviceloader;osgi.serviceloader="jakarta.mail.Provider" Low
Product pom artifactid angus-mail Highest
Product pom groupid org.eclipse.angus Highest
Product pom name Angus Mail Provider High
Product pom parent-artifactid all Medium
Version file version 2.0.4 High
Version Manifest Bundle-Version 2.0.4 High
Version pom version 2.0.4 Highest
sharepoint-online-connector-0.9.4.war: annotations-13.0.jar
Description:
A set of annotations used for code inspection support and code documentation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/annotations-13.0.jar
MD5: f4fb462172517b46b6cd90003508515a
SHA1: 919f0dfe192fb4e063e7dacadee7f8bb9a2672a9
SHA256: ace2a10dc8e2d5fd34925ecac03e4988b2c0f851650c94b8cef49ba1bd111478
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name annotations High
Vendor jar package name annotations Highest
Vendor jar package name annotations Low
Vendor jar package name intellij Highest
Vendor jar package name intellij Low
Vendor jar package name jetbrains Highest
Vendor jar package name lang Low
Vendor pom artifactid annotations Low
Vendor pom developer id JetBrains Medium
Vendor pom developer name JetBrains Team Medium
Vendor pom developer org JetBrains Medium
Vendor pom developer org URL http://www.jetbrains.com Medium
Vendor pom groupid org.jetbrains Highest
Vendor pom name IntelliJ IDEA Annotations High
Vendor pom url http://www.jetbrains.org Highest
Product file name annotations High
Product jar package name annotations Highest
Product jar package name annotations Low
Product jar package name intellij Highest
Product jar package name jetbrains Highest
Product jar package name lang Low
Product pom artifactid annotations Highest
Product pom developer id JetBrains Low
Product pom developer name JetBrains Team Low
Product pom developer org JetBrains Low
Product pom developer org URL http://www.jetbrains.com Low
Product pom groupid org.jetbrains Highest
Product pom name IntelliJ IDEA Annotations High
Product pom url http://www.jetbrains.org Medium
Version file version 13.0 High
Version pom version 13.0 Highest
pkg:maven/org.jetbrains/annotations@13.0
(Confidence :High)
sharepoint-online-connector-0.9.4.war: asm-9.4.jar
License:
BSD-3-Clause;link=https://asm.ow2.io/LICENSE.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/asm-9.4.jar
MD5: ffa64f03a23a4823d98703e6ce6ff397
SHA1: b4e0e2d2e023aa317b7cfcfc916377ea348e07d1
SHA256: 39d0e2b3dc45af65a09b097945750a94a126e052e124f93468443a1d0e15f381
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name asm High
Vendor jar package name asm Highest
Vendor jar package name asm Low
Vendor jar package name objectweb Highest
Vendor jar package name objectweb Low
Vendor Manifest bundle-docurl http://asm.ow2.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor Manifest bundle-symbolicname org.objectweb.asm Medium
Product file name asm High
Product jar package name asm Highest
Product jar package name asm Low
Product jar package name objectweb Highest
Product Manifest bundle-docurl http://asm.ow2.org Low
Product Manifest Bundle-Name org.objectweb.asm Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest bundle-symbolicname org.objectweb.asm Medium
Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High
Version file version 9.4 High
Version Manifest Implementation-Version 9.4 High
sharepoint-online-connector-0.9.4.war: azure-core-1.57.0.jar
Description:
This package contains core types for Azure Java clients.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-core-1.57.0.jar
MD5: 0d4a713cd952eb3d0c3ebc9cc50ede86
SHA1: 4fe5978491bb9a305b98dc5456a138ad7ba0f250
SHA256: 32b479b85ac12ec624d42551cc210834c98ca2b623b2ee0c777debac3adbddaa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-core High
Vendor jar package name azure Highest
Vendor jar package name client Highest
Vendor jar package name core Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-core Low
Vendor pom developer id microsoft Medium
Vendor pom developer name Microsoft Medium
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure Java Core Library High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-core High
Product jar package name azure Highest
Product jar package name client Highest
Product jar package name core Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure Java Core Library High
Product pom artifactid azure-core Highest
Product pom developer id microsoft Low
Product pom developer name Microsoft Low
Product pom groupid com.azure Highest
Product pom name Microsoft Azure Java Core Library High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.57.0 High
Version Manifest Implementation-Version 1.57.0 High
Version pom parent-version 1.57.0 Low
Version pom version 1.57.0 Highest
pkg:maven/com.azure/azure-core@1.57.0
(Confidence :High)
cpe:2.3:a:microsoft:azure_sdk_for_java:1.57.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-33117 suppress
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
CWE-347 Improper Verification of Cryptographic Signature, CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
sharepoint-online-connector-0.9.4.war: azure-core-http-netty-1.16.2.jar
Description:
This package contains the Netty HTTP client plugin for azure-core.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-core-http-netty-1.16.2.jar
MD5: a3fd5106f4484fcbddd757fc79279a53
SHA1: 2ac10e5534929c682d93b6187386fe2e3c5bb54f
SHA256: 84282bd76cf3d7ab72ad32f3e8cba9875f14cfdb12a2203c928b39208f373c98
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-core-http-netty High
Vendor jar package name azure Highest
Vendor jar package name core Highest
Vendor jar package name http Highest
Vendor jar package name netty Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-core-http-netty Low
Vendor pom developer id microsoft Medium
Vendor pom developer name Microsoft Medium
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure Netty HTTP Client Library High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-core-http-netty High
Product jar package name azure Highest
Product jar package name core Highest
Product jar package name http Highest
Product jar package name netty Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure Netty HTTP Client Library High
Product pom artifactid azure-core-http-netty Highest
Product pom developer id microsoft Low
Product pom developer name Microsoft Low
Product pom groupid com.azure Highest
Product pom name Microsoft Azure Netty HTTP Client Library High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.16.2 High
Version Manifest Implementation-Version 1.16.2 High
Version pom parent-version 1.16.2 Low
Version pom version 1.16.2 Highest
pkg:maven/com.azure/azure-core-http-netty@1.16.2
(Confidence :High)
cpe:2.3:a:microsoft:azure_sdk_for_java:1.16.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-33117 suppress
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
CWE-347 Improper Verification of Cryptographic Signature, CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
sharepoint-online-connector-0.9.4.war: azure-identity-1.18.1.jar
Description:
This module contains client library for Microsoft Azure Identity.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-identity-1.18.1.jar
MD5: e97bf19449e6bd37e4ebbf6e5bf03c37
SHA1: 38a431597ec940dd77f425443135deb6991b640d
SHA256: 8f4b36c6bf7472220d6b052364bd0cad441f2d9328a119ecdcf423a4ab4331c1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-identity High
Vendor jar package name azure Highest
Vendor jar package name identity Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-identity Low
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure client library for Identity High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-identity High
Product jar package name azure Highest
Product jar package name identity Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure client library for Identity High
Product pom artifactid azure-identity Highest
Product pom groupid com.azure Highest
Product pom name Microsoft Azure client library for Identity High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.18.1 High
Version Manifest Implementation-Version 1.18.1 High
Version pom parent-version 1.18.1 Low
Version pom version 1.18.1 Highest
pkg:maven/com.azure/azure-identity@1.18.1
(Confidence :High)
cpe:2.3:a:microsoft:azure_sdk_for_java:1.18.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-33117 suppress
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
CWE-347 Improper Verification of Cryptographic Signature, CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
sharepoint-online-connector-0.9.4.war: azure-json-1.5.0.jar
Description:
This package provides interfaces for reading and writing JSON.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-json-1.5.0.jar
MD5: 8db69eaaef3583ab84ddbdbd18cb1c2b
SHA1: d12cf1a1d31ca75b27a5bbe0fbcf5ad73b7471b5
SHA256: 65b1ec85f5d734221f1028d60c95bf5b453515797d6ab68ea8c36a6f2d5bc56b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-json High
Vendor jar package name azure Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-json Low
Vendor pom developer id microsoft Medium
Vendor pom developer name Microsoft Medium
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure Java JSON Library High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-json High
Product jar package name azure Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure Java JSON Library High
Product pom artifactid azure-json Highest
Product pom developer id microsoft Low
Product pom developer name Microsoft Low
Product pom groupid com.azure Highest
Product pom name Microsoft Azure Java JSON Library High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.5.0 High
Version Manifest Implementation-Version 1.5.0 High
Version pom parent-version 1.5.0 Low
Version pom version 1.5.0 Highest
pkg:maven/com.azure/azure-json@1.5.0
(Confidence :High)
cpe:2.3:a:microsoft:azure_sdk_for_java:1.5.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-33117 suppress
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.
CWE-347 Improper Verification of Cryptographic Signature, CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
sharepoint-online-connector-0.9.4.war: azure-xml-1.2.0.jar
Description:
This package provides interfaces for reading and writing XML.
License:
The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-xml-1.2.0.jar
MD5: 0a50063dac825ebff557aaecd7b8747d
SHA1: 05a811882dc4eba119c7d1f0fc65acf39eaf417c
SHA256: 69d9559c561d3125bfd2bf9b5248601e442902bc755d935dde3edba97dc0d931
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-xml High
Vendor jar package name azure Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-xml Low
Vendor pom developer id microsoft Medium
Vendor pom developer name Microsoft Medium
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure Java XML Library High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-xml High
Product jar package name azure Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure Java XML Library High
Product pom artifactid azure-xml Highest
Product pom developer id microsoft Low
Product pom developer name Microsoft Low
Product pom groupid com.azure Highest
Product pom name Microsoft Azure Java XML Library High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.2.0 High
Version Manifest Implementation-Version 1.2.0 High
Version pom parent-version 1.2.0 Low
Version pom version 1.2.0 Highest
pkg:maven/com.azure/azure-xml@1.2.0
(Confidence :High)
cpe:2.3:a:xml_library_project:xml_library:1.2.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: checker-qual-3.33.0.jar
License:
MIT
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/checker-qual-3.33.0.jar
MD5: fc9418b779d9d57dcd52197006cbdb9b
SHA1: de2b60b62da487644fc11f734e73c8b0b431238f
SHA256: e316255bbfcd9fe50d165314b85abb2b33cb2a66a93c491db648e498a82c2de1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checker Low
Vendor jar package name checkerframework Highest
Vendor jar package name checkerframework Low
Vendor jar package name qual Highest
Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checker Low
Product jar package name checkerframework Highest
Product jar package name qual Highest
Product jar package name qual Low
Product Manifest automatic-module-name org.checkerframework.checker.qual Medium
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Version file version 3.33.0 High
Version Manifest Implementation-Version 3.33.0 High
sharepoint-online-connector-0.9.4.war: error_prone_annotations-2.38.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/error_prone_annotations-2.38.0.jar
MD5: 912f8206614000252841d89cb0461895
SHA1: fc0ae991433e8590ba51cd558421478318a74c8c
SHA256: 6661d5335090a5fc61dd869d2095bc6c1e2156e3aa47a6e4ababdf64c99a7889
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.38.0 High
Version Manifest Bundle-Version 2.38.0 High
Version pom version 2.38.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.38.0
(Confidence :High)
sharepoint-online-connector-0.9.4.war: failureaccess-1.0.1.jar
Description:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes is conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name failureaccess High
Vendor jar package name common Highest
Vendor jar package name concurrent Highest
Vendor jar package name google Highest
Vendor jar package name util Highest
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Vendor pom artifactid failureaccess Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High
Vendor pom parent-artifactid guava-parent Low
Product file name failureaccess High
Product jar package name common Highest
Product jar package name concurrent Highest
Product jar package name google Highest
Product jar package name util Highest
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium
Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium
Product pom artifactid failureaccess Highest
Product pom groupid com.google.guava Highest
Product pom name Guava InternalFutureFailureAccess and InternalFutures High
Product pom parent-artifactid guava-parent Medium
Version file version 1.0.1 High
Version Manifest Bundle-Version 1.0.1 High
Version pom parent-version 1.0.1 Low
Version pom version 1.0.1 Highest
pkg:maven/com.google.guava/failureaccess@1.0.1
(Confidence :High)
sharepoint-online-connector-0.9.4.war: gson-2.13.1.jar
Description:
Gson JSON library
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/gson-2.13.1.jar
MD5: d82c16b045ce4832679d70f26a67b30c
SHA1: 853ce06c11316b33a8eae5e9095da096a9528b8f
SHA256: 94855942d4992f112946d3de1c334e709237b8126d8130bf07807c018a4a2120
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name gson High
Vendor jar package name google Highest
Vendor jar package name gson Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-contactaddress https://github.com/google/gson Low
Vendor Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low
Vendor Manifest bundle-docurl https://github.com/google/gson Low
Vendor Manifest bundle-symbolicname com.google.gson Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid gson Low
Vendor pom groupid com.google.code.gson Highest
Vendor pom name Gson High
Vendor pom parent-artifactid gson-parent Low
Product file name gson High
Product jar package name google Highest
Product jar package name gson Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-contactaddress https://github.com/google/gson Low
Product Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low
Product Manifest bundle-docurl https://github.com/google/gson Low
Product Manifest Bundle-Name Gson Medium
Product Manifest bundle-symbolicname com.google.gson Medium
Product Manifest multi-release true Low
Product pom artifactid gson Highest
Product pom groupid com.google.code.gson Highest
Product pom name Gson High
Product pom parent-artifactid gson-parent Medium
Version file version 2.13.1 High
Version Manifest Bundle-Version 2.13.1 High
Version pom version 2.13.1 Highest
sharepoint-online-connector-0.9.4.war: guava-32.1.2-jre.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/guava-32.1.2-jre.jar
MD5: 5fe031b3b35ed56182478811a931d617
SHA1: 5e64ec7e056456bef3a4bc4c6fdaef71e8ab6318
SHA256: bc65dea7cfd9e4dacf8419d8af0e741655857d27885bb35d943d7187fc3a8fce
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name guava High
Vendor jar package name common Highest
Vendor jar package name google Highest
Vendor Manifest automatic-module-name com.google.common Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava: Google Core Libraries for Java High
Vendor pom parent-artifactid guava-parent Low
Vendor pom url google/guava Highest
Product file name guava High
Product jar package name common Highest
Product jar package name google Highest
Product Manifest automatic-module-name com.google.common Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom artifactid guava Highest
Product pom groupid com.google.guava Highest
Product pom name Guava: Google Core Libraries for Java High
Product pom parent-artifactid guava-parent Medium
Product pom url google/guava High
Version pom version 32.1.2-jre Highest
sharepoint-online-connector-0.9.4.war: jackson-annotations-2.18.4.jar
Description:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jackson-annotations-2.18.4.jar
MD5: 73e53f24c756c4bab25eae8c746d77a4
SHA1: 21e5645ac25cd6c281cfc9e51df031055d26ffd6
SHA256: 2166156094cd146397eb4814bd117cabe3353390dfa894bcc06ce46b15bd428e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-annotations High
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-annotations Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-annotations High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest specification-title Jackson-annotations Medium
Product pom artifactid jackson-annotations Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-annotations High
Product pom parent-artifactid jackson-parent Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.18.4 High
Version Manifest Bundle-Version 2.18.4 High
Version Manifest Implementation-Version 2.18.4 High
Version pom parent-version 2.18.4 Low
Version pom version 2.18.4 Highest
sharepoint-online-connector-0.9.4.war: jackson-core-2.18.4.1.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jackson-core-2.18.4.1.jar
MD5: 4771254e0b2054589e4f4a87991b8ea8
SHA1: 3757427823c9f5ad6c7c7145598cfac2a13e03e0
SHA256: 56934543aee549896c1c665b1a58400ec1076562fb5407f53270ecafc120af3a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.18.4.1 High
Version Manifest Bundle-Version 2.18.4.1 High
Version Manifest Implementation-Version 2.18.4.1 High
Version pom version 2.18.4.1 Highest
sharepoint-online-connector-0.9.4.war: jackson-databind-2.18.4.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jackson-databind-2.18.4.jar
MD5: f4f9b19d51c3eea46c3456d272dff324
SHA1: 7533a629c563ef6a5e2424d6ff3654155abea6b0
SHA256: 452dcfd2cf381390090b7e14479d294d134320c55c3b744405c2270827a83c03
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.18.4 High
Version Manifest Bundle-Version 2.18.4 High
Version Manifest Implementation-Version 2.18.4 High
Version pom version 2.18.4 Highest
sharepoint-online-connector-0.9.4.war: jackson-dataformat-yaml-2.18.4.jar
Description:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jackson-dataformat-yaml-2.18.4.jar
MD5: 2e35d919b44e69cdc43df8f6d3ae1408
SHA1: 119572c5ecb7d9a08e1cbf3cebeecbe2a496b93f
SHA256: 496ba696703eab7d8f2b307711cfa8d83b59efae748e22e36f814a3bbf3d7659
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-dataformat-yaml High
Vendor jar package name dataformat Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-YAML High
Vendor pom parent-artifactid jackson-dataformats-text Low
Vendor pom url FasterXML/jackson-dataformats-text Highest
Product file name jackson-dataformat-yaml High
Product jar package name dataformat Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low
Product Manifest Bundle-Name Jackson-dataformat-YAML Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium
Product Manifest Implementation-Title Jackson-dataformat-YAML High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-dataformat-YAML Medium
Product pom artifactid jackson-dataformat-yaml Highest
Product pom groupid com.fasterxml.jackson.dataformat Highest
Product pom name Jackson-dataformat-YAML High
Product pom parent-artifactid jackson-dataformats-text Medium
Product pom url FasterXML/jackson-dataformats-text High
Version file version 2.18.4 High
Version Manifest Bundle-Version 2.18.4 High
Version Manifest Implementation-Version 2.18.4 High
Version pom version 2.18.4 Highest
sharepoint-online-connector-0.9.4.war: jackson-datatype-jsr310-2.18.4.jar
Description:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jackson-datatype-jsr310-2.18.4.jar
MD5: 7adaa35667cc6e6c038ab8ddfc6853ec
SHA1: 3ef73abb0019203a8b626684edaa3e2c2c2def53
SHA256: 2fd8908146116773299441f14ae62477600ff2334c12541c65406b98ed7edeca
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jsr310 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jsr310 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jsr310 Low
Vendor pom developer email nicholas@nicholaswilliams.net Low
Vendor pom developer id beamerblvd Medium
Vendor pom developer name Nick Williams Medium
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: JSR310 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jsr310 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jsr310 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low
Product Manifest Bundle-Name Jackson datatype: JSR310 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium
Product Manifest Implementation-Title Jackson datatype: JSR310 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: JSR310 Medium
Product pom artifactid jackson-datatype-jsr310 Highest
Product pom developer email nicholas@nicholaswilliams.net Low
Product pom developer id beamerblvd Low
Product pom developer name Nick Williams Low
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: JSR310 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.18.4 High
Version Manifest Bundle-Version 2.18.4 High
Version Manifest Implementation-Version 2.18.4 High
Version pom version 2.18.4 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.18.4
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: jakarta.activation-api-2.1.3.jar
Description:
Specification
License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.activation-api High
Vendor jar package name activation Highest
Vendor jar package name jakarta Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.activation-api Medium
Vendor Manifest extension-name jakarta.activation Medium
Vendor Manifest implementation-build-id 7f7d358 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.activation-api Low
Vendor pom developer email bill.shannon@oracle.com Low
Vendor pom developer id shannon Medium
Vendor pom developer name Bill Shannon Medium
Vendor pom developer org Oracle Medium
Vendor pom groupid jakarta.activation Highest
Vendor pom name Jakarta Activation API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url jakartaee/jaf-api Highest
Vendor pom (hint) developer org sun Medium
Product file name jakarta.activation-api High
Product jar package name activation Highest
Product jar package name jakarta Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Activation API Medium
Product Manifest bundle-symbolicname jakarta.activation-api Medium
Product Manifest extension-name jakarta.activation Medium
Product Manifest implementation-build-id 7f7d358 Low
Product Manifest Implementation-Title Jakarta Activation API High
Product Manifest specification-title Jakarta Activation Specification Medium
Product pom artifactid jakarta.activation-api Highest
Product pom developer email bill.shannon@oracle.com Low
Product pom developer id shannon Low
Product pom developer name Bill Shannon Low
Product pom developer org Oracle Low
Product pom groupid jakarta.activation Highest
Product pom name Jakarta Activation API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url jakartaee/jaf-api High
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.3
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jakarta.annotation-api-2.1.1.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 2.1.1 High
Version Manifest Bundle-Version 2.1.1 High
Version Manifest Implementation-Version 2.1.1 High
Version pom parent-version 2.1.1 Low
Version pom version 2.1.1 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1
(Confidence :High)
cpe:2.3:a:oracle:projects:2.1.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: jakarta.mail-api-2.1.3.jar
Description:
Specification API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.mail-api High
Vendor jar package name jakarta Highest
Vendor jar package name mail Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.mail-api Medium
Vendor Manifest extension-name jakarta.mail Medium
Vendor Manifest implementation-build-id 0f448dc Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.mail-api Low
Vendor pom groupid jakarta.mail Highest
Vendor pom name Jakarta Mail API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name jakarta.mail-api High
Product jar package name jakarta Highest
Product jar package name mail Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Mail API Medium
Product Manifest bundle-symbolicname jakarta.mail-api Medium
Product Manifest extension-name jakarta.mail Medium
Product Manifest implementation-build-id 0f448dc Low
Product Manifest Implementation-Title Jakarta Mail API High
Product Manifest specification-title Jakarta Mail Specification Medium
Product pom artifactid jakarta.mail-api Highest
Product pom groupid jakarta.mail Highest
Product pom name Jakarta Mail API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.3 High
Version Manifest Bundle-Version 2.1.3 High
Version pom parent-version 2.1.3 Low
Version pom version 2.1.3 Highest
sharepoint-online-connector-0.9.4.war: jakarta.xml.bind-api-4.0.2.jar
Description:
Jakarta XML Binding API 4.0 Design Specification
License:
http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.xml.bind-api High
Vendor jar package name bind Highest
Vendor jar package name jakarta Highest
Vendor jar package name xml Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Vendor Manifest extension-name jakarta.xml.bind Medium
Vendor Manifest implementation-build-id ca43d8b Low
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.xml.bind-api Low
Vendor pom groupid jakarta.xml.bind Highest
Vendor pom name Jakarta XML Binding API High
Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low
Product file name jakarta.xml.bind-api High
Product jar package name bind Highest
Product jar package name jakarta Highest
Product jar package name xml Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta XML Binding API Medium
Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium
Product Manifest extension-name jakarta.xml.bind Medium
Product Manifest implementation-build-id ca43d8b Low
Product pom artifactid jakarta.xml.bind-api Highest
Product pom groupid jakarta.xml.bind Highest
Product pom name Jakarta XML Binding API High
Product pom parent-artifactid jakarta.xml.bind-api-parent Medium
Version file version 4.0.2 High
Version Manifest Bundle-Version 4.0.2 High
Version Manifest Implementation-Version 4.0.2 High
Version pom version 4.0.2 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jaxb-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jaxb-0.9.5.jar
MD5: 62dd26407b3fe4a95c87d9fa0800a192
SHA1: 3cf649244df727ca00cbbf2149f3d71781faac64
SHA256: f26be27f61e1161a03ec62e1b83c9374082a45eceed34315e5b56fa7af92bd65
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jaxb High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name jaxb High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name jaxb Medium
Version file version 0.9.5 High
sharepoint-online-connector-0.9.4.war: jjwt-api-0.12.6.jar
Description:
JSON Web Token support for the JVM and Android
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jjwt-api-0.12.6.jar
MD5: 995d2066feaa206de5e880045c9407d4
SHA1: 478886a888f6add04937baf0361144504a024967
SHA256: 8fabe0be1dfad1c823dc43137453e017d2c83f376422c83e017d9dd1043e6984
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jjwt-api High
Vendor jar package name io Highest
Vendor jar package name jsonwebtoken Highest
Vendor Manifest build-jdk-spec 1.7 Low
Vendor Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Vendor Manifest bundle-symbolicname io.jsonwebtoken.jjwt-api Medium
Vendor Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-api Low
Vendor Manifest Implementation-Vendor jsonwebtoken.io High
Vendor Manifest Implementation-Vendor-Id io.jsonwebtoken Medium
Vendor Manifest specification-vendor jsonwebtoken.io Low
Vendor pom artifactid jjwt-api Low
Vendor pom groupid io.jsonwebtoken Highest
Vendor pom name JJWT :: API High
Vendor pom parent-artifactid jjwt-root Low
Product file name jjwt-api High
Product jar package name io Highest
Product jar package name jsonwebtoken Highest
Product Manifest build-jdk-spec 1.7 Low
Product Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Product Manifest Bundle-Name JJWT :: API Medium
Product Manifest bundle-symbolicname io.jsonwebtoken.jjwt-api Medium
Product Manifest Implementation-Title JJWT :: API High
Product Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-api Low
Product Manifest specification-title JJWT :: API Medium
Product pom artifactid jjwt-api Highest
Product pom groupid io.jsonwebtoken Highest
Product pom name JJWT :: API High
Product pom parent-artifactid jjwt-root Medium
Version file version 0.12.6 High
Version Manifest Bundle-Version 0.12.6 High
Version Manifest Implementation-Version 0.12.6 High
Version pom version 0.12.6 Highest
pkg:maven/io.jsonwebtoken/jjwt-api@0.12.6
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jjwt-impl-0.12.6.jar
Description:
JSON Web Token support for the JVM and Android
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jjwt-impl-0.12.6.jar
MD5: e96f699bad6353508953424e82e5de45
SHA1: ac23673a84b6089e0369fb8ab2c69edd91cd6eb0
SHA256: ad80ceda467ddab64f0e729257dd5f72f61487cc3b92e696270e620f0d88168f
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jjwt-impl High
Vendor jar package name impl Highest
Vendor jar package name io Highest
Vendor jar package name jsonwebtoken Highest
Vendor Manifest build-jdk-spec 1.7 Low
Vendor Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Vendor Manifest bundle-symbolicname io.jsonwebtoken.jjwt-impl Medium
Vendor Manifest fragment-host io.jsonwebtoken.jjwt-api Low
Vendor Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-impl Low
Vendor Manifest Implementation-Vendor jsonwebtoken.io High
Vendor Manifest Implementation-Vendor-Id io.jsonwebtoken Medium
Vendor Manifest specification-vendor jsonwebtoken.io Low
Vendor pom artifactid jjwt-impl Low
Vendor pom groupid io.jsonwebtoken Highest
Vendor pom name JJWT :: Impl High
Vendor pom parent-artifactid jjwt-root Low
Product file name jjwt-impl High
Product jar package name impl Highest
Product jar package name io Highest
Product jar package name jsonwebtoken Highest
Product Manifest build-jdk-spec 1.7 Low
Product Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Product Manifest Bundle-Name JJWT :: Impl Medium
Product Manifest bundle-symbolicname io.jsonwebtoken.jjwt-impl Medium
Product Manifest fragment-host io.jsonwebtoken.jjwt-api Low
Product Manifest Implementation-Title JJWT :: Impl High
Product Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-impl Low
Product Manifest specification-title JJWT :: Impl Medium
Product pom artifactid jjwt-impl Highest
Product pom groupid io.jsonwebtoken Highest
Product pom name JJWT :: Impl High
Product pom parent-artifactid jjwt-root Medium
Version file version 0.12.6 High
Version Manifest Bundle-Version 0.12.6 High
Version Manifest Implementation-Version 0.12.6 High
Version pom version 0.12.6 Highest
pkg:maven/io.jsonwebtoken/jjwt-impl@0.12.6
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jjwt-jackson-0.12.6.jar
Description:
JSON Web Token support for the JVM and Android
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jjwt-jackson-0.12.6.jar
MD5: a6f99a3cc5d2c7fd820f2aad638ca401
SHA1: f141e0c1136ba17f2632858238a31ae05642dbf8
SHA256: 8f8c293730fa0241a0f882b6128c3e5b2c07f3ff3e6391126ef71e73ecb24ea0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jjwt-jackson High
Vendor jar package name io Highest
Vendor jar package name jackson Highest
Vendor jar package name jsonwebtoken Highest
Vendor Manifest build-jdk-spec 1.7 Low
Vendor Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Vendor Manifest bundle-symbolicname io.jsonwebtoken.jjwt-jackson Medium
Vendor Manifest fragment-host io.jsonwebtoken.jjwt-api Low
Vendor Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-jackson Low
Vendor Manifest Implementation-Vendor jsonwebtoken.io High
Vendor Manifest Implementation-Vendor-Id io.jsonwebtoken Medium
Vendor Manifest specification-vendor jsonwebtoken.io Low
Vendor pom artifactid jjwt-jackson Low
Vendor pom groupid io.jsonwebtoken Highest
Vendor pom name JJWT :: Extensions :: Jackson High
Vendor pom parent-artifactid jjwt-root Low
Product file name jjwt-jackson High
Product jar package name io Highest
Product jar package name jackson Highest
Product jar package name jsonwebtoken Highest
Product Manifest build-jdk-spec 1.7 Low
Product Manifest bundle-docurl https://github.com/jwtk/jjwt Low
Product Manifest Bundle-Name JJWT :: Extensions :: Jackson Medium
Product Manifest bundle-symbolicname io.jsonwebtoken.jjwt-jackson Medium
Product Manifest fragment-host io.jsonwebtoken.jjwt-api Low
Product Manifest Implementation-Title JJWT :: Extensions :: Jackson High
Product Manifest implementation-url https://github.com/jwtk/jjwt/jjwt-jackson Low
Product Manifest specification-title JJWT :: Extensions :: Jackson Medium
Product pom artifactid jjwt-jackson Highest
Product pom groupid io.jsonwebtoken Highest
Product pom name JJWT :: Extensions :: Jackson High
Product pom parent-artifactid jjwt-root Medium
Version file version 0.12.6 High
Version Manifest Bundle-Version 0.12.6 High
Version Manifest Implementation-Version 0.12.6 High
Version pom version 0.12.6 Highest
pkg:maven/io.jsonwebtoken/jjwt-jackson@0.12.6
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jna-5.17.0.jar
Description:
JNA Library
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jna-5.17.0.jar
MD5: 08fc1e1f239ec4511e8d9e5a433f6244
SHA1: 33d12735bef894440780fce64f9758d420c7bae2
SHA256: b3a9408e7c51e08ef0e3bfcc08f443f6ec0f6191ba8cd7c18d53d2b22e5bdbc0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jna High
Vendor jar package name jna Highest
Vendor jar package name jna Low
Vendor jar package name sun Highest
Vendor jar package name sun Low
Vendor jar (hint) package name oracle Highest
Vendor jar (hint) package name oracle Low
Vendor Manifest automatic-module-name com.sun.jna Medium
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname com.sun.jna Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Product file name jna High
Product jar package name jna Highest
Product jar package name jna Low
Product jar package name library Highest
Product jar package name native Highest
Product jar package name sun Highest
Product jar package name win32 Highest
Product Manifest automatic-module-name com.sun.jna Medium
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna Medium
Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname com.sun.jna Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Version file name jna Medium
Version file version 5.17.0 High
Version jar package name jna Highest
Version jar package name sun Highest
Version jar package name win32 Highest
Version Manifest Bundle-Version 5.17.0 High
Version Manifest Implementation-Version 5.17.0 (b0) High
cpe:2.3:a:oracle:java_se:5.17.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: jna-5.17.0.jar: jnidispatch.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jna-5.17.0.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256: b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
sharepoint-online-connector-0.9.4.war: jna-5.17.0.jar: jnidispatch.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jna-5.17.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256: 5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
sharepoint-online-connector-0.9.4.war: jna-5.17.0.jar: jnidispatch.dll
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jna-5.17.0.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256: 752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
sharepoint-online-connector-0.9.4.war: jna-platform-5.17.0.jar
Description:
JNA Platform Library
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jna-platform-5.17.0.jar
MD5: e0ae0c295de31af32a3800e56a5263be
SHA1: a4934c44d25a9d8c2ddf4203affd20330cb3426f
SHA256: b7e3d46c87bad2eb409b0e704916bcd81206168e357312dfddd0e253679cd9e0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jna-platform High
Vendor jar package name jna Highest
Vendor jar package name jna Low
Vendor jar package name platform Highest
Vendor jar package name platform Low
Vendor jar package name sun Highest
Vendor jar package name sun Low
Vendor jar (hint) package name oracle Highest
Vendor jar (hint) package name oracle Low
Vendor Manifest automatic-module-name com.sun.jna.platform Medium
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Product file name jna-platform High
Product jar package name jna Highest
Product jar package name jna Low
Product jar package name platform Highest
Product jar package name platform Low
Product jar package name sun Highest
Product jar package name win32 Low
Product Manifest automatic-module-name com.sun.jna.platform Medium
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna-platform Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Product Manifest bundle-symbolicname com.sun.jna.platform Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Version file name jna-platform Medium
Version file version 5.17.0 High
Version Manifest Bundle-Version 5.17.0 High
Version Manifest Implementation-Version 5.17.0 (b0) High
sharepoint-online-connector-0.9.4.war: jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
sharepoint-online-connector-0.9.4.war: jwks-rsa-0.22.2.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/jwks-rsa-0.22.2.jar
MD5: e9e463a71278978e3f8e3e0ea0e8c489
SHA1: 07a45ec6ea44ba5da209b29fbf9d8098f2bb3e5a
SHA256: 368d98719dcefcb54aee84375ee7b5191ac9be30dfbde121252478be9bdf8ebd
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name jwks-rsa High
Vendor jar package name auth0 Low
Vendor jar package name jwk Low
Product file name jwks-rsa High
Product jar package name jwk Low
Version file name jwks-rsa Medium
Version file version 0.22.2 High
sharepoint-online-connector-0.9.4.war: kotlin-stdlib-1.9.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/kotlin-stdlib-1.9.10.jar
MD5: da8348128b101f854fafa9a31e3806bd
SHA1: 72812e8a368917ab5c0a5081b56915ffdfec93b7
SHA256: 55e989c512b80907799f854309f3bc7782c5b3d13932442d0379d5c472711504
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name kotlin-stdlib High
Vendor jar package name kotlin Low
Vendor Manifest Implementation-Vendor JetBrains High
Vendor Manifest kotlin-runtime-component Main Low
Vendor Manifest multi-release true Low
Product file name kotlin-stdlib High
Product jar package name kotlin Highest
Product Manifest Implementation-Title kotlin-stdlib High
Product Manifest kotlin-runtime-component Main Low
Product Manifest multi-release true Low
Version file name kotlin-stdlib Medium
Version file version 1.9.10 High
Version Manifest Implementation-Version 1.9.10-release-459 High
Related Dependencies
sharepoint-online-connector-0.9.4.war: kotlin-stdlib-common-1.9.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/kotlin-stdlib-common-1.9.10.jar
MD5: de4024a53c843e959f2d50ecd1f0e951
SHA1: dafaf2c27f27c09220cee312df10917d9a5d97ce
SHA256: cde3341ba18a2ba262b0b7cf6c55b20c90e8d434e42c9a13e6a3f770db965a88
sharepoint-online-connector-0.9.4.war: kotlin-stdlib-jdk7-1.9.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/kotlin-stdlib-jdk7-1.9.10.jar
MD5: 14f35bcc452b095f3034a1471960cccc
SHA1: bc5bfc2690338defd5195b05c57562f2194eeb10
SHA256: ac6361bf9ad1ed382c2103d9712c47cdec166232b4903ed596e8876b0681c9b7
sharepoint-online-connector-0.9.4.war: kotlin-stdlib-jdk8-1.9.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/kotlin-stdlib-jdk8-1.9.10.jar
MD5: d223cbd9e57f02cf4e9f3d9ed01edcee
SHA1: c7510d64a83411a649c76f2778304ddf71d7437b
SHA256: a4c74d94d64ce1abe53760fe0389dd941f6fc558d0dab35e47c085a11ec80f28
cpe:2.3:a:jetbrains:kotlin:1.9.10:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2020-29582 suppress
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CWE-276 Incorrect Default Permissions
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
Description:
An empty artifact that Guava depends on to signal that it is providing
ListenableFuture -- but is also available in a second "version" that
contains com.google.common.util.concurrent.ListenableFuture class, without
any other Guava classes. The idea is:
- If users want only ListenableFuture, they depend on listenablefuture-1.0.
- If users want all of Guava, they depend on guava, which, as of Guava
27.0, depends on
listenablefuture-9999.0-empty-to-avoid-conflict-with-guava. The 9999.0-...
version number is enough for some build systems (notably, Gradle) to select
that empty artifact over the "real" listenablefuture-1.0 -- avoiding a
conflict with the copy of ListenableFuture in guava itself. If users are
using an older version of Guava or a build system other than Gradle, they
may see class conflicts. If so, they can solve them by manually excluding
the listenablefuture artifact or manually forcing their build systems to
use 9999.0-....
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
MD5: d094c22570d65e132c19cea5d352e381
SHA1: b421526c5f297295adef1c886e5246c39d4ac629
SHA256: b372a037d4230aa57fbeffdef30fd6123f9c0c2db85d0aced00c91b974f33f99
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name listenablefuture High
Vendor pom artifactid listenablefuture Low
Vendor pom groupid com.google.guava Highest
Vendor pom name Guava ListenableFuture only High
Vendor pom parent-artifactid guava-parent Low
Product file name listenablefuture High
Product pom artifactid listenablefuture Highest
Product pom groupid com.google.guava Highest
Product pom name Guava ListenableFuture only High
Product pom parent-artifactid guava-parent Medium
Version pom parent-version 9999.0-empty-to-avoid-conflict-with-guava Low
Version pom version 9999.0-empty-to-avoid-conflict-with-guava Highest
pkg:maven/com.google.guava/listenablefuture@9999.0-empty-to-avoid-conflict-with-guava
(Confidence :High)
sharepoint-online-connector-0.9.4.war: microsoft-graph-6.55.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-graph-6.55.0.jar
MD5: c28a4d04927a9553c271070978423505
SHA1: 7b3717c9edd51b323cf10217d06e1e01ff90a717
SHA256: 6e91e13e69b843e450ad0b5c90945b96619f193a632419f69c54f9dffb1b3810
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name microsoft-graph High
Vendor jar package name graph Highest
Vendor jar package name graph Low
Vendor jar package name microsoft Highest
Vendor jar package name microsoft Low
Vendor Manifest automatic-module-name com.microsoft.graph Medium
Product file name microsoft-graph High
Product jar package name graph Highest
Product jar package name graph Low
Product jar package name item Low
Product jar package name microsoft Highest
Product Manifest automatic-module-name com.microsoft.graph Medium
Version file name microsoft-graph Medium
Version file version 6.55.0 High
sharepoint-online-connector-0.9.4.war: microsoft-graph-core-3.6.4.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-graph-core-3.6.4.jar
MD5: 3ce1b081c48eb9e65dcd1353c0a3090b
SHA1: e73861bbec703ff1fc0a540d8c51eea0cee1ed9f
SHA256: e9798d7d0d9afca1b405e563ef0d6175a0932d8b0f7c9206b5a752a03d0f6c65
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name microsoft-graph-core High
Vendor jar package name core Highest
Vendor jar package name core Low
Vendor jar package name graph Highest
Vendor jar package name graph Low
Vendor jar package name microsoft Highest
Vendor jar package name microsoft Low
Vendor Manifest automatic-module-name com.microsoft.graph.core Medium
Product file name microsoft-graph-core High
Product jar package name core Highest
Product jar package name core Low
Product jar package name graph Highest
Product jar package name graph Low
Product jar package name microsoft Highest
Product Manifest automatic-module-name com.microsoft.graph.core Medium
Version file name microsoft-graph-core Medium
Version file version 3.6.4 High
sharepoint-online-connector-0.9.4.war: microsoft-kiota-http-okHttp-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-http-okHttp-1.8.10.jar
MD5: ac01072306f277f5709def5c2c4e2a68
SHA1: 18b68d3310130d551b729fc7cc1bd6463001cd0b
SHA256: 83b155e265ec4be98f67e4d17c29dd1dd5f0833a8fa47dd15f751d97987f434a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name microsoft-kiota-http-okHttp High
Vendor jar package name http Low
Vendor jar package name kiota Highest
Vendor jar package name kiota Low
Vendor jar package name microsoft Highest
Vendor jar package name microsoft Low
Vendor Manifest automatic-module-name com.microsoft.kiota Medium
Product file name microsoft-kiota-http-okHttp High
Product jar package name http Low
Product jar package name kiota Highest
Product jar package name kiota Low
Product jar package name microsoft Highest
Product jar package name middleware Low
Product Manifest automatic-module-name com.microsoft.kiota Medium
Version file name microsoft-kiota-http-okHttp Medium
Version file version 1.8.10 High
Related Dependencies
sharepoint-online-connector-0.9.4.war: microsoft-kiota-abstractions-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-abstractions-1.8.10.jar
MD5: ecf343bf4e95008ba6de0865653e0952
SHA1: 6f4f70f558f7e00ac258bb3be2d1873e144d2c0b
SHA256: 783ffa60c3dddda3fd7ee6312747b2b1810c7d6304b4050d7099fd7b1498f55c
sharepoint-online-connector-0.9.4.war: microsoft-kiota-authentication-azure-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-authentication-azure-1.8.10.jar
MD5: 5fc0f0a8d71e7dc166ae018f5b581758
SHA1: c2e48306b0dcac7a35f5caa6c93e5979a72fcd42
SHA256: c04eda7e482e321aa21dacdb787a14fbc9da067193827a29d91dbc4041ee718d
sharepoint-online-connector-0.9.4.war: microsoft-kiota-serialization-form-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-serialization-form-1.8.10.jar
MD5: 6a3fb6105f44cc0f14aa98fea8114b6c
SHA1: 7abeea510661b75ff9035078c6e79ec0c7c7ce65
SHA256: 2c351505186b762bc4600ba94dd21654afea3b9a8aba2231738bed1c4a5340ea
sharepoint-online-connector-0.9.4.war: microsoft-kiota-serialization-json-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-serialization-json-1.8.10.jar
MD5: fa85a7f484608017867ff1100e80df3d
SHA1: 7647278d621419a9ddddf3767bb439c39d05553f
SHA256: 52974b4e114b00f91f8635d65b2edf79bfd35268cce1f9170a471fbc1bdedb33
sharepoint-online-connector-0.9.4.war: microsoft-kiota-serialization-multipart-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-serialization-multipart-1.8.10.jar
MD5: 935e0900c7f6ae3591d1c96dd6f36663
SHA1: 5c602d35f90db170544ef7442c5046cc6dfeb249
SHA256: 758b62785936109c2192ab2ec88707869b15cc0a68d740cddfd0b5aa3eee46bd
sharepoint-online-connector-0.9.4.war: microsoft-kiota-serialization-text-1.8.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/microsoft-kiota-serialization-text-1.8.10.jar
MD5: 9b928b584091528dd875e3704876945d
SHA1: 915fad6ada67acda5f6a805c90078d6a5922502f
SHA256: 7ffbd899d863a17b0d62415ba2b5a7594946cd5d187657a8c3e68b27f14d4b3c
cpe:2.3:a:microsoft:kiota:1.8.10:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2026-41134 suppress
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, and default value emission). When malicious values from an OpenAPI description are emitted into generated source without context-appropriate escaping, an attacker can break out of string literals and inject additional code into generated clients. This issue is only practically exploitable when the OpenAPI description used for generation is from an untrusted source, or a normally trusted OpenAPI description has been compromised/tampered with. Only generating from trusted, integrity-protected API descriptions significantly reduces the risk. To remediate the issue, upgrade Kiota to 1.31.1 or later and regenerate/refresh existing generated clients as a precaution. Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.
CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv4:
Base Score: HIGH (7.3)
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
sharepoint-online-connector-0.9.4.war: msal4j-1.23.1.jar
Description:
Microsoft Authentication Library for Java gives you the ability to obtain tokens from Azure AD v2 (work and school
accounts, MSA) and Azure AD B2C, gaining access to Microsoft Cloud API and any other API secured by Microsoft
identities
License:
MIT License
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/msal4j-1.23.1.jar
MD5: 83292e43f99fe6b47c3419bb581d4f5b
SHA1: 6c722b514873b24a4e1ce9c22dca36ea3c22bdbe
SHA256: 414d4fe3c66c7bb1a741014f352e5f0a8329172703e7fbb0020d232a8c8385b1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name msal4j High
Vendor jar package name aad Highest
Vendor jar package name microsoft Highest
Vendor jar package name msal4j Highest
Vendor Manifest automatic-module-name com.microsoft.aad.msal4j Medium
Vendor Manifest bundle-developers msopentech;name="Microsoft Open Technologies, Inc." Low
Vendor Manifest bundle-docurl https://github.com/AzureAD/microsoft-authentication-library-for-java Low
Vendor Manifest bundle-symbolicname msal4j Medium
Vendor Manifest Implementation-Vendor-Id com.microsoft.azure Medium
Vendor pom artifactid msal4j Low
Vendor pom developer id msopentech Medium
Vendor pom developer name Microsoft Open Technologies, Inc. Medium
Vendor pom groupid com.microsoft.azure Highest
Vendor pom name msal4j High
Vendor pom url AzureAD/microsoft-authentication-library-for-java Highest
Product file name msal4j High
Product jar package name aad Highest
Product jar package name microsoft Highest
Product jar package name msal4j Highest
Product Manifest automatic-module-name com.microsoft.aad.msal4j Medium
Product Manifest bundle-developers msopentech;name="Microsoft Open Technologies, Inc." Low
Product Manifest bundle-docurl https://github.com/AzureAD/microsoft-authentication-library-for-java Low
Product Manifest Bundle-Name msal4j Medium
Product Manifest bundle-symbolicname msal4j Medium
Product Manifest Implementation-Title msal4j High
Product Manifest specification-title msal4j Medium
Product pom artifactid msal4j Highest
Product pom developer id msopentech Low
Product pom developer name Microsoft Open Technologies, Inc. Low
Product pom groupid com.microsoft.azure Highest
Product pom name msal4j High
Product pom url AzureAD/microsoft-authentication-library-for-java High
Version file version 1.23.1 High
Version Manifest Bundle-Version 1.23.1 High
Version Manifest Implementation-Version 1.23.1 High
Version pom version 1.23.1 Highest
pkg:maven/com.microsoft.azure/msal4j@1.23.1
(Confidence :High)
cpe:2.3:a:microsoft:authentication_library:1.23.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
CVE-2024-35255 suppress
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: msal4j-persistence-extension-1.3.0.jar
Description:
Implementation of ITokenCacheAccessAspect interface defined in Java MSAL SDK (artifactId - msal4j)
for persistence of token cache in platform specific secret storage:
* Win - file encrypted with DPAPI
* Mac - key chain
* Linux - key ring
License:
MIT License
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/msal4j-persistence-extension-1.3.0.jar
MD5: 7bc0a0a50fd149b732e1fbec92a4b0a3
SHA1: 8a8ef1517d27a5b4de1512ef94679bdb59f210b6
SHA256: dfc41c817fbfa76057af6ffe4379dbca6a5e16b8e87df8bdda23f371756c2d09
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name msal4j-persistence-extension High
Vendor jar package name microsoft Highest
Vendor jar package name persistence Highest
Vendor Manifest Implementation-Vendor-Id com.microsoft.azure Medium
Vendor pom artifactid msal4j-persistence-extension Low
Vendor pom developer id ms Medium
Vendor pom developer name Microsoft Corporation Medium
Vendor pom groupid com.microsoft.azure Highest
Vendor pom name msal4j-persistence-extension High
Vendor pom url AzureAD/microsoft-authentication-library-for-java Highest
Product file name msal4j-persistence-extension High
Product jar package name microsoft Highest
Product jar package name persistence Highest
Product Manifest Implementation-Title msal4j-persistence-extension High
Product Manifest specification-title msal4j-persistence-extension Medium
Product pom artifactid msal4j-persistence-extension Highest
Product pom developer id ms Low
Product pom developer name Microsoft Corporation Low
Product pom groupid com.microsoft.azure Highest
Product pom name msal4j-persistence-extension High
Product pom url AzureAD/microsoft-authentication-library-for-java High
Version file version 1.3.0 High
Version Manifest Implementation-Version 1.3.0 High
Version pom version 1.3.0 Highest
pkg:maven/com.microsoft.azure/msal4j-persistence-extension@1.3.0
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-buffer-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-buffer-4.1.127.Final.jar
MD5: 4b5c9cc04745c23c4238a3a7a05f9272
SHA1: 356b4f2e759d36fec774cd17e583a7609d8ec15d
SHA256: 4a0a17dc5a58d910c56545be6912b9923cfe902522dc1df268e774bc22443eb6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-buffer High
Vendor jar package name buffer Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.buffer Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.buffer Medium
Vendor Manifest implementation-url https://netty.io/netty-buffer/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-buffer Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Buffer High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-buffer High
Product jar package name buffer Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.buffer Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Buffer Medium
Product Manifest bundle-symbolicname io.netty.buffer Medium
Product Manifest Implementation-Title Netty/Buffer High
Product Manifest implementation-url https://netty.io/netty-buffer/ Low
Product Manifest specification-title Netty/Buffer Medium
Product pom artifactid netty-buffer Highest
Product pom groupid io.netty Highest
Product pom name Netty/Buffer High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-buffer@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-codec-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-4.1.127.Final.jar
MD5: 29493708bfdee16a32c4d5a26a7a88af
SHA1: b05d16b459b6c6042197a1f3aef671cf535767c3
SHA256: 187d21cee1a114f43b87be235f66c83828bdd0a3e0c1cdfebedaa37748e6e470
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec Medium
Vendor Manifest implementation-url https://netty.io/netty-codec/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec Medium
Product Manifest bundle-symbolicname io.netty.codec Medium
Product Manifest Implementation-Title Netty/Codec High
Product Manifest implementation-url https://netty.io/netty-codec/ Low
Product Manifest specification-title Netty/Codec Medium
Product pom artifactid netty-codec Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-codec@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-codec-dns-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-dns-4.1.127.Final.jar
MD5: 1184c9fd3cb612a5d579f7f1270bb157
SHA1: bcb5a439fc94dacaf98bac2426e40f21376a8e1a
SHA256: 4398b97193aad6bf2a9a90ad86a83b892b62589a4a2c90d0d0a3d94a71b47976
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-dns High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.dns Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-dns Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-dns/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-dns Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/DNS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-dns High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.dns Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/DNS Medium
Product Manifest bundle-symbolicname io.netty.codec-dns Medium
Product Manifest Implementation-Title Netty/Codec/DNS High
Product Manifest implementation-url https://netty.io/netty-codec-dns/ Low
Product Manifest specification-title Netty/Codec/DNS Medium
Product pom artifactid netty-codec-dns Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/DNS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-codec-dns@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-codec-http-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-http-4.1.127.Final.jar
MD5: 309fabe1546e66ff9842dd4ae569902f
SHA1: c4c3fa12be76064a7a96631959641bcd600e6556
SHA256: 2408776c87c1808b5522298c25e8290427123763f4addfda02dff6a24a538f61
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP Medium
Product Manifest bundle-symbolicname io.netty.codec-http Medium
Product Manifest Implementation-Title Netty/Codec/HTTP High
Product Manifest implementation-url https://netty.io/netty-codec-http/ Low
Product Manifest specification-title Netty/Codec/HTTP Medium
Product pom artifactid netty-codec-http Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-codec-http@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-codec-http2-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-http2-4.1.127.Final.jar
MD5: a134e194077ed67bfc94ad24cadf8c7e
SHA1: 39cf7a8790047fecda2c1fe87ee54d2f32aefb45
SHA256: 0eb1befa55f785b47729d58d4fce72abea73b7f48fc1c434d71953e6a558ffaa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http2 High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http2 Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http2 Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP2 High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http2 High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP2 Medium
Product Manifest bundle-symbolicname io.netty.codec-http2 Medium
Product Manifest Implementation-Title Netty/Codec/HTTP2 High
Product Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Product Manifest specification-title Netty/Codec/HTTP2 Medium
Product pom artifactid netty-codec-http2 Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP2 High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-codec-http2@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-codec-socks-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-socks-4.1.127.Final.jar
MD5: bc40c14c9acde31c0cb32a49a97d071f
SHA1: c664f38b0f004e6b4ecf64f826939e24a56cbe9c
SHA256: d3d251f9239951a845f22e39191f95471fb2eb7951b9878ea4555ccac99529fb
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-socks High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.socks Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-socks Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-socks Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/Socks High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-socks High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.socks Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/Socks Medium
Product Manifest bundle-symbolicname io.netty.codec-socks Medium
Product Manifest Implementation-Title Netty/Codec/Socks High
Product Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Product Manifest specification-title Netty/Codec/Socks Medium
Product pom artifactid netty-codec-socks Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/Socks High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-codec-socks@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-common-4.1.127.Final.jar (shaded: org.jctools:jctools-core:4.0.5)
Description:
Java Concurrency Tools Core Library
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-common-4.1.127.Final.jar/META-INF/maven/org.jctools/jctools-core/pom.xml
MD5: 5d5135397b920a7dcbca5c1fb0576cf2
SHA1: eaa05d6ad937464312a2681a3236c0e06602bbb7
SHA256: a69897b8ff0c2198b4b8cd7d4f93fde6d42b8e9dbfc95553585e27587b24e211
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jctools-core Low
Vendor pom groupid org.jctools Highest
Vendor pom name Java Concurrency Tools Core Library High
Vendor pom url JCTools Highest
Product pom artifactid jctools-core Highest
Product pom groupid org.jctools Highest
Product pom name Java Concurrency Tools Core Library High
Product pom url JCTools High
Version pom version 4.0.5 Highest
pkg:maven/org.jctools/jctools-core@4.0.5
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-common-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-common-4.1.127.Final.jar
MD5: 2a00ede31389e68fa4bb5cb7ff0c6f13
SHA1: ada4ab671678f956e1cd5067ba94bc340af1d8bf
SHA256: a6732bb70dc15ed96aa33ecca82c0d7b20f8ff41adf04f74f168f626adf359e8
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-common High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.common Medium
Vendor Manifest implementation-url https://netty.io/netty-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-common High
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Common Medium
Product Manifest bundle-symbolicname io.netty.common Medium
Product Manifest Implementation-Title Netty/Common High
Product Manifest implementation-url https://netty.io/netty-common/ Low
Product Manifest specification-title Netty/Common Medium
Product pom artifactid netty-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Common High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-common@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-handler-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-handler-4.1.127.Final.jar
MD5: 34add5070e2132ea2238d27aca710dc7
SHA1: 5e9ee8931666a12b52340309f92d51d0b49611de
SHA256: 88b6892bc1321d32409392e5b9f94e59d8e800678c029c71e7c0d76daf6050d0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler High
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.handler Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler Medium
Vendor Manifest implementation-url https://netty.io/netty-handler/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler High
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.handler Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler Medium
Product Manifest bundle-symbolicname io.netty.handler Medium
Product Manifest Implementation-Title Netty/Handler High
Product Manifest implementation-url https://netty.io/netty-handler/ Low
Product Manifest specification-title Netty/Handler Medium
Product pom artifactid netty-handler Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-handler@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-handler-proxy-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-handler-proxy-4.1.127.Final.jar
MD5: 9334275c874e64d715ce7e9deb891b5d
SHA1: 85cfd39769b7f12ae56b7e46ed506a9ac0daeef4
SHA256: 2c0c8046e5d737e08f40a7c2907526648860d0434e125bd51de3c2cf390453fb
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler-proxy High
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name proxy Highest
Vendor Manifest automatic-module-name io.netty.handler.proxy Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler-proxy Medium
Vendor Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler-proxy Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler/Proxy High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler-proxy High
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name proxy Highest
Product Manifest automatic-module-name io.netty.handler.proxy Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler/Proxy Medium
Product Manifest bundle-symbolicname io.netty.handler-proxy Medium
Product Manifest Implementation-Title Netty/Handler/Proxy High
Product Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Product Manifest specification-title Netty/Handler/Proxy Medium
Product pom artifactid netty-handler-proxy Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler/Proxy High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-handler-proxy@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-resolver-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-4.1.127.Final.jar
MD5: 6b5b753699903056c1ebb650b4fb7e24
SHA1: 2b34a14b6ec23761d6d2300a1c261914401f2553
SHA256: a57ee62deb54ed99690db2696039f0f768a65c974677946ed48b2a2d8510ded3
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver High
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver Medium
Product Manifest bundle-symbolicname io.netty.resolver Medium
Product Manifest Implementation-Title Netty/Resolver High
Product Manifest implementation-url https://netty.io/netty-resolver/ Low
Product Manifest specification-title Netty/Resolver Medium
Product pom artifactid netty-resolver Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-resolver@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-4.1.127.Final.jar
MD5: e90fc410d21b69b25d1417deddec7359
SHA1: 568ff6c6a899ffc64d4a7a461059291dcc502062
SHA256: a9b619a902ede5ced0579082734011111d099a52f512d03a17f9a7d79afa3c69
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns High
Vendor jar package name dns Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver.dns Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns High
Product jar package name dns Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver.dns Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS Medium
Product Manifest bundle-symbolicname io.netty.resolver-dns Medium
Product Manifest Implementation-Title Netty/Resolver/DNS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns/ Low
Product Manifest specification-title Netty/Resolver/DNS Medium
Product pom artifactid netty-resolver-dns Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-resolver-dns@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-classes-macos-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-classes-macos-4.1.127.Final.jar
MD5: 900628972c3c9cd7c2a003e8dac00887
SHA1: 21c93bc3a412afeac8deb10874d6dc7cfb961ea0
SHA256: 2ac04be6bee607331e0f09a57c9f724ae0947a39702d98b23ec1b6a74dd82076
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns-classes-macos High
Vendor jar package name dns Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver.dns.classes.macos Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns-classes-macos Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns-classes-macos/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns-classes-macos Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS/Classes/MacOS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns-classes-macos High
Product jar package name dns Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver.dns.classes.macos Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS/Classes/MacOS Medium
Product Manifest bundle-symbolicname io.netty.resolver-dns-classes-macos Medium
Product Manifest Implementation-Title Netty/Resolver/DNS/Classes/MacOS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns-classes-macos/ Low
Product Manifest specification-title Netty/Resolver/DNS/Classes/MacOS Medium
Product pom artifactid netty-resolver-dns-classes-macos Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS/Classes/MacOS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-resolver-dns-classes-macos@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-native-macos-4.1.127.Final-osx-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-native-macos-4.1.127.Final-osx-x86_64.jar
MD5: 5b0d0e5bad46b47cd3a5e5a2740b2111
SHA1: 310929708225c05f4dd99015523eccabf1493bc2
SHA256: 85956fdc92618f3880c612f0943d4e91c9dcd543f4c58fa055d04dfa64bf8f66
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns-native-macos High
Vendor Manifest automatic-module-name io.netty.resolver.dns.macos.osx.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_resolver_dns_native_macos_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns-native-macos.osx-x86_64 Medium
Vendor Manifest fragment-host io.netty.resolver-dns-classes-macos Low
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns-native-macos/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns-native-macos Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS/Native/MacOS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns-native-macos High
Product Manifest automatic-module-name io.netty.resolver.dns.macos.osx.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS/Native/MacOS Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_resolver_dns_native_macos_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Product Manifest bundle-symbolicname io.netty.resolver-dns-native-macos.osx-x86_64 Medium
Product Manifest fragment-host io.netty.resolver-dns-classes-macos Low
Product Manifest Implementation-Title Netty/Resolver/DNS/Native/MacOS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns-native-macos/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Resolver/DNS/Native/MacOS Medium
Product pom artifactid netty-resolver-dns-native-macos Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS/Native/MacOS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-resolver-dns-native-macos@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-tcnative-boringssl-static-2.0.74.Final.jar
Description:
A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
to BoringSSL and Apache APR.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-tcnative-boringssl-static-2.0.74.Final.jar
MD5: 0504e9b897e0e20dc0dca5c8869b89bc
SHA1: 536b68a3bdabab178c042402150309db00e8f54d
SHA256: ec3b14ceff74c5d7e24a378e64074744cc5e7035c49cf6ca0a4e23dff9713d1f
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-tcnative-boringssl-static High
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.tcnative-boringssl-static Medium
Vendor Manifest fragment-host io.netty.tcnative-classes Low
Vendor Manifest implementation-url https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-tcnative-boringssl-static Low
Vendor pom developer email netty@googlegroups.com Low
Vendor pom developer id netty.io Medium
Vendor pom developer name The Netty Project Contributors Medium
Vendor pom developer org The Netty Project Medium
Vendor pom developer org URL https://netty.io/ Medium
Vendor pom groupid io.netty Highest
Vendor pom name Netty/TomcatNative [BoringSSL - Static] High
Vendor pom url netty/netty-tcnative/netty-tcnative-boringssl-static/ Highest
Product file name netty-tcnative-boringssl-static High
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/TomcatNative [BoringSSL - Static] Medium
Product Manifest bundle-symbolicname io.netty.tcnative-boringssl-static Medium
Product Manifest fragment-host io.netty.tcnative-classes Low
Product Manifest Implementation-Title Netty/TomcatNative [BoringSSL - Static] High
Product Manifest implementation-url https://github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/ Low
Product Manifest multi-release true Low
Product Manifest specification-title Netty/TomcatNative [BoringSSL - Static] Medium
Product pom artifactid netty-tcnative-boringssl-static Highest
Product pom developer email netty@googlegroups.com Low
Product pom developer id netty.io Low
Product pom developer name The Netty Project Contributors Low
Product pom developer org The Netty Project Low
Product pom developer org URL https://netty.io/ Low
Product pom groupid io.netty Highest
Product pom name Netty/TomcatNative [BoringSSL - Static] High
Product pom url netty/netty-tcnative/netty-tcnative-boringssl-static/ High
Version Manifest Bundle-Version 2.0.74.Final High
Version Manifest Implementation-Version 2.0.74.Final High
Version pom version 2.0.74.Final Highest
pkg:maven/io.netty/netty-tcnative-boringssl-static@2.0.74.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-tcnative-classes-2.0.74.Final.jar
Description:
A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is dynamically linked
to OpenSSL and Apache APR.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-tcnative-classes-2.0.74.Final.jar
MD5: d08736a30c50e4348174a542ed3cc446
SHA1: c3b2e6ac13230849355f7ecaaeb12668a22e9c0a
SHA256: 194874cf723794dd409fd1e728cd91ffbcff0584d73b4d8a1ad0d69d04acf9b3
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-tcnative-classes High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name tcnative Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.tcnative-classes Medium
Vendor Manifest implementation-url https://github.com/netty/netty-tcnative/netty-tcnative-classes/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-tcnative-classes Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/TomcatNative [OpenSSL - Classes] High
Vendor pom parent-artifactid netty-tcnative-parent Low
Product file name netty-tcnative-classes High
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name tcnative Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/TomcatNative [OpenSSL - Classes] Medium
Product Manifest bundle-symbolicname io.netty.tcnative-classes Medium
Product Manifest Implementation-Title Netty/TomcatNative [OpenSSL - Classes] High
Product Manifest implementation-url https://github.com/netty/netty-tcnative/netty-tcnative-classes/ Low
Product Manifest multi-release true Low
Product Manifest specification-title Netty/TomcatNative [OpenSSL - Classes] Medium
Product pom artifactid netty-tcnative-classes Highest
Product pom groupid io.netty Highest
Product pom name Netty/TomcatNative [OpenSSL - Classes] High
Product pom parent-artifactid netty-tcnative-parent Medium
Version Manifest Bundle-Version 2.0.74.Final High
Version Manifest Implementation-Version 2.0.74.Final High
Version pom version 2.0.74.Final Highest
pkg:maven/io.netty/netty-tcnative-classes@2.0.74.Final
(Confidence :High)
cpe:2.3:a:openssl:openssl:2.0.74:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: netty-transport-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-4.1.127.Final.jar
MD5: c3034b7b846baad3128f2d588532ecd9
SHA1: 9925d9d6be72436b661ba6a71cc8d2897fe83cf0
SHA256: 0d1ad82bc658f9919ca750cebe2571d4b0ae4514ec781964091f405343760e92
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport Medium
Vendor Manifest implementation-url https://netty.io/netty-transport/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport High
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport Medium
Product Manifest bundle-symbolicname io.netty.transport Medium
Product Manifest Implementation-Title Netty/Transport High
Product Manifest implementation-url https://netty.io/netty-transport/ Low
Product Manifest specification-title Netty/Transport Medium
Product pom artifactid netty-transport Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-transport-classes-epoll-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-classes-epoll-4.1.127.Final.jar
MD5: 6570ebf4f6207c854b3fabde2c5d0943
SHA1: 03e1f9af9f34817b9cf613eedbaf87dfcdd3ccd9
SHA256: a39452eb911cb60068da6cdfd00e513b0a06e195b064fc44bd6fbfbc43c9527e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-epoll High
Vendor jar package name epoll Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-epoll High
Product jar package name epoll Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/Epoll Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Product Manifest Implementation-Title Netty/Transport/Classes/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Product Manifest specification-title Netty/Transport/Classes/Epoll Medium
Product pom artifactid netty-transport-classes-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/Epoll High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport-classes-epoll@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-transport-classes-kqueue-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-classes-kqueue-4.1.127.Final.jar
MD5: f36ce4994ddd2880d73efaf9928421d6
SHA1: 6a3d4ccfa70e58130d626ef7f5a3f95b5d1903b3
SHA256: 9428ce83fb5c6b482bfe2d8ce244a5d2370674aff6e7ff30ee89ce0d962964db
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-kqueue High
Vendor jar package name io Highest
Vendor jar package name kqueue Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.kqueue Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-kqueue Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-kqueue/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-kqueue Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/KQueue High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-kqueue High
Product jar package name io Highest
Product jar package name kqueue Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.kqueue Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/KQueue Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-kqueue Medium
Product Manifest Implementation-Title Netty/Transport/Classes/KQueue High
Product Manifest implementation-url https://netty.io/netty-transport-classes-kqueue/ Low
Product Manifest specification-title Netty/Transport/Classes/KQueue Medium
Product pom artifactid netty-transport-classes-kqueue Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/KQueue High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport-classes-kqueue@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-transport-native-epoll-4.1.127.Final-linux-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-epoll-4.1.127.Final-linux-x86_64.jar
MD5: 59fc2eed3eb5b82ebb663e5f4d6e2270
SHA1: 9a4657cd5fa3b7ac19698727b0891353c3ea1ce3
SHA256: 3d03f27eea1cd23357a56a96e1eeedfeb3d74fa0ba4d5c36a862bd035056275b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-epoll High
Vendor Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-epoll Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-epoll High
Product Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Epoll Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Product Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-epoll Low
Product Manifest Implementation-Title Netty/Transport/Native/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/Epoll Medium
Product pom artifactid netty-transport-native-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Epoll High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport-native-epoll@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-transport-native-kqueue-4.1.127.Final-osx-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-kqueue-4.1.127.Final-osx-x86_64.jar
MD5: cad5b26cde5b0d3d6801c43076ebc3d8
SHA1: 17031c708423849f8563b2f0705c17aa562e1c14
SHA256: d7d806a9f245492ec5898440478e1795a9ec95389a6de9aae53f13aae3276b71
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-kqueue High
Vendor Manifest automatic-module-name io.netty.transport.kqueue.osx.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_kqueue_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-kqueue.osx-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-kqueue Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-kqueue/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-kqueue Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/KQueue High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-kqueue High
Product Manifest automatic-module-name io.netty.transport.kqueue.osx.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/KQueue Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_kqueue_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Product Manifest bundle-symbolicname io.netty.transport-native-kqueue.osx-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-kqueue Low
Product Manifest Implementation-Title Netty/Transport/Native/KQueue High
Product Manifest implementation-url https://netty.io/netty-transport-native-kqueue/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/KQueue Medium
Product pom artifactid netty-transport-native-kqueue Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/KQueue High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport-native-kqueue@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: netty-transport-native-unix-common-4.1.127.Final.jar
Description:
Static library which contains common unix utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-unix-common-4.1.127.Final.jar
MD5: 9b41d899ea5338fd618fead158d243df
SHA1: 9cc0512d2ddfe9ae76c6db796e1980a8bdbadae1
SHA256: 0e3a45e3ce1fe034ca8b32c1579afa5f06729ca6427b7b0610528c4ef37c6e50
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-unix-common High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name unix Highest
Vendor Manifest automatic-module-name io.netty.transport.unix.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-unix-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Unix/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-unix-common High
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name unix Highest
Product Manifest automatic-module-name io.netty.transport.unix.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Unix/Common Medium
Product Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Product Manifest Implementation-Title Netty/Transport/Native/Unix/Common High
Product Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Product Manifest specification-title Netty/Transport/Native/Unix/Common Medium
Product pom artifactid netty-transport-native-unix-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Unix/Common High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
pkg:maven/io.netty/netty-transport-native-unix-common@4.1.127.Final
(Confidence :High)
sharepoint-online-connector-0.9.4.war: okhttp-4.12.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/okhttp-4.12.0.jar
MD5: 6acba053af88fed87e710c6c29911d7c
SHA1: 2f4525d4a200e97e1b87449c2cd9bd2e25b7e8cd
SHA256: b1050081b14bb7a3a7e55a4d3ef01b5dcfabc453b4573a4fc019767191d5f4e0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name okhttp High
Vendor jar package name internal Low
Vendor jar package name okhttp3 Highest
Vendor jar package name okhttp3 Low
Vendor Manifest automatic-module-name okhttp3 Medium
Product file name okhttp High
Product jar package name internal Low
Product jar package name okhttp3 Highest
Product Manifest automatic-module-name okhttp3 Medium
Version file name okhttp Medium
Version file version 4.12.0 High
sharepoint-online-connector-0.9.4.war: okio-jvm-3.6.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/okio-jvm-3.6.0.jar
MD5: 26370180ff99a7e8a12dcaac2a70cc6e
SHA1: 5600569133b7bdefe1daf9ec7f4abeb6d13e1786
SHA256: 67543f0736fc422ae927ed0e504b98bc5e269fda0d3500579337cb713da28412
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name okio-jvm High
Vendor jar package name okio Highest
Vendor jar package name okio Low
Vendor Manifest automatic-module-name okio Medium
Vendor Manifest bundle-symbolicname com.squareup.okio Medium
Product file name okio-jvm High
Product jar package name okio Highest
Product Manifest automatic-module-name okio Medium
Product Manifest Bundle-Name com.squareup.okio Medium
Product Manifest bundle-symbolicname com.squareup.okio Medium
Version file name okio-jvm Medium
Version file version 3.6.0 High
Version Manifest Bundle-Version 3.6.0 High
cpe:2.3:a:squareup:okio:3.6.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
sharepoint-online-connector-0.9.4.war: opentelemetry-api-1.54.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/opentelemetry-api-1.54.0.jar
MD5: ebcd53dd629ecaa820762f9897fc56b4
SHA1: 1f309aa3b0ada4808ec092390486ffdad4c917e9
SHA256: 53d9d704b658a33f5ba551be930c6bc6f7ac151fc51c8cf8974761fcb39e2542
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name opentelemetry-api High
Vendor jar package name api Highest
Vendor jar package name api Low
Vendor jar package name io Highest
Vendor jar package name io Low
Vendor jar package name opentelemetry Highest
Vendor jar package name opentelemetry Low
Vendor Manifest automatic-module-name io.opentelemetry.api Medium
Product file name opentelemetry-api High
Product jar package name api Highest
Product jar package name api Low
Product jar package name io Highest
Product jar package name opentelemetry Highest
Product jar package name opentelemetry Low
Product Manifest automatic-module-name io.opentelemetry.api Medium
Product Manifest Implementation-Title all High
Version file version 1.54.0 High
Version Manifest Implementation-Version 1.54.0 High
Related Dependencies
sharepoint-online-connector-0.9.4.war: opentelemetry-common-1.54.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/opentelemetry-common-1.54.0.jar
MD5: 2f16e6ebf12400cb0416aa57acf9fafc
SHA1: 0468902f395c631919a8e63bf1a352365133dc1e
SHA256: 76a110d7073626efbf0f4b539b67b8f880e07e6f25636784844ad95145b5023d
sharepoint-online-connector-0.9.4.war: opentelemetry-context-1.54.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/opentelemetry-context-1.54.0.jar
MD5: 139ef2c83dfe837fee79cf32b2cf18f4
SHA1: dea52910b067f62ee93bead08cde2847dd5e4675
SHA256: 48b947f45679ad7833d9a7226cd3209f0babc48b3c19074b76618d86b0e0bedf
sharepoint-online-connector-0.9.4.war: org.eclipse.persistence.core-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/org.eclipse.persistence.core-5.0.0-B10.jar
MD5: 0220aebe0d5d2e3e17212b4f170bc861
SHA1: 7ab1bff81e53437b06882cac903427164e047cc8
SHA256: be3b97f65e605c29b539db0c7adb134ec61413943368432705c4731965b1370a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.core High
Vendor jar package name core Highest
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Vendor Manifest extension-name org.eclipse.persistence.core Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Vendor pom artifactid eclipse.persistence.core Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink Core High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.core High
Product jar package name core Highest
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink Core Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.core Medium
Product Manifest extension-name org.eclipse.persistence.core Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.core Medium
Product pom artifactid eclipse.persistence.core Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink Core High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.core@5.0.0-B10
(Confidence :High)
sharepoint-online-connector-0.9.4.war: org.eclipse.persistence.moxy-5.0.0-B10.jar
Description:
Comprehensive and universal persistence framework for Java.
License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/org.eclipse.persistence.moxy-5.0.0-B10.jar
MD5: 550ec8c0a31fbc5b6d0cd63f75b7d897
SHA1: aede7488445daebad7fb1f7202593e0800e858db
SHA256: 6d040ff629d81d54a7d5f18e73370288126062db7325a87e13fc97bbe65f935a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name org.eclipse.persistence.moxy High
Vendor jar package name eclipse Highest
Vendor jar package name persistence Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Vendor Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Vendor Manifest extension-name org.eclipse.persistence.moxy Medium
Vendor Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Vendor pom artifactid eclipse.persistence.moxy Low
Vendor pom groupid org.eclipse.persistence Highest
Vendor pom name EclipseLink MOXy High
Vendor pom parent-artifactid org.eclipse.persistence.parent Low
Product file name org.eclipse.persistence.moxy High
Product jar package name eclipse Highest
Product jar package name persistence Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.eclipse.org/eclipselink Low
Product Manifest Bundle-Name EclipseLink MOXy Medium
Product Manifest bundle-symbolicname org.eclipse.persistence.moxy Medium
Product Manifest extension-name org.eclipse.persistence.moxy Medium
Product Manifest hk2-bundle-name org.eclipse.persistence:org.eclipse.persistence.moxy Medium
Product pom artifactid eclipse.persistence.moxy Highest
Product pom groupid org.eclipse.persistence Highest
Product pom name EclipseLink MOXy High
Product pom parent-artifactid org.eclipse.persistence.parent Medium
Version pom version 5.0.0-B10 Highest
pkg:maven/org.eclipse.persistence/org.eclipse.persistence.moxy@5.0.0-B10
(Confidence :High)
sharepoint-online-connector-0.9.4.war: proxy-properties-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/proxy-properties-0.9.5.jar
MD5: 1986126e2f527b2ec3b5b33e5da6a0d5
SHA1: f5a1c724bffae539f3e314c8b0db6dd00cd19f21
SHA256: 9142bb6a051ca371350a56a0228e756630c276d68db29c028f4cb59c9adc4573
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name proxy-properties High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name proxy-properties High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name proxy-properties Medium
Version file version 0.9.5 High
sharepoint-online-connector-0.9.4.war: reactive-streams-1.0.4.jar
Description:
Reactive Streams API
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactive-streams-1.0.4.jar
MD5: eda7978509c32d99166745cc144c99cd
SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7
SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactive-streams High
Vendor jar package name reactivestreams Highest
Vendor jar package name reactivestreams Low
Vendor Manifest automatic-module-name org.reactivestreams Medium
Vendor Manifest bundle-docurl http://reactive-streams.org Low
Vendor Manifest bundle-symbolicname reactive-streams Medium
Product file name reactive-streams High
Product jar package name reactivestreams Highest
Product Manifest automatic-module-name org.reactivestreams Medium
Product Manifest bundle-docurl http://reactive-streams.org Low
Product Manifest Bundle-Name reactive-streams-jvm Medium
Product Manifest bundle-symbolicname reactive-streams Medium
Version file name reactive-streams Medium
Version file version 1.0.4 High
Version Manifest Bundle-Version 1.0.4 High
sharepoint-online-connector-0.9.4.war: reactor-core-3.7.11.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactor-core-3.7.11.jar
MD5: 72ad66c911ce291d8f384fa1704737dd
SHA1: 8ac8ee9da2424c81c029f8c361e34838f77a1b78
SHA256: e353ded14403fac8ff33a51a7e759d2faf84f3935a7cc5f567edbba36c7721ba
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-core High
Vendor jar package name core Highest
Vendor jar package name core Low
Vendor jar package name publisher Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.core Medium
Vendor Manifest bundle-symbolicname io.projectreactor.reactor-core Medium
Vendor Manifest multi-release true Low
Product file name reactor-core High
Product jar package name core Highest
Product jar package name core Low
Product jar package name publisher Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.core Medium
Product Manifest Bundle-Name reactor-core Medium
Product Manifest bundle-symbolicname io.projectreactor.reactor-core Medium
Product Manifest Implementation-Title reactor-core High
Product Manifest multi-release true Low
Version file version 3.7.11 High
Version Manifest Implementation-Version 3.7.11 High
sharepoint-online-connector-0.9.4.war: reactor-netty-core-1.2.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactor-netty-core-1.2.10.jar
MD5: d2a12596a679d8a996a5824a385e7e61
SHA1: a2c808ca5468f4b48f6baa1b2d6bc1f6b3637074
SHA256: f0e6cf567110cfe6da55abfcf5f41a7b98a82f20e531bf4519565c4163f9793b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-netty-core High
Vendor jar package name netty Highest
Vendor jar package name netty Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.netty.core Medium
Vendor Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-core Medium
Vendor Manifest multi-release true Low
Product file name reactor-netty-core High
Product jar package name netty Highest
Product jar package name netty Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.netty.core Medium
Product Manifest Bundle-Name reactor-netty-core Medium
Product Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-core Medium
Product Manifest Implementation-Title reactor-netty-core High
Product Manifest multi-release true Low
Version file version 1.2.10 High
Version Manifest Implementation-Version 1.2.10 High
sharepoint-online-connector-0.9.4.war: reactor-netty-http-1.2.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactor-netty-http-1.2.10.jar
MD5: 1722742824e774911edf15e23ddb517c
SHA1: e60ff32fe2e13c0be741378b85d810e99e49c80e
SHA256: bf4df02ab9db60232ffeda74304cc06a4217ab278fd1a78557a1494a9cbc645a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-netty-http High
Vendor jar package name http Highest
Vendor jar package name http Low
Vendor jar package name netty Highest
Vendor jar package name netty Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.netty.http Medium
Vendor Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-http Medium
Product file name reactor-netty-http High
Product jar package name http Highest
Product jar package name http Low
Product jar package name netty Highest
Product jar package name netty Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.netty.http Medium
Product Manifest Bundle-Name reactor-netty-http Medium
Product Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-http Medium
Product Manifest Implementation-Title reactor-netty-http High
Version file version 1.2.10 High
Version Manifest Implementation-Version 1.2.10 High
sharepoint-online-connector-0.9.4.war: snakeyaml-2.3.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/snakeyaml-2.3.jar
MD5: 2a1c2ee8923dcd6bd6d025751af5df37
SHA1: 936b36210e27320f920536f695cf1af210c44586
SHA256: 63a76fe66b652360bd4c2c107e6f0258daa7d4bb492008ba8c26fcd230ff9146
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.3 High
Version pom version 2.3 Highest
sharepoint-online-connector-0.9.4.war: stax-api-1.0-2.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/stax-api-1.0-2.jar
MD5: 7d18b63063580284c3f5734081fdc99f
SHA1: d6337b0de8b25e53e81b922352fbea9f9f57ba0b
SHA256: e8c70ebd76f982c9582a82ef82cf6ce14a7d58a4a4dca5cb7b7fc988c80089b7
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name stax-api High
Vendor jar package name javax Low
Vendor jar package name stream Low
Vendor jar package name xml Low
Product file name stax-api High
Product jar package name stream Low
Product jar package name xml Low
Version file name stax-api Medium
Version file version 1.0.2 High
sharepoint-online-connector-0.9.4.war: std-uritemplate-2.0.0.jar
Description:
Std UriTemplate, RFC 6570 implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/std-uritemplate-2.0.0.jar
MD5: b630b74a39177d3fa6b70ce04bbec880
SHA1: 35ecaab6a9b686d11da19626a352a18a1357a26f
SHA256: 626bbacb7e2ca4c2e8427133c39788d38e7f85d0ace0c697255afc1a8f46be6e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name std-uritemplate High
Vendor jar package name github Highest
Vendor jar package name github Low
Vendor jar package name io Highest
Vendor jar package name io Low
Vendor jar package name stduritemplate Low
Vendor pom artifactid std-uritemplate Low
Vendor pom developer email andrea.peruffo1982@gmail.com Low
Vendor pom developer id andreaTP Medium
Vendor pom developer name Andrea Peruffo Medium
Vendor pom groupid io.github.std-uritemplate Highest
Vendor pom name Standard Uri Template High
Vendor pom url https://std-uritemplate.github.io/ Highest
Product file name std-uritemplate High
Product jar package name github Highest
Product jar package name github Low
Product jar package name io Highest
Product jar package name stduritemplate Low
Product pom artifactid std-uritemplate Highest
Product pom developer email andrea.peruffo1982@gmail.com Low
Product pom developer id andreaTP Low
Product pom developer name Andrea Peruffo Low
Product pom groupid io.github.std-uritemplate Highest
Product pom name Standard Uri Template High
Product pom url https://std-uritemplate.github.io/ Medium
Version file version 2.0.0 High
Version pom version 2.0.0 Highest
pkg:maven/io.github.std-uritemplate/std-uritemplate@2.0.0
(Confidence :High)
sharepoint-online-connector-0.9.4.war: war-connector-bridge-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/war-connector-bridge-0.9.5.jar
MD5: d30d230b69cd912e0a5b520226115414
SHA1: f87d602579133c6c538e341a3891458f176c5666
SHA256: 9bc5dafd561bc7a99979f603ac5331eacd3d3c8f21f717b24fed1ff8045ec421
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name war-connector-bridge High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name war-connector-bridge High
Product jar package name connector Low
Product jar package name transconnect Low
Product jar package name war Low
Version file name war-connector-bridge Medium
Version file version 0.9.5 High
sharepoint-online-connector-0.9.4.war: yaml-descriptor-0.9.5.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/yaml-descriptor-0.9.5.jar
MD5: 139586d6d73e3a49bd3e7fba273f0199
SHA1: 0484c4ecddab80a4c8b1a4d12667750af151e8bd
SHA256: ff7826a7641fb90aca304878bc97d505da06d971d2df3f0b272f621aeaa3abff
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name yaml-descriptor High
Vendor jar package name connector Low
Vendor jar package name io Low
Vendor jar package name transconnect Low
Product file name yaml-descriptor High
Product jar package name connector Low
Product jar package name extension Low
Product jar package name transconnect Low
Version file name yaml-descriptor Medium
Version file version 0.9.5 High
shib-networking-9.1.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.shibboleth/shib-networking/9.1.3/6663a55af0262b09d616c574d76f39261f19ff27/shib-networking-9.1.3.jar
MD5: ba109d5eaf2cb2a2f8ccf5ce5caa5f49
SHA1: 6663a55af0262b09d616c574d76f39261f19ff27
SHA256: b4364f10e40d74fcfede51836b6d5a9ed63bf9dfa5afbc8a3d2dbfbae46dc2f5
Referenced In Project/Scope: server-start:webapps
shib-networking-9.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name shib-networking High
Vendor gradle artifactid shib-networking Highest
Vendor gradle groupid net.shibboleth Highest
Vendor jar package name net Highest
Vendor jar package name shared Highest
Vendor jar package name shibboleth Highest
Vendor Manifest automatic-module-name net.shibboleth.networking Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid shib-networking Low
Vendor pom groupid net.shibboleth Highest
Vendor pom name Shibboleth Shared :: Networking Support High
Vendor pom parent-artifactid shib-shared-parent Low
Product file name shib-networking High
Product gradle artifactid shib-networking Highest
Product jar package name net Highest
Product jar package name shared Highest
Product jar package name shibboleth Highest
Product Manifest automatic-module-name net.shibboleth.networking Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid shib-networking Highest
Product pom groupid net.shibboleth Highest
Product pom name Shibboleth Shared :: Networking Support High
Product pom parent-artifactid shib-shared-parent Medium
Version file version 9.1.3 High
Version gradle version 9.1.3 Highest
Version pom version 9.1.3 Highest
pkg:maven/net.shibboleth/shib-networking@9.1.3
(Confidence :High)
shib-security-9.1.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.shibboleth/shib-security/9.1.3/2a571af447ad89203c919f38c532b174b374a741/shib-security-9.1.3.jar
MD5: 23e2360130c446a325771ddb01eb2990
SHA1: 2a571af447ad89203c919f38c532b174b374a741
SHA256: 5ef94ecbe4f5773e0e16bcbe1c783026447a07f426e622e073b87a33af6db9e8
Referenced In Project/Scope: server-start:webapps
shib-security-9.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name shib-security High
Vendor gradle artifactid shib-security Highest
Vendor gradle groupid net.shibboleth Highest
Vendor jar package name net Highest
Vendor jar package name security Highest
Vendor jar package name shared Highest
Vendor jar package name shibboleth Highest
Vendor Manifest automatic-module-name net.shibboleth.shared.security Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid shib-security Low
Vendor pom groupid net.shibboleth Highest
Vendor pom name Shibboleth Shared :: Security Support High
Vendor pom parent-artifactid shib-shared-parent Low
Product file name shib-security High
Product gradle artifactid shib-security Highest
Product jar package name net Highest
Product jar package name security Highest
Product jar package name shared Highest
Product jar package name shibboleth Highest
Product Manifest automatic-module-name net.shibboleth.shared.security Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid shib-security Highest
Product pom groupid net.shibboleth Highest
Product pom name Shibboleth Shared :: Security Support High
Product pom parent-artifactid shib-shared-parent Medium
Version file version 9.1.3 High
Version gradle version 9.1.3 Highest
Version pom version 9.1.3 Highest
pkg:maven/net.shibboleth/shib-security@9.1.3
(Confidence :High)
shib-support-9.1.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.shibboleth/shib-support/9.1.3/67e8c6997e3d9b2163142cdcf499bceed103e961/shib-support-9.1.3.jar
MD5: c16fd1575f16c25830c015fd3af87d5b
SHA1: 67e8c6997e3d9b2163142cdcf499bceed103e961
SHA256: 618778067103d111fdadf74637e0b9bc43ee976dde254105b34670673087afc5
Referenced In Project/Scope: server-start:webapps
shib-support-9.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name shib-support High
Vendor gradle artifactid shib-support Highest
Vendor gradle groupid net.shibboleth Highest
Vendor jar package name net Highest
Vendor jar package name shared Highest
Vendor jar package name shibboleth Highest
Vendor Manifest automatic-module-name net.shibboleth.shared.support Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid shib-support Low
Vendor pom groupid net.shibboleth Highest
Vendor pom name Shibboleth Shared :: Generic Support Classes High
Vendor pom parent-artifactid shib-shared-parent Low
Product file name shib-support High
Product gradle artifactid shib-support Highest
Product jar package name net Highest
Product jar package name shared Highest
Product jar package name shibboleth Highest
Product Manifest automatic-module-name net.shibboleth.shared.support Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid shib-support Highest
Product pom groupid net.shibboleth Highest
Product pom name Shibboleth Shared :: Generic Support Classes High
Product pom parent-artifactid shib-shared-parent Medium
Version file version 9.1.3 High
Version gradle version 9.1.3 Highest
Version pom version 9.1.3 Highest
pkg:maven/net.shibboleth/shib-support@9.1.3
(Confidence :High)
shib-velocity-9.1.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.shibboleth/shib-velocity/9.1.3/7ebc28719553529e87bf0c92cfb641b29063e0df/shib-velocity-9.1.3.jar
MD5: a98141beb6d2919937b40e86b3583e5b
SHA1: 7ebc28719553529e87bf0c92cfb641b29063e0df
SHA256: 09fbc8f9b0938099dd0d0364884650295e87c226948d3bb5fc1ae05838a8ef40
Referenced In Project/Scope: server-start:webapps
shib-velocity-9.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name shib-velocity High
Vendor gradle artifactid shib-velocity Highest
Vendor gradle groupid net.shibboleth Highest
Vendor jar package name net Highest
Vendor jar package name shared Highest
Vendor jar package name shibboleth Highest
Vendor jar package name velocity Highest
Vendor Manifest automatic-module-name net.shibboleth.shared.velocity Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid shib-velocity Low
Vendor pom groupid net.shibboleth Highest
Vendor pom name Shibboleth Shared :: Velocity Support High
Vendor pom parent-artifactid shib-shared-parent Low
Product file name shib-velocity High
Product gradle artifactid shib-velocity Highest
Product jar package name net Highest
Product jar package name shared Highest
Product jar package name shibboleth Highest
Product jar package name velocity Highest
Product Manifest automatic-module-name net.shibboleth.shared.velocity Medium
Product Manifest build-jdk-spec 17 Low
Product pom artifactid shib-velocity Highest
Product pom groupid net.shibboleth Highest
Product pom name Shibboleth Shared :: Velocity Support High
Product pom parent-artifactid shib-shared-parent Medium
Version file version 9.1.3 High
Version gradle version 9.1.3 Highest
Version pom version 9.1.3 Highest
pkg:maven/net.shibboleth/shib-velocity@9.1.3
(Confidence :High)
slf4j-api-2.0.17.jar
Description:
The slf4j API
License:
https://opensource.org/license/mit
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.slf4j/slf4j-api/2.0.17/d9e58ac9c7779ba3bf8142aff6c830617a7fe60f/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/ch.qos.logback/logback-classic@1.5.21
pkg:maven/TRANSCONNECT.backend.adapters/opcua-adapter@unspecified
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
pkg:maven/TRANSCONNECT.backend/server-start@unspecified
pkg:maven/org.slf4j/slf4j-api@2.0.17
pkg:maven/org.slf4j/slf4j-api@2.0.17
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor gradle artifactid slf4j-api Highest
Vendor gradle groupid org.slf4j Highest
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product gradle artifactid slf4j-api Highest
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version gradle version 2.0.17 Highest
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.17
(Confidence :High)
smack-3.0.4.jar
Description:
Smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. A pure Java library, it can be embedded into your applications to create anything from a full XMPP client to simple XMPP integrations such as sending notification messages.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jivesoftware/smack/3.0.4/6c753d9ee1267d5c95f129575963e62ed49860a1/smack-3.0.4.jar
MD5: e8df1da0211543e00c4fa32b2401fc74
SHA1: 6c753d9ee1267d5c95f129575963e62ed49860a1
SHA256: 03ce9a149453a4799f90d4660841c5cc862b1b580df8caefb8b8fb40ab57fbb4
Referenced In Project/Scope: server-start:runtimeClasspath
smack-3.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name smack High
Vendor gradle artifactid smack Highest
Vendor gradle groupid jivesoftware Highest
Vendor jar package name jivesoftware Low
Vendor jar package name smack Low
Vendor pom artifactid smack Low
Vendor pom groupid jivesoftware Highest
Vendor pom name Smack High
Vendor pom url http://www.jivesoftware.org/smack/ Highest
Product file name smack High
Product gradle artifactid smack Highest
Product jar package name smack Low
Product pom artifactid smack Highest
Product pom groupid jivesoftware Highest
Product pom name Smack High
Product pom url http://www.jivesoftware.org/smack/ Medium
Version file version 3.0.4 High
Version gradle version 3.0.4 Highest
Version pom version 3.0.4 Highest
pkg:maven/jivesoftware/smack@3.0.4
(Confidence :High)
smackx-3.0.4.jar
Description:
Smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. A pure Java library, it can be embedded into your applications to create anything from a full XMPP client to simple XMPP integrations such as sending notification messages.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/jivesoftware/smackx/3.0.4/bd7557b72511ad3de3f8d1c8d3b336226e116622/smackx-3.0.4.jar
MD5: fe04c6acdf1b4f415268e684e0c49b5d
SHA1: bd7557b72511ad3de3f8d1c8d3b336226e116622
SHA256: 23810a1c1e9f25b638d2d3250b943c1494d6aec3a63b74c53a3ffe8d2de12f69
Referenced In Project/Scope: server-start:runtimeClasspath
smackx-3.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name smackx High
Vendor gradle artifactid smackx Highest
Vendor gradle groupid jivesoftware Highest
Vendor jar package name jivesoftware Low
Vendor jar package name smackx Low
Vendor pom artifactid smackx Low
Vendor pom groupid jivesoftware Highest
Vendor pom name Smack Extensions High
Vendor pom url http://www.jivesoftware.org/smack/ Highest
Product file name smackx High
Product gradle artifactid smackx Highest
Product jar package name smackx Low
Product pom artifactid smackx Highest
Product pom groupid jivesoftware Highest
Product pom name Smack Extensions High
Product pom url http://www.jivesoftware.org/smack/ Medium
Version file version 3.0.4 High
Version gradle version 3.0.4 Highest
Version pom version 3.0.4 Highest
pkg:maven/jivesoftware/smackx@3.0.4
(Confidence :High)
snakeyaml-2.4.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.yaml/snakeyaml/2.4/e0666b825b796f85521f02360e77f4c92c5a7a07/snakeyaml-2.4.jar
MD5: 29410ee3a987e3bff7b847933c591972
SHA1: e0666b825b796f85521f02360e77f4c92c5a7a07
SHA256: ef779af5d29a9dde8cc70ce0341f5c6f7735e23edff9685ceaa9d35359b7bb7f
Referenced In Project/Scope: server-start:webapps
snakeyaml-2.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor gradle artifactid snakeyaml Highest
Vendor gradle groupid org.yaml Highest
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product gradle artifactid snakeyaml Highest
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.4 High
Version gradle version 2.4 Highest
Version pom version 2.4 Highest
sshd-common-2.15.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.sshd/sshd-common/2.15.0/c3a4140b543d5e419d57809562fec297ffea46f5/sshd-common-2.15.0.jar
MD5: 1921f76630059fdf43306135711eae45
SHA1: c3a4140b543d5e419d57809562fec297ffea46f5
SHA256: 9529ddd62aea684c9fd3b897b159a3521f129f06cddb2371f8e928e26a987656
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
sshd-common-2.15.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sshd-common High
Vendor gradle artifactid sshd-common Highest
Vendor gradle groupid org.apache.sshd Highest
Vendor jar package name apache Highest
Vendor jar package name common Highest
Vendor jar package name sshd Highest
Vendor Manifest automatic-module-name org.apache.sshd.common Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid sshd-common Low
Vendor pom groupid org.apache.sshd Highest
Vendor pom name Apache Mina SSHD :: Common support utilities High
Vendor pom parent-artifactid sshd Low
Product file name sshd-common High
Product gradle artifactid sshd-common Highest
Product jar package name apache Highest
Product jar package name common Highest
Product jar package name sshd Highest
Product Manifest automatic-module-name org.apache.sshd.common Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Apache Mina SSHD :: Common support utilities High
Product Manifest specification-title Apache Mina SSHD :: Common support utilities Medium
Product pom artifactid sshd-common Highest
Product pom groupid org.apache.sshd Highest
Product pom name Apache Mina SSHD :: Common support utilities High
Product pom parent-artifactid sshd Medium
Version file version 2.15.0 High
Version gradle version 2.15.0 Highest
Version Manifest Implementation-Version 2.15.0 High
Version pom version 2.15.0 Highest
sshd-core-2.15.0.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.sshd/sshd-core/2.15.0/bc6ff14b0dddfaec40063b86871774d65a771eaa/sshd-core-2.15.0.jar
MD5: 762ae62ff429ca40cee845cf17996811
SHA1: bc6ff14b0dddfaec40063b86871774d65a771eaa
SHA256: 011637289ee240cdd9d02bb77898a777207b0cdc557d4ea596a4da33abdb211f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
sshd-core-2.15.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sshd-core High
Vendor gradle artifactid sshd-core Highest
Vendor gradle groupid org.apache.sshd Highest
Vendor jar package name apache Highest
Vendor jar package name core Highest
Vendor jar package name sshd Highest
Vendor Manifest automatic-module-name org.apache.sshd.core Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid sshd-core Low
Vendor pom groupid org.apache.sshd Highest
Vendor pom name Apache Mina SSHD :: Core High
Vendor pom parent-artifactid sshd Low
Product file name sshd-core High
Product gradle artifactid sshd-core Highest
Product jar package name apache Highest
Product jar package name core Highest
Product jar package name sshd Highest
Product Manifest automatic-module-name org.apache.sshd.core Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Apache Mina SSHD :: Core High
Product Manifest specification-title Apache Mina SSHD :: Core Medium
Product pom artifactid sshd-core Highest
Product pom groupid org.apache.sshd Highest
Product pom name Apache Mina SSHD :: Core High
Product pom parent-artifactid sshd Medium
Version file version 2.15.0 High
Version gradle version 2.15.0 Highest
Version Manifest Implementation-Version 2.15.0 High
Version pom version 2.15.0 Highest
sshd-sftp-2.15.0.jar
Description:
The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.sshd/sshd-sftp/2.15.0/2e226055ed060c64ed76256a9c45de6d0109eef8/sshd-sftp-2.15.0.jar
MD5: d1b8833e64b964d5469f40696d330b7d
SHA1: 2e226055ed060c64ed76256a9c45de6d0109eef8
SHA256: 4dcf4f8cc123dca9802fa993b754308be388f13daa6d59148e38cf8d0673962b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
sshd-sftp-2.15.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name sshd-sftp High
Vendor gradle artifactid sshd-sftp Highest
Vendor gradle groupid org.apache.sshd Highest
Vendor jar package name apache Highest
Vendor jar package name sftp Highest
Vendor jar package name sshd Highest
Vendor Manifest automatic-module-name org.apache.sshd.sftp Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.sshd.sftp Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid sshd-sftp Low
Vendor pom groupid org.apache.sshd Highest
Vendor pom name Apache Mina SSHD :: SFTP High
Vendor pom parent-artifactid sshd Low
Product file name sshd-sftp High
Product gradle artifactid sshd-sftp Highest
Product jar package name apache Highest
Product jar package name server Highest
Product jar package name sftp Highest
Product jar package name sshd Highest
Product Manifest automatic-module-name org.apache.sshd.sftp Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache Mina SSHD :: SFTP Medium
Product Manifest bundle-symbolicname org.apache.sshd.sftp Medium
Product Manifest Implementation-Title Apache Mina SSHD :: SFTP High
Product Manifest specification-title Apache Mina SSHD :: SFTP Medium
Product pom artifactid sshd-sftp Highest
Product pom groupid org.apache.sshd Highest
Product pom name Apache Mina SSHD :: SFTP High
Product pom parent-artifactid sshd Medium
Version file version 2.15.0 High
Version gradle version 2.15.0 Highest
Version Manifest Bundle-Version 2.15.0 High
Version Manifest Implementation-Version 2.15.0 High
Version pom version 2.15.0 Highest
stax-ex-1.8.1.jar
Description:
Extensions to JSR-173 StAX API.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jvnet.staxex/stax-ex/1.8.1/78011e483a21102fb4858f3e8f269a677e50aa23/stax-ex-1.8.1.jar
MD5: 8fea4418fa80e957e39c174cec08053c
SHA1: 78011e483a21102fb4858f3e8f269a677e50aa23
SHA256: 20522549056e9e50aa35ef0b445a2e47a53d06be0b0a9467d704e2483ffb049a
Referenced In Project/Scope: server-start:compileClasspath
stax-ex-1.8.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name stax-ex High
Vendor gradle artifactid stax-ex Highest
Vendor gradle groupid org.jvnet.staxex Highest
Vendor jar package name jvnet Highest
Vendor jar package name staxex Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium
Vendor Manifest implementation-build-id 1.8.1-acf3f94, 2018-12-27T15:12:49+0000 Low
Vendor Manifest implementation-url https://projects.eclipse.org/projects/ee4j/stax-ex Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.jvnet.staxex Medium
Vendor pom artifactid stax-ex Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer email Zheng.Jun.Li@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer id zhengjl Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom developer name Zheng Jun Li Medium
Vendor pom groupid org.jvnet.staxex Highest
Vendor pom name Extended StAX API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name stax-ex High
Product gradle artifactid stax-ex Highest
Product jar package name jvnet Highest
Product jar package name staxex Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Extended StAX API Medium
Product Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium
Product Manifest implementation-build-id 1.8.1-acf3f94, 2018-12-27T15:12:49+0000 Low
Product Manifest Implementation-Title Extended StAX API High
Product Manifest implementation-url https://projects.eclipse.org/projects/ee4j/stax-ex Low
Product pom artifactid stax-ex Highest
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer email Zheng.Jun.Li@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer id zhengjl Low
Product pom developer name Roman Grigoriadi Low
Product pom developer name Zheng Jun Li Low
Product pom groupid org.jvnet.staxex Highest
Product pom name Extended StAX API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 1.8.1 High
Version gradle version 1.8.1 Highest
Version Manifest Bundle-Version 1.8.1 High
Version Manifest Implementation-Version 1.8.1 High
Version pom parent-version 1.8.1 Low
Version pom version 1.8.1 Highest
pkg:maven/org.jvnet.staxex/stax-ex@1.8.1
(Confidence :High)
cpe:2.3:a:oracle:projects:1.8.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
stax-ex-2.1.0.jar
Description:
Extensions to JSR-173 StAX API.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jvnet.staxex/stax-ex/2.1.0/33160568d70c01da407f8ba982bacf283d00ad4a/stax-ex-2.1.0.jar
MD5: 700a50c797db31429bf0c57b5adb8b55
SHA1: 33160568d70c01da407f8ba982bacf283d00ad4a
SHA256: 9f786ab52392106a53491bd1ddd8bd9028c95bb280e30387b70d498a8647cf35
Referenced In Project/Scope: server-start:webapps
stax-ex-2.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name stax-ex High
Vendor gradle artifactid stax-ex Highest
Vendor gradle groupid org.jvnet.staxex Highest
Vendor jar package name jvnet Highest
Vendor jar package name staxex Highest
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium
Vendor Manifest implementation-build-id 2.1.0 - 8eeacab Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor pom artifactid stax-ex Low
Vendor pom developer email Roman.Grigoriadi@oracle.com Low
Vendor pom developer email Zheng.Jun.Li@oracle.com Low
Vendor pom developer id bravehorsie Medium
Vendor pom developer id zhengjl Medium
Vendor pom developer name Roman Grigoriadi Medium
Vendor pom developer name Zheng Jun Li Medium
Vendor pom groupid org.jvnet.staxex Highest
Vendor pom name Extended StAX API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Product file name stax-ex High
Product gradle artifactid stax-ex Highest
Product jar package name jvnet Highest
Product jar package name staxex Highest
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Extended StAX API Medium
Product Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium
Product Manifest implementation-build-id 2.1.0 - 8eeacab Low
Product Manifest Implementation-Title Extended StAX API High
Product pom artifactid stax-ex Highest
Product pom developer email Roman.Grigoriadi@oracle.com Low
Product pom developer email Zheng.Jun.Li@oracle.com Low
Product pom developer id bravehorsie Low
Product pom developer id zhengjl Low
Product pom developer name Roman Grigoriadi Low
Product pom developer name Zheng Jun Li Low
Product pom groupid org.jvnet.staxex Highest
Product pom name Extended StAX API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Version file version 2.1.0 High
Version gradle version 2.1.0 Highest
Version Manifest Bundle-Version 2.1.0 High
Version Manifest implementation-build-id 2.1.0 Low
Version Manifest Implementation-Version 2.1.0 High
Version pom parent-version 2.1.0 Low
Version pom version 2.1.0 Highest
pkg:maven/org.jvnet.staxex/stax-ex@2.1.0
(Confidence :High)
stax2-api-4.2.2.jar
Description:
Stax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API.
License:
The BSD 2-Clause License: http://www.opensource.org/licenses/bsd-license.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.codehaus.woodstox/stax2-api/4.2.2/b0d746cadea928e5264f2ea294ea9a1bf815bbde/stax2-api-4.2.2.jar
MD5: 6949cace015c0f408f0b846e3735d301
SHA1: b0d746cadea928e5264f2ea294ea9a1bf815bbde
SHA256: a61c48d553efad78bc01fffc4ac528bebbae64cbaec170b2a5e39cf61eb51abe
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
stax2-api-4.2.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name stax2-api High
Vendor gradle artifactid stax2-api Highest
Vendor gradle groupid org.codehaus.woodstox Highest
Vendor jar package name codehaus Highest
Vendor jar package name stax2 Highest
Vendor jar package name typed Highest
Vendor jar package name validation Highest
Vendor Manifest automatic-module-name org.codehaus.stax2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://github.com/FasterXML/stax2-api Low
Vendor Manifest bundle-symbolicname stax2-api Medium
Vendor Manifest Implementation-Vendor fasterxml.com High
Vendor Manifest Implementation-Vendor-Id org.codehaus.woodstox Medium
Vendor Manifest specification-vendor fasterxml.com Low
Vendor pom artifactid stax2-api Low
Vendor pom developer email tatu@fasterxml.com Low
Vendor pom developer id tatu Medium
Vendor pom developer name Tatu Saloranta Medium
Vendor pom groupid org.codehaus.woodstox Highest
Vendor pom name Stax2 API High
Vendor pom organization name fasterxml.com High
Vendor pom organization url http://fasterxml.com Medium
Vendor pom parent-artifactid oss-parent Low
Vendor pom parent-groupid com.fasterxml Medium
Vendor pom url http://github.com/FasterXML/stax2-api Highest
Product file name stax2-api High
Product gradle artifactid stax2-api Highest
Product jar package name codehaus Highest
Product jar package name stax2 Highest
Product jar package name typed Highest
Product jar package name validation Highest
Product Manifest automatic-module-name org.codehaus.stax2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://github.com/FasterXML/stax2-api Low
Product Manifest Bundle-Name Stax2 API Medium
Product Manifest bundle-symbolicname stax2-api Medium
Product Manifest Implementation-Title Stax2 API High
Product Manifest specification-title Stax2 API Medium
Product pom artifactid stax2-api Highest
Product pom developer email tatu@fasterxml.com Low
Product pom developer id tatu Low
Product pom developer name Tatu Saloranta Low
Product pom groupid org.codehaus.woodstox Highest
Product pom name Stax2 API High
Product pom organization name fasterxml.com Low
Product pom organization url http://fasterxml.com Low
Product pom parent-artifactid oss-parent Medium
Product pom parent-groupid com.fasterxml Medium
Product pom url http://github.com/FasterXML/stax2-api Medium
Version file version 4.2.2 High
Version gradle version 4.2.2 Highest
Version Manifest Bundle-Version 4.2.2 High
Version Manifest Implementation-Version 4.2.2 High
Version pom parent-version 4.2.2 Low
Version pom version 4.2.2 Highest
pkg:maven/org.codehaus.woodstox/stax2-api@4.2.2
(Confidence :High)
staxon-1.3.jar
Description:
JSON via StAX - Core
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/de.odysseus.staxon/staxon/1.3/9cec6f1c1a05eeebb0b83b3e909fd4b496ddde44/staxon-1.3.jar
MD5: bcbfd772e6787394d5a7dad031cf0cf7
SHA1: 9cec6f1c1a05eeebb0b83b3e909fd4b496ddde44
SHA256: 54781e78c9183f54a63c9e497170187568b31979a7d236d1c6f858d91af93be6
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
staxon-1.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name staxon High
Vendor gradle artifactid staxon Highest
Vendor gradle groupid de.odysseus.staxon Highest
Vendor jar package name de Highest
Vendor jar package name de Low
Vendor jar package name json Highest
Vendor jar package name odysseus Highest
Vendor jar package name odysseus Low
Vendor jar package name staxon Highest
Vendor jar package name staxon Low
Vendor pom artifactid staxon Low
Vendor pom groupid de.odysseus.staxon Highest
Vendor pom name StAXON Core High
Vendor pom parent-artifactid staxon-parent Low
Product file name staxon High
Product gradle artifactid staxon Highest
Product jar package name de Highest
Product jar package name json Highest
Product jar package name json Low
Product jar package name odysseus Highest
Product jar package name odysseus Low
Product jar package name staxon Highest
Product jar package name staxon Low
Product pom artifactid staxon Highest
Product pom groupid de.odysseus.staxon Highest
Product pom name StAXON Core High
Product pom parent-artifactid staxon-parent Medium
Version file version 1.3 High
Version gradle version 1.3 Highest
Version pom version 1.3 Highest
pkg:maven/de.odysseus.staxon/staxon@1.3
(Confidence :High)
swagger-annotations-jakarta-2.2.41.jar
Description:
swagger-annotations-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-annotations-jakarta/2.2.41/bd1988adb6f1eac7df260f4268c7a37f723e632f/swagger-annotations-jakarta-2.2.41.jar
MD5: 129436b461924dc0b0bbda4e79a5056a
SHA1: bd1988adb6f1eac7df260f4268c7a37f723e632f
SHA256: 714df4b94e8956a86de9a95fae85d5d9ebcdfd0bf9d84e3634bc16b60e30a94e
Referenced In Project/Scope: server-start:webapps
swagger-annotations-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-annotations-jakarta High
Vendor gradle artifactid swagger-annotations-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name io Highest
Vendor jar package name oas Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.oas.annotations Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Vendor pom artifactid swagger-annotations-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-annotations-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-annotations-jakarta High
Product gradle artifactid swagger-annotations-jakarta Highest
Product jar package name io Highest
Product jar package name oas Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.oas.annotations Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Product Manifest Bundle-Name swagger-annotations Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Product pom artifactid swagger-annotations-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-annotations-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-annotations-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-core-jakarta-2.2.41.jar
Description:
swagger-core-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-core-jakarta/2.2.41/7dc6b47e28b83921fc1173525eb37f1f59b18d37/swagger-core-jakarta-2.2.41.jar
MD5: afac99bac94659de90dc53d2994f53ce
SHA1: 7dc6b47e28b83921fc1173525eb37f1f59b18d37
SHA256: d5319a04b4dec6dbdc359536e3be080bdcf391281dfcedafff0ba08eb02e6f03
Referenced In Project/Scope: server-start:webapps
swagger-core-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-core-jakarta High
Vendor gradle artifactid swagger-core-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name core Highest
Vendor jar package name io Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.core Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-core.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Vendor pom artifactid swagger-core-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-core-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-core-jakarta High
Product gradle artifactid swagger-core-jakarta Highest
Product jar package name core Highest
Product jar package name io Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.core Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Product Manifest Bundle-Name swagger-core Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-core.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Product pom artifactid swagger-core-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-core-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-core-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-integration-jakarta-2.2.41.jar
Description:
swagger-integration-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-integration-jakarta/2.2.41/bd90773363d7b79b540ec962a9dfddfca386cbd1/swagger-integration-jakarta-2.2.41.jar
MD5: 6103153acffae10a092e259bb34ab439
SHA1: bd90773363d7b79b540ec962a9dfddfca386cbd1
SHA256: feba9ff9e973b45c7cac755d56f9d23511a2ce0db4bbf213414d65a1557f41cf
Referenced In Project/Scope: server-start:webapps
swagger-integration-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-integration-jakarta High
Vendor gradle artifactid swagger-integration-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name io Highest
Vendor jar package name oas Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.oas.integration Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-integration Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-integration.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-integration Low
Vendor pom artifactid swagger-integration-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-integration-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-integration-jakarta High
Product gradle artifactid swagger-integration-jakarta Highest
Product jar package name io Highest
Product jar package name oas Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.oas.integration Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-integration Low
Product Manifest Bundle-Name swagger-integration Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-integration.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-integration Low
Product pom artifactid swagger-integration-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-integration-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-integration-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-jaxrs2-jakarta-2.2.41.jar
Description:
swagger-jaxrs2-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-jaxrs2-jakarta/2.2.41/ca5f91ab3ec5e0dae17153f22bcb5c3b899748dc/swagger-jaxrs2-jakarta-2.2.41.jar
MD5: 692611f92b9fe61f582910fe4271ab64
SHA1: ca5f91ab3ec5e0dae17153f22bcb5c3b899748dc
SHA256: 7b0962a3ab1ae510479a2321a677da84fc17fcdb2112643cd56586f565f088fb
Referenced In Project/Scope: server-start:webapps
swagger-jaxrs2-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-jaxrs2-jakarta High
Vendor gradle artifactid swagger-jaxrs2-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name io Highest
Vendor jar package name jaxrs2 Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.jaxrs2 Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2 Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-jaxrs2.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2 Low
Vendor pom artifactid swagger-jaxrs2-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-jaxrs2-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-jaxrs2-jakarta High
Product gradle artifactid swagger-jaxrs2-jakarta Highest
Product jar package name io Highest
Product jar package name jaxrs2 Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.jaxrs2 Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2 Low
Product Manifest Bundle-Name swagger-jaxrs2 Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-jaxrs2.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2 Low
Product pom artifactid swagger-jaxrs2-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-jaxrs2-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-jaxrs2-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-jaxrs2-servlet-initializer-v2-jakarta-2.2.41.jar
Description:
swagger-jaxrs2-servlet-initializer-v2-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-jaxrs2-servlet-initializer-v2-jakarta/2.2.41/fc1cc8596df68d7a74fdba44efbac6be7fdb1f9e/swagger-jaxrs2-servlet-initializer-v2-jakarta-2.2.41.jar
MD5: 9b6079bc1c861306a34f9b8f3f81c3be
SHA1: fc1cc8596df68d7a74fdba44efbac6be7fdb1f9e
SHA256: b63592378cf63d48e0fda7b93cbb5abbb4ff5ac55efdb8afeb06d61437cdd52f
Referenced In Project/Scope: server-start:webapps
swagger-jaxrs2-servlet-initializer-v2-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-jaxrs2-servlet-initializer-v2-jakarta High
Vendor gradle artifactid swagger-jaxrs2-servlet-initializer-v2-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name io Highest
Vendor jar package name jaxrs2 Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.jaxrs2.integration.servlet Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2-servlet-initializer-v2 Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-jaxrs2-servlet-initializer-v2.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2-servlet-initializer-v2 Low
Vendor pom artifactid swagger-jaxrs2-servlet-initializer-v2-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-jaxrs2-servlet-initializer-v2-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-jaxrs2-servlet-initializer-v2-jakarta High
Product gradle artifactid swagger-jaxrs2-servlet-initializer-v2-jakarta Highest
Product jar package name io Highest
Product jar package name jaxrs2 Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.jaxrs2.integration.servlet Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2-servlet-initializer-v2 Low
Product Manifest Bundle-Name swagger-jaxrs2-servlet-initializer-v2 Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-jaxrs2-servlet-initializer-v2.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs2-servlet-initializer-v2 Low
Product pom artifactid swagger-jaxrs2-servlet-initializer-v2-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-jaxrs2-servlet-initializer-v2-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-jaxrs2-servlet-initializer-v2-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:gmail-servlet_project:gmail-servlet:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-models-jakarta-2.2.41.jar
Description:
swagger-models-jakarta
License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html"
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.swagger.core.v3/swagger-models-jakarta/2.2.41/3f57b30a6ca6624dd6feb2612f2f17bea1e2b3d9/swagger-models-jakarta-2.2.41.jar
MD5: 110a78136896cc7752a1af8087df9cca
SHA1: 3f57b30a6ca6624dd6feb2612f2f17bea1e2b3d9
SHA256: 287144c3afcf7980769d2b9ee6cfbcfe429f3cb38470f578bc1fd9c5b03de97e
Referenced In Project/Scope: server-start:webapps
swagger-models-jakarta-2.2.41.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-models-jakarta High
Vendor gradle artifactid swagger-models-jakarta Highest
Vendor gradle groupid io.swagger.core.v3 Highest
Vendor jar package name io Highest
Vendor jar package name oas Highest
Vendor jar package name swagger Highest
Vendor jar package name v3 Highest
Vendor Manifest automatic-module-name io.swagger.v3.oas.models Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-models.jakarta Medium
Vendor Manifest mode development Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Vendor pom artifactid swagger-models-jakarta Low
Vendor pom groupid io.swagger.core.v3 Highest
Vendor pom name swagger-models-jakarta High
Vendor pom parent-artifactid swagger-project-jakarta Low
Product file name swagger-models-jakarta High
Product gradle artifactid swagger-models-jakarta Highest
Product jar package name io Highest
Product jar package name oas Highest
Product jar package name swagger Highest
Product jar package name v3 Highest
Product Manifest automatic-module-name io.swagger.v3.oas.models Medium
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low
Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Product Manifest Bundle-Name swagger-models Jakarta Medium
Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-models.jakarta Medium
Product Manifest mode development Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Product pom artifactid swagger-models-jakarta Highest
Product pom groupid io.swagger.core.v3 Highest
Product pom name swagger-models-jakarta High
Product pom parent-artifactid swagger-project-jakarta Medium
Version file version 2.2.41 High
Version gradle version 2.2.41 Highest
Version Manifest Bundle-Version 2.2.41 High
Version Manifest implementation-version 2.2.41 High
Version pom version 2.2.41 Highest
pkg:maven/io.swagger.core.v3/swagger-models-jakarta@2.2.41
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:2.2.41:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-ui-5.17.14.jar
Description:
WebJar for Swagger UI
License:
Apache-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar
MD5: 0000f3977f67d7c1b7ac77a36bfabcca
SHA1: 7c746d197424eb721b4e08fcaa9e85231662d81f
SHA256: 3d16fe99be7ef7fc6fd6b9a0b6d12e3a5444735d8a2c0c6246fbc804da5103bb
Referenced In Project/Scope: server-start:webapps
swagger-ui-5.17.14.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name swagger-ui High
Vendor gradle artifactid swagger-ui Highest
Vendor gradle groupid org.webjars Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-symbolicname org.webjars.swagger-ui Medium
Vendor pom artifactid swagger-ui Low
Vendor pom developer id webjars Medium
Vendor pom groupid org.webjars Highest
Vendor pom name Swagger UI High
Vendor pom url https://www.webjars.org Highest
Product file name swagger-ui High
Product gradle artifactid swagger-ui Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest Bundle-Name Swagger UI Medium
Product Manifest bundle-symbolicname org.webjars.swagger-ui Medium
Product pom artifactid swagger-ui Highest
Product pom developer id webjars Low
Product pom groupid org.webjars Highest
Product pom name Swagger UI High
Product pom url https://www.webjars.org Medium
Version file version 5.17.14 High
Version gradle version 5.17.14 Highest
Version Manifest Bundle-Version 5.17.14 High
Version pom version 5.17.14 Highest
pkg:maven/org.webjars/swagger-ui@5.17.14
(Confidence :High)
cpe:2.3:a:http-swagger_project:http-swagger:5.17.14:*:*:*:*:*:*:*
(Confidence :Low)
suppress
swagger-ui-5.17.14.jar: swagger-initializer.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-initializer.js
MD5: ff995915f51c051c59fed883f5d7be28
SHA1: c434dd8fbfa625a10351681d3037ee79d5682207
SHA256: a895034f24f12d7cd81ec47c98da4f15721d9d9a8d2405f22f21704821f81d02
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
swagger-ui-5.17.14.jar: swagger-ui-bundle.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-ui-bundle.js
MD5: bccc97f77bdb8edc590ae3abdf83b9a7
SHA1: 36af3f79010ac51754bbfa35e86f73b28521e559
SHA256: c2e4a9ef08144839ff47c14202063ecfe4e59e70a4e7154a26bd50d880c88ba1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name DOMPurify High
Product file name DOMPurify High
Version file version 3.1.4 High
pkg:javascript/DOMPurify@3.1.4
(Confidence :Highest)
CVE-2025-26791 suppress
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions up to (excluding) 3.2.4
CVE-2026-41240 suppress
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive sanitization with their attributes intact. Version 3.4.0 patches the issue.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-183 Permissive List of Allowed Inputs
CVSSv4:
Base Score: MEDIUM (6.0)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.0
CVE-2026-0540 suppress
DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4:
Base Score: MEDIUM (5.3)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 2.5.3; versions up to (including) 2.5.8
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 3.1.3; versions up to (including) 3.3.1
CVE-2025-15599 suppress
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4:
Base Score: MEDIUM (5.1)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 2.5.3; versions up to (including) 2.5.8
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 3.1.3; versions up to (excluding) 3.2.7
CVE-2026-41238 (RETIREJS) suppress
Unscored:
References:
CVE-2026-41239 (RETIREJS) suppress
Unscored:
References:
DOMPurify has a logic inconsistency where FORBID_TAGS is not checked when a function-based ADD_TAGS (tagCheck) returns true. Due to short-circuit evaluation, the FORBID_TAGS check is never evaluated, allowing explicitly forbidden elements to pass through sanitization when EXTRA_ELEMENT_HANDLING.tagCheck is configured. (RETIREJS) suppress
DOMPurify has a logic inconsistency where FORBID_TAGS is not checked when a function-based ADD_TAGS (tagCheck) returns true. Due to short-circuit evaluation, the FORBID_TAGS check is never evaluated, allowing explicitly forbidden elements to pass through sanitization when EXTRA_ELEMENT_HANDLING.tagCheck is configured.
Unscored:
References:
DOMPurify is vulnerable to mutation-XSS (mXSS) when sanitized HTML is embedded into special raw-text wrapper elements such as xmp, script, iframe, noembed, noframes, or noscript before being assigned via innerHTML. Attacker-controlled sequences like </xmp> inside attribute values close the raw-text context during the second parse, causing the sanitized output to mutate into executable markup. (RETIREJS) suppress
DOMPurify is vulnerable to mutation-XSS (mXSS) when sanitized HTML is embedded into special raw-text wrapper elements such as xmp, script, iframe, noembed, noframes, or noscript before being assigned via innerHTML. Attacker-controlled sequences like </xmp> inside attribute values close the raw-text context during the second parse, causing the sanitized output to mutate into executable markup.
Unscored:
References:
DOMPurify's ADD_ATTR predicate function mechanism (via EXTRA_ELEMENT_HANDLING.attributeCheck) short-circuits URI validation when the predicate returns true. This allows unsafe protocols such as javascript: to survive sanitization in href and similar attributes, enabling DOM-based XSS when such links are activated. (RETIREJS) suppress
DOMPurify's ADD_ATTR predicate function mechanism (via EXTRA_ELEMENT_HANDLING.attributeCheck) short-circuits URI validation when the predicate returns true. This allows unsafe protocols such as javascript: to survive sanitization in href and similar attributes, enabling DOM-based XSS when such links are activated.
Unscored:
References:
When USE_PROFILES is enabled, DOMPurify rebuilds ALLOWED_ATTR as a plain array whose properties are looked up by name, making it susceptible to prototype pollution. If Array.prototype has been polluted with an event handler attribute name (e.g. onclick), DOMPurify will allow that event handler to survive sanitization, resulting in DOM-based XSS. (RETIREJS) suppress
When USE_PROFILES is enabled, DOMPurify rebuilds ALLOWED_ATTR as a plain array whose properties are looked up by name, making it susceptible to prototype pollution. If Array.prototype has been polluted with an event handler attribute name (e.g. onclick), DOMPurify will allow that event handler to survive sanitization, resulting in DOM-based XSS.
Unscored:
References:
swagger-ui-5.17.14.jar: swagger-ui-es-bundle-core.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-ui-es-bundle-core.js
MD5: 6d1d2b740c3afdcc8e06a3296077dae3
SHA1: b7592ebdff721dd9e4395b602fe5302aa8900355
SHA256: a27834fd6ba3947c10118dac3f87ab91dc000926d725036f7db6758b6c4fb61c
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
swagger-ui-5.17.14.jar: swagger-ui-es-bundle.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-ui-es-bundle.js
MD5: 8eb90030c9696e65fba69e5cca855278
SHA1: 47717c193b2c8be0538f7f63c4ddccc9da6e75ad
SHA256: eb5860a4aff8e9cdb7753056739ee1724cc89baaaab326e75d3936062e06b551
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name DOMPurify High
Product file name DOMPurify High
Version file version 3.1.4 High
pkg:javascript/DOMPurify@3.1.4
(Confidence :Highest)
CVE-2025-26791 suppress
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions up to (excluding) 3.2.4
CVE-2026-41240 suppress
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive sanitization with their attributes intact. Version 3.4.0 patches the issue.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-183 Permissive List of Allowed Inputs
CVSSv4:
Base Score: MEDIUM (6.0)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions up to (excluding) 3.4.0
CVE-2026-0540 suppress
DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4:
Base Score: MEDIUM (5.3)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 2.5.3; versions up to (including) 2.5.8
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 3.1.3; versions up to (including) 3.3.1
CVE-2025-15599 suppress
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4:
Base Score: MEDIUM (5.1)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions (NVD):
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 2.5.3; versions up to (including) 2.5.8
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* versions from (including) 3.1.3; versions up to (excluding) 3.2.7
CVE-2026-41238 (RETIREJS) suppress
Unscored:
References:
CVE-2026-41239 (RETIREJS) suppress
Unscored:
References:
DOMPurify has a logic inconsistency where FORBID_TAGS is not checked when a function-based ADD_TAGS (tagCheck) returns true. Due to short-circuit evaluation, the FORBID_TAGS check is never evaluated, allowing explicitly forbidden elements to pass through sanitization when EXTRA_ELEMENT_HANDLING.tagCheck is configured. (RETIREJS) suppress
DOMPurify has a logic inconsistency where FORBID_TAGS is not checked when a function-based ADD_TAGS (tagCheck) returns true. Due to short-circuit evaluation, the FORBID_TAGS check is never evaluated, allowing explicitly forbidden elements to pass through sanitization when EXTRA_ELEMENT_HANDLING.tagCheck is configured.
Unscored:
References:
DOMPurify is vulnerable to mutation-XSS (mXSS) when sanitized HTML is embedded into special raw-text wrapper elements such as xmp, script, iframe, noembed, noframes, or noscript before being assigned via innerHTML. Attacker-controlled sequences like </xmp> inside attribute values close the raw-text context during the second parse, causing the sanitized output to mutate into executable markup. (RETIREJS) suppress
DOMPurify is vulnerable to mutation-XSS (mXSS) when sanitized HTML is embedded into special raw-text wrapper elements such as xmp, script, iframe, noembed, noframes, or noscript before being assigned via innerHTML. Attacker-controlled sequences like </xmp> inside attribute values close the raw-text context during the second parse, causing the sanitized output to mutate into executable markup.
Unscored:
References:
DOMPurify's ADD_ATTR predicate function mechanism (via EXTRA_ELEMENT_HANDLING.attributeCheck) short-circuits URI validation when the predicate returns true. This allows unsafe protocols such as javascript: to survive sanitization in href and similar attributes, enabling DOM-based XSS when such links are activated. (RETIREJS) suppress
DOMPurify's ADD_ATTR predicate function mechanism (via EXTRA_ELEMENT_HANDLING.attributeCheck) short-circuits URI validation when the predicate returns true. This allows unsafe protocols such as javascript: to survive sanitization in href and similar attributes, enabling DOM-based XSS when such links are activated.
Unscored:
References:
When USE_PROFILES is enabled, DOMPurify rebuilds ALLOWED_ATTR as a plain array whose properties are looked up by name, making it susceptible to prototype pollution. If Array.prototype has been polluted with an event handler attribute name (e.g. onclick), DOMPurify will allow that event handler to survive sanitization, resulting in DOM-based XSS. (RETIREJS) suppress
When USE_PROFILES is enabled, DOMPurify rebuilds ALLOWED_ATTR as a plain array whose properties are looked up by name, making it susceptible to prototype pollution. If Array.prototype has been polluted with an event handler attribute name (e.g. onclick), DOMPurify will allow that event handler to survive sanitization, resulting in DOM-based XSS.
Unscored:
References:
swagger-ui-5.17.14.jar: swagger-ui-standalone-preset.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-ui-standalone-preset.js
MD5: 861c3618a16aefc88e19a052836718e5
SHA1: c3073b573e55925510e2e6e6a1e2a564a2bc8558
SHA256: 33b7a6f5afcac4902fdf93281be2d2e12db15f241d384606e6e6d17745b7f86f
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
swagger-ui-5.17.14.jar: swagger-ui.js
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.webjars/swagger-ui/5.17.14/7c746d197424eb721b4e08fcaa9e85231662d81f/swagger-ui-5.17.14.jar/META-INF/resources/webjars/swagger-ui/5.17.14/swagger-ui.js
MD5: f5967d03b75271cf7d23ab17931ae2f4
SHA1: 8b0335d5bade188456d36cefad9b22976b907d90
SHA256: cbd1a3687472d025b41a49836fc0e59679d7fd8eab38168d51b439e730b778a1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
taglibs-standard-impl-1.2.5.jar
Description:
An implementation of the JSP Standard Tag Library (JSTL).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.taglibs/taglibs-standard-impl/1.2.5/9b9783ccb2a323383e6e20e36d368f8997b71967/taglibs-standard-impl-1.2.5.jar
MD5: 8e5c8db242fbef3db1acfcbb3bc8ec8b
SHA1: 9b9783ccb2a323383e6e20e36d368f8997b71967
SHA256: d075cb77d94e2d115b4d90a897b57d65cc31ed8e1b95d65361da324642705728
Referenced In Project/Scope: server-start:runtimeClasspath
taglibs-standard-impl-1.2.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name taglibs-standard-impl High
Vendor gradle artifactid taglibs-standard-impl Highest
Vendor gradle groupid org.apache.taglibs Highest
Vendor jar package name apache Highest
Vendor jar package name standard Highest
Vendor jar package name tag Highest
Vendor jar package name taglibs Highest
Vendor Manifest bundle-docurl http://tomcat.apache.org/taglibs/standard-1.2.5/taglibs-standard-impl Low
Vendor Manifest bundle-symbolicname org.apache.taglibs.standard-impl Medium
Vendor pom artifactid taglibs-standard-impl Low
Vendor pom developer name Bjorn Townsend Medium
Vendor pom developer name Dmitri Plotnikov Medium
Vendor pom developer name Felipe Leme Medium
Vendor pom developer name Glenn Nielsen Medium
Vendor pom developer name Hans Bergsten Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jan Luehe Medium
Vendor pom developer name Justyna Horwat Medium
Vendor pom developer name Mark Kolb Medium
Vendor pom developer name Nathan Abramson Medium
Vendor pom developer name Pierre Delisle Medium
Vendor pom developer name Scott Hasse Medium
Vendor pom developer name Shawn Bayern Medium
Vendor pom groupid org.apache.taglibs Highest
Vendor pom name Apache Standard Taglib Implementation High
Vendor pom parent-artifactid taglibs-standard Low
Product file name taglibs-standard-impl High
Product gradle artifactid taglibs-standard-impl Highest
Product jar package name apache Highest
Product jar package name standard Highest
Product jar package name tag Highest
Product jar package name taglibs Highest
Product Manifest bundle-docurl http://tomcat.apache.org/taglibs/standard-1.2.5/taglibs-standard-impl Low
Product Manifest Bundle-Name Apache Standard Taglib Implementation Medium
Product Manifest bundle-symbolicname org.apache.taglibs.standard-impl Medium
Product Manifest Implementation-Title Apache Standard Taglib Implementation High
Product pom artifactid taglibs-standard-impl Highest
Product pom developer name Bjorn Townsend Low
Product pom developer name Dmitri Plotnikov Low
Product pom developer name Felipe Leme Low
Product pom developer name Glenn Nielsen Low
Product pom developer name Hans Bergsten Low
Product pom developer name Henri Yandell Low
Product pom developer name Jan Luehe Low
Product pom developer name Justyna Horwat Low
Product pom developer name Mark Kolb Low
Product pom developer name Nathan Abramson Low
Product pom developer name Pierre Delisle Low
Product pom developer name Scott Hasse Low
Product pom developer name Shawn Bayern Low
Product pom groupid org.apache.taglibs Highest
Product pom name Apache Standard Taglib Implementation High
Product pom parent-artifactid taglibs-standard Medium
Version file version 1.2.5 High
Version gradle version 1.2.5 Highest
Version Manifest Bundle-Version 1.2.5 High
Version Manifest Implementation-Version 1.2.5 High
Version pom version 1.2.5 Highest
taglibs-standard-spec-1.2.5.jar
Description:
An implementation of the JSP Standard Tag Library (JSTL) Specification API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.taglibs/taglibs-standard-spec/1.2.5/c3bb98c30f75fef1e229d1d03cf8457de22f1ba0/taglibs-standard-spec-1.2.5.jar
MD5: 671c434560d04e8f06aac02a413d11e4
SHA1: c3bb98c30f75fef1e229d1d03cf8457de22f1ba0
SHA256: 81a195f8acab3f072fe4d6c279b7c29575bcac49081076e3d08bbda829275189
Referenced In Project/Scope: server-start:runtimeClasspath
taglibs-standard-spec-1.2.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name taglibs-standard-spec High
Vendor gradle artifactid taglibs-standard-spec Highest
Vendor gradle groupid org.apache.taglibs Highest
Vendor jar package name jsp Highest
Vendor jar package name jstl Highest
Vendor Manifest bundle-docurl http://tomcat.apache.org/taglibs/standard-1.2.5/taglibs-standard-spec Low
Vendor Manifest bundle-symbolicname org.apache.taglibs.taglibs-standard-spec;singleton=true Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid taglibs-standard-spec Low
Vendor pom developer name Bjorn Townsend Medium
Vendor pom developer name Dmitri Plotnikov Medium
Vendor pom developer name Felipe Leme Medium
Vendor pom developer name Glenn Nielsen Medium
Vendor pom developer name Hans Bergsten Medium
Vendor pom developer name Henri Yandell Medium
Vendor pom developer name Jan Luehe Medium
Vendor pom developer name Justyna Horwat Medium
Vendor pom developer name Mark Kolb Medium
Vendor pom developer name Nathan Abramson Medium
Vendor pom developer name Pierre Delisle Medium
Vendor pom developer name Scott Hasse Medium
Vendor pom developer name Shawn Bayern Medium
Vendor pom groupid org.apache.taglibs Highest
Vendor pom name Apache Standard Taglib Specification API High
Vendor pom parent-artifactid taglibs-standard Low
Product file name taglibs-standard-spec High
Product gradle artifactid taglibs-standard-spec Highest
Product jar package name jsp Highest
Product jar package name jstl Highest
Product Manifest bundle-docurl http://tomcat.apache.org/taglibs/standard-1.2.5/taglibs-standard-spec Low
Product Manifest Bundle-Name Apache Standard Taglib Specification API Medium
Product Manifest bundle-symbolicname org.apache.taglibs.taglibs-standard-spec;singleton=true Medium
Product Manifest Implementation-Title Apache Standard Taglib Specification API High
Product Manifest specification-title JSR-052 JavaServer Pages Standard Tag Library Specification Medium
Product pom artifactid taglibs-standard-spec Highest
Product pom developer name Bjorn Townsend Low
Product pom developer name Dmitri Plotnikov Low
Product pom developer name Felipe Leme Low
Product pom developer name Glenn Nielsen Low
Product pom developer name Hans Bergsten Low
Product pom developer name Henri Yandell Low
Product pom developer name Jan Luehe Low
Product pom developer name Justyna Horwat Low
Product pom developer name Mark Kolb Low
Product pom developer name Nathan Abramson Low
Product pom developer name Pierre Delisle Low
Product pom developer name Scott Hasse Low
Product pom developer name Shawn Bayern Low
Product pom groupid org.apache.taglibs Highest
Product pom name Apache Standard Taglib Specification API High
Product pom parent-artifactid taglibs-standard Medium
Version file version 1.2.5 High
Version gradle version 1.2.5 Highest
Version Manifest Bundle-Version 1.2.5 High
Version Manifest Implementation-Version 1.2.5 High
Version pom version 1.2.5 Highest
third-party-jackson-core-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/third-party-jackson-core/2.26.30/5bb70421679cc805240598d4275fdc854d22cce9/third-party-jackson-core-2.26.30.jar
MD5: 268619b9de822090cd7e5f14944a5882
SHA1: 5bb70421679cc805240598d4275fdc854d22cce9
SHA256: 4f006348a708a9625188f1b7b2c5474caab9cb54286ba0de51cd3dc79a30ae35
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
third-party-jackson-core-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name third-party-jackson-core High
Vendor gradle artifactid third-party-jackson-core Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name amazon Low
Vendor jar package name awssdk Highest
Vendor jar package name awssdk Low
Vendor jar package name software Highest
Vendor jar package name software Low
Vendor jar package name thirdparty Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.thirdparty.jackson.core Medium
Vendor pom artifactid third-party-jackson-core Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Third Party :: Jackson-core High
Vendor pom parent-artifactid third-party Low
Vendor pom url https://aws.amazon.com/sdkforjava Highest
Product file name third-party-jackson-core High
Product gradle artifactid third-party-jackson-core Highest
Product jar package name amazon Highest
Product jar package name amazon Low
Product jar package name awssdk Highest
Product jar package name awssdk Low
Product jar package name software Highest
Product jar package name thirdparty Highest
Product jar package name thirdparty Low
Product Manifest automatic-module-name software.amazon.awssdk.thirdparty.jackson.core Medium
Product pom artifactid third-party-jackson-core Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Third Party :: Jackson-core High
Product pom parent-artifactid third-party Medium
Product pom url https://aws.amazon.com/sdkforjava Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
txw2-2.3.2.jar
Description:
TXW is a library that allows you to write XML documents.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/txw2/2.3.2/ce5be7da2e442c25ec14c766cb60cb802741727b/txw2-2.3.2.jar
MD5: 3f278f148c5d27dc608c25cb7d093b94
SHA1: ce5be7da2e442c25ec14c766cb60cb802741727b
SHA256: 4a6a9f483388d461b81aa9a28c685b8b74c0597993bf1884b04eddbca95f48fe
Referenced In Project/Scope: server-start:compileClasspath
txw2-2.3.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name txw2 High
Vendor gradle artifactid txw2 Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name sun Highest
Vendor jar package name txw Highest
Vendor jar package name txw2 Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest git-revision ae93d95 Low
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest Implementation-Vendor-Id com.oracle Medium
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom artifactid txw2 Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name TXW2 Runtime High
Vendor pom parent-artifactid jaxb-txw-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Product file name txw2 High
Product gradle artifactid txw2 Highest
Product jar package name sun Highest
Product jar package name txw Highest
Product jar package name txw2 Highest
Product jar package name xml Highest
Product Manifest git-revision ae93d95 Low
Product Manifest Implementation-Title TXW Runtime High
Product Manifest specification-title Java Architecture for XML Binding Medium
Product pom artifactid txw2 Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name TXW2 Runtime High
Product pom parent-artifactid jaxb-txw-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Version file version 2.3.2 High
Version gradle version 2.3.2 Highest
Version Manifest build-id 2.3.2 Medium
Version Manifest Implementation-Version 2.3.2 High
Version Manifest major-version 2.3.2 Medium
Version pom version 2.3.2 Highest
pkg:maven/org.glassfish.jaxb/txw2@2.3.2
(Confidence :High)
txw2-2.3.6.jar
Description:
TXW is a library that allows you to write XML documents.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/txw2/2.3.6/45db7b69a8f1ec2c21eb7d4fc0ee729f53c1addc/txw2-2.3.6.jar
MD5: dd02e61e4662e6461f0c21b08e721021
SHA1: 45db7b69a8f1ec2c21eb7d4fc0ee729f53c1addc
SHA256: f8bc249d22ad950257c373aea80c2f16f18f5eb4d557bdb2660bf5e1f1e84776
Referenced In Project/Scope: server-start:runtimeClasspath
txw2-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name txw2 High
Vendor gradle artifactid txw2 Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name sun Highest
Vendor jar package name txw Highest
Vendor jar package name txw2 Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest git-revision e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor pom artifactid txw2 Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name TXW2 Runtime High
Vendor pom parent-artifactid jaxb-txw-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name txw2 High
Product gradle artifactid txw2 Highest
Product jar package name sun Highest
Product jar package name txw Highest
Product jar package name txw2 Highest
Product jar package name xml Highest
Product Manifest git-revision e9f7f5f Low
Product Manifest Implementation-Title Jakarta XML Binding Implementation High
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid txw2 Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name TXW2 Runtime High
Product pom parent-artifactid jaxb-txw-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest build-id 2.3.6 Medium
Version Manifest Implementation-Version 2.3.6 High
Version Manifest major-version 2.3.6 Medium
Version pom version 2.3.6 Highest
pkg:maven/org.glassfish.jaxb/txw2@2.3.6
(Confidence :High)
txw2-4.0.5.jar
Description:
TXW is a library that allows you to write XML documents.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/txw2/4.0.5/f36a4ef12120a9bb06d766d6a0e54b144fd7ed98/txw2-4.0.5.jar
MD5: 2f5aa7dbd5e326562cff6ce720a1485a
SHA1: f36a4ef12120a9bb06d766d6a0e54b144fd7ed98
SHA256: 917355bc451481f30d043b24d123110517966af34383901773882810dca480e5
Referenced In Project/Scope: server-start:webapps
txw2-4.0.5.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name txw2 High
Vendor gradle artifactid txw2 Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name sun Highest
Vendor jar package name txw Highest
Vendor jar package name txw2 Highest
Vendor jar package name xml Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest git-revision cb19596 Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid txw2 Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name TXW2 Runtime High
Vendor pom parent-artifactid jaxb-txw-parent Low
Vendor pom parent-groupid com.sun.xml.bind.mvn Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name txw2 High
Product gradle artifactid txw2 Highest
Product jar package name sun Highest
Product jar package name txw Highest
Product jar package name txw2 Highest
Product jar package name xml Highest
Product Manifest git-revision cb19596 Low
Product Manifest Implementation-Title Eclipse Implementation of JAXB High
Product Manifest specification-title Jakarta XML Binding Medium
Product pom artifactid txw2 Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name TXW2 Runtime High
Product pom parent-artifactid jaxb-txw-parent Medium
Product pom parent-groupid com.sun.xml.bind.mvn Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 4.0.5 High
Version gradle version 4.0.5 Highest
Version Manifest build-version 4.0.5 Medium
Version pom version 4.0.5 Highest
pkg:maven/org.glassfish.jaxb/txw2@4.0.5
(Confidence :High)
utils-2.26.30.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/software.amazon.awssdk/utils/2.26.30/e7d1fdf137805f5c2f306af70d9ea40a0909e92c/utils-2.26.30.jar
MD5: 073f03698908240be85f47ffb36e3527
SHA1: e7d1fdf137805f5c2f306af70d9ea40a0909e92c
SHA256: 47125639c3e699fc339154d695fa0cde78c34033cebb19808a1b750f44da692e
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
utils-2.26.30.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name utils High
Vendor gradle artifactid utils Highest
Vendor gradle groupid software.amazon.awssdk Highest
Vendor jar package name amazon Highest
Vendor jar package name awssdk Highest
Vendor jar package name software Highest
Vendor jar package name utils Highest
Vendor Manifest automatic-module-name software.amazon.awssdk.utils Medium
Vendor Manifest build-jdk-spec 11 Low
Vendor pom artifactid utils Low
Vendor pom groupid software.amazon.awssdk Highest
Vendor pom name AWS Java SDK :: Utilities High
Vendor pom parent-artifactid aws-sdk-java-pom Low
Product file name utils High
Product gradle artifactid utils Highest
Product jar package name amazon Highest
Product jar package name awssdk Highest
Product jar package name software Highest
Product jar package name utils Highest
Product Manifest automatic-module-name software.amazon.awssdk.utils Medium
Product Manifest build-jdk-spec 11 Low
Product pom artifactid utils Highest
Product pom groupid software.amazon.awssdk Highest
Product pom name AWS Java SDK :: Utilities High
Product pom parent-artifactid aws-sdk-java-pom Medium
Version file version 2.26.30 High
Version gradle version 2.26.30 Highest
Version pom version 2.26.30 Highest
vavr-0.10.7.jar
Description:
Vavr (formerly called Javaslang) is an object-functional language extension to Java 8+.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.vavr/vavr/0.10.7/855105af0b36941e0d23303a8edeec9e6655719a/vavr-0.10.7.jar
MD5: 282f7a459656719db99b56813980c2e8
SHA1: 855105af0b36941e0d23303a8edeec9e6655719a
SHA256: 40d05a7531f7d6411d7fce5e096ed93f52e780c9cb6f699a9ced88f765288a0c
Referenced In Project/Scope: server-start:runtimeClasspath
vavr-0.10.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name vavr High
Vendor gradle artifactid vavr Highest
Vendor gradle groupid io.vavr Highest
Vendor jar package name io Highest
Vendor jar package name vavr Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-symbolicname io.vavr Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid vavr Low
Vendor pom groupid io.vavr Highest
Vendor pom name Vavr High
Vendor pom parent-artifactid vavr-parent Low
Vendor pom url https://vavr.io Highest
Product file name vavr High
Product gradle artifactid vavr Highest
Product jar package name io Highest
Product jar package name vavr Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Bundle-Name Vavr Medium
Product Manifest bundle-symbolicname io.vavr Medium
Product Manifest multi-release true Low
Product pom artifactid vavr Highest
Product pom groupid io.vavr Highest
Product pom name Vavr High
Product pom parent-artifactid vavr-parent Medium
Product pom url https://vavr.io Medium
Version file version 0.10.7 High
Version gradle version 0.10.7 Highest
Version Manifest Bundle-Version 0.10.7 High
Version pom version 0.10.7 Highest
pkg:maven/io.vavr/vavr@0.10.7
(Confidence :High)
vavr-match-0.10.7.jar
Description:
Annotation for structural pattern matching
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.vavr/vavr-match/0.10.7/25d24e4d9afc565538cb505bac7285c091aced5a/vavr-match-0.10.7.jar
MD5: 9fd462f9cf2de60b40d826ccdd6b3710
SHA1: 25d24e4d9afc565538cb505bac7285c091aced5a
SHA256: ed86f834c0c03fa2d9ec270914a47a8a0d017573bc11fa2b5b999cbdccb18614
Referenced In Project/Scope: server-start:runtimeClasspath
vavr-match-0.10.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name vavr-match High
Vendor gradle artifactid vavr-match Highest
Vendor gradle groupid io.vavr Highest
Vendor jar package name annotation Highest
Vendor jar package name io Highest
Vendor jar package name match Highest
Vendor jar package name vavr Highest
Vendor Manifest automatic-module-name io.vavr.match Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-symbolicname io.vavr.match Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid vavr-match Low
Vendor pom developer email cafebab3@gmail.com Low
Vendor pom developer email gpiwowarek@gmail.com Low
Vendor pom developer id danieldietrich Medium
Vendor pom developer id pivovarit Medium
Vendor pom developer name Daniel Dietrich Medium
Vendor pom developer name Grzegorz Piwowarek Medium
Vendor pom groupid io.vavr Highest
Vendor pom name Vavr Match High
Vendor pom url https://vavr.io Highest
Product file name vavr-match High
Product gradle artifactid vavr-match Highest
Product jar package name annotation Highest
Product jar package name io Highest
Product jar package name match Highest
Product jar package name vavr Highest
Product Manifest automatic-module-name io.vavr.match Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest Bundle-Name Vavr Match Medium
Product Manifest bundle-symbolicname io.vavr.match Medium
Product Manifest multi-release true Low
Product pom artifactid vavr-match Highest
Product pom developer email cafebab3@gmail.com Low
Product pom developer email gpiwowarek@gmail.com Low
Product pom developer id danieldietrich Low
Product pom developer id pivovarit Low
Product pom developer name Daniel Dietrich Low
Product pom developer name Grzegorz Piwowarek Low
Product pom groupid io.vavr Highest
Product pom name Vavr Match High
Product pom url https://vavr.io Medium
Version file version 0.10.7 High
Version gradle version 0.10.7 Highest
Version Manifest Bundle-Version 0.10.7 High
Version pom version 0.10.7 Highest
pkg:maven/io.vavr/vavr-match@0.10.7
(Confidence :High)
velocity-engine-core-2.4.1.jar
Description:
Apache Velocity is a general purpose template engine.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.velocity/velocity-engine-core/2.4.1/b662837e8006d5c383bd128503ea86ef5b4d361/velocity-engine-core-2.4.1.jar
MD5: 41a3757dc9d701590be703d1f2bd2462
SHA1: 0b662837e8006d5c383bd128503ea86ef5b4d361
SHA256: 1c19157d1171d560088e485be97c93a7a2f7e9f56e517f0a30273c5c39df6231
Referenced In Project/Scope: server-start:webapps
velocity-engine-core-2.4.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name velocity-engine-core High
Vendor gradle artifactid velocity-engine-core Highest
Vendor gradle groupid org.apache.velocity Highest
Vendor jar package name apache Highest
Vendor jar package name velocity Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.velocity.engine-core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid velocity-engine-core Low
Vendor pom groupid org.apache.velocity Highest
Vendor pom name Apache Velocity - Engine High
Vendor pom parent-artifactid velocity-engine-parent Low
Product file name velocity-engine-core High
Product gradle artifactid velocity-engine-core Highest
Product jar package name apache Highest
Product jar package name template Highest
Product jar package name velocity Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache Velocity - Engine Medium
Product Manifest bundle-symbolicname org.apache.velocity.engine-core Medium
Product Manifest Implementation-Title Apache Velocity - Engine High
Product Manifest specification-title Apache Velocity - Engine Medium
Product pom artifactid velocity-engine-core Highest
Product pom groupid org.apache.velocity Highest
Product pom name Apache Velocity - Engine High
Product pom parent-artifactid velocity-engine-parent Medium
Version file version 2.4.1 High
Version gradle version 2.4.1 Highest
Version Manifest Bundle-Version 2.4.1 High
Version Manifest Implementation-Version 2.4.1 High
Version pom version 2.4.1 Highest
weld-se-shaded-5.1.2.Final.jar (shaded: jakarta.el:jakarta.el-api:5.0.1)
Description:
Jakarta Expression Language defines an expression language for Java applications
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/jakarta.el/jakarta.el-api/pom.xml
MD5: e59d38e6f16a213b721edca9b5ee389b
SHA1: f8eb17de87dd57f4e30ea8cb4e8ecd3dd191f8d7
SHA256: 06b94a0dcedec8c9072b670f2408c4f0970781f6308505442724241e25a81348
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jakarta.el-api Low
Vendor pom developer email el-dev@eclipse.org Low
Vendor pom developer id jakarta-ee4j-el Medium
Vendor pom developer name Jakarta Expression Language Developers Medium
Vendor pom developer org Eclipse Foundation Medium
Vendor pom groupid jakarta.el Highest
Vendor pom name Jakarta Expression Language API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.el Highest
Product pom artifactid jakarta.el-api Highest
Product pom developer email el-dev@eclipse.org Low
Product pom developer id jakarta-ee4j-el Low
Product pom developer name Jakarta Expression Language Developers Low
Product pom developer org Eclipse Foundation Low
Product pom groupid jakarta.el Highest
Product pom name Jakarta Expression Language API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.el Medium
Version pom parent-version 5.0.1 Low
Version pom version 5.0.1 Highest
pkg:maven/jakarta.el/jakarta.el-api@5.0.1
(Confidence :High)
cpe:2.3:a:eclipse:jakarta_expression_language:5.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.classfilewriter:jboss-classfilewriter:1.3.0.Final)
Description:
A bytecode writer that creates .class files at runtime
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.classfilewriter/jboss-classfilewriter/pom.xml
MD5: 473f56308269f99b8922638b15bb6534
SHA1: 1b67105916c2c1eda3b53f7473c6bf763fad9cfb
SHA256: 32e72cd06748c014e7c742516b4793fb8431dceb6dfc3878a5a15ce8e1527108
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-classfilewriter Low
Vendor pom developer email sdouglas@redhat.com Low
Vendor pom developer name Stuart Douglas Medium
Vendor pom groupid org.jboss.classfilewriter Highest
Vendor pom name classfilewriter High
Vendor pom parent-artifactid jboss-parent Low
Vendor pom parent-groupid org.jboss Medium
Vendor pom url jbossas/jboss-classfilewriter Highest
Product pom artifactid jboss-classfilewriter Highest
Product pom developer email sdouglas@redhat.com Low
Product pom developer name Stuart Douglas Low
Product pom groupid org.jboss.classfilewriter Highest
Product pom name classfilewriter High
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Medium
Product pom url jbossas/jboss-classfilewriter High
Version pom parent-version 1.3.0.Final Low
Version pom version 1.3.0.Final Highest
pkg:maven/org.jboss.classfilewriter/jboss-classfilewriter@1.3.0.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.jdeparser:jdeparser:2.0.3.Final)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.jdeparser/jdeparser/pom.xml
MD5: cfc4cddb99ee1be4a70ec14142eb2277
SHA1: ab5e35dc566b507d0c4e00175ac4c12ee7251d59
SHA256: 8f0084a615a3e716d020fc4e74c370c7d346b7ab3e1f7284656cad2b50c1929d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jdeparser Low
Vendor pom groupid org.jboss.jdeparser Highest
Vendor pom parent-artifactid jboss-parent Low
Vendor pom parent-groupid org.jboss Medium
Product pom artifactid jdeparser Highest
Product pom groupid org.jboss.jdeparser Highest
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Medium
Version pom parent-version 2.0.3.Final Low
Version pom version 2.0.3.Final Highest
pkg:maven/org.jboss.jdeparser/jdeparser@2.0.3.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.logging:jboss-logging-annotations:2.2.1.Final)
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.logging/jboss-logging-annotations/pom.xml
MD5: 8b46da9db066b417db170296bb0238a0
SHA1: 84964d9370219d6a18d445dff40c1f7472c3341c
SHA256: c053271fa743cff1c90b1fcb82845eb66fcc289d549d2f9902c7b456577250a0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-logging-annotations Low
Vendor pom groupid org.jboss.logging Highest
Vendor pom name JBoss Logging I18n Annotations High
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Product pom artifactid jboss-logging-annotations Highest
Product pom groupid org.jboss.logging Highest
Product pom name JBoss Logging I18n Annotations High
Product pom parent-artifactid jboss-logging-tools-parent Medium
Version pom version 2.2.1.Final Highest
pkg:maven/org.jboss.logging/jboss-logging-annotations@2.2.1.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.logging:jboss-logging-processor:2.2.1.Final)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.logging/jboss-logging-processor/pom.xml
MD5: 81484c063cbbac4f93d861fa99527ae2
SHA1: d1a80d21e360cebb4263ceb8de1a02fec98bd559
SHA256: 175ae861457e5a20c8524599a84b7755b5954f7e5bf0ba27f89318672dbc3c34
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-logging-processor Low
Vendor pom groupid org.jboss.logging Highest
Vendor pom name JBoss Logging I18n Annotation Processor High
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Product pom artifactid jboss-logging-processor Highest
Product pom groupid org.jboss.logging Highest
Product pom name JBoss Logging I18n Annotation Processor High
Product pom parent-artifactid jboss-logging-tools-parent Medium
Version pom version 2.2.1.Final Highest
pkg:maven/org.jboss.logging/jboss-logging-processor@2.2.1.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.logging:jboss-logging:3.5.0.Final)
Description:
The JBoss Logging Framework
License:
Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.logging/jboss-logging/pom.xml
MD5: 163991147c121b891fe3898dabf4c666
SHA1: 07005c250dadc2cc23a4f1aebf8b7de1e148db9c
SHA256: 4b68e3b46d9dc22d99d7819352fcbb43767d31d8ebd22a8e13f10e11867c468e
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-logging Low
Vendor pom groupid org.jboss.logging Highest
Vendor pom name JBoss Logging 3 High
Vendor pom parent-artifactid jboss-parent Low
Vendor pom parent-groupid org.jboss Medium
Vendor pom url http://www.jboss.org Highest
Product pom artifactid jboss-logging Highest
Product pom groupid org.jboss.logging Highest
Product pom name JBoss Logging 3 High
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Medium
Product pom url http://www.jboss.org Medium
Version pom parent-version 3.5.0.Final Low
Version pom version 3.5.0.Final Highest
pkg:maven/org.jboss.logging/jboss-logging@3.5.0.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld.environment:weld-environment-common:5.1.2.Final)
Description:
Common tools for non-standard Weld environments (SE, Servlet containers)
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld.environment/weld-environment-common/pom.xml
MD5: 162c6ce5d620370206c918f7ab25be5c
SHA1: d100ca74ac6e61394716b75142fc56d222133967
SHA256: 7c50cf8f8226e6445bdd5a7e82bfe4d5ea3237857c58638e12bad5d646867861
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-environment-common Low
Vendor pom groupid org.jboss.weld.environment Highest
Vendor pom name Weld Environment Common High
Vendor pom parent-artifactid weld-core-parent Low
Vendor pom parent-groupid org.jboss.weld Medium
Vendor pom url http://weld.cdi-spec.org Highest
Product pom artifactid weld-environment-common Highest
Product pom groupid org.jboss.weld.environment Highest
Product pom name Weld Environment Common High
Product pom parent-artifactid weld-core-parent Medium
Product pom parent-groupid org.jboss.weld Medium
Product pom url http://weld.cdi-spec.org Medium
Version pom version 5.1.2.Final Highest
pkg:maven/org.jboss.weld.environment/weld-environment-common@5.1.2.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld.se:weld-se-core:5.1.2.Final)
Description:
Weld support for Java SE
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld.se/weld-se-core/pom.xml
MD5: 87c2fc5ebc21a007b71efa58873b182d
SHA1: 3468bd27cdae9f71abe2346298e1bfb3eeee9fea
SHA256: ab1c69a94e0afdeb21ba6360ff7684fc3ac1c4a557e27486d38a3c9e30b4257f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-se-core Low
Vendor pom developer name Pete Royle Medium
Vendor pom groupid org.jboss.weld.se Highest
Vendor pom name Weld SE (Core) High
Vendor pom parent-artifactid weld-se-parent Low
Vendor pom url http://weld.cdi-spec.org Highest
Product pom artifactid weld-se-core Highest
Product pom developer name Pete Royle Low
Product pom groupid org.jboss.weld.se Highest
Product pom name Weld SE (Core) High
Product pom parent-artifactid weld-se-parent Medium
Product pom url http://weld.cdi-spec.org Medium
Version pom version 5.1.2.Final Highest
pkg:maven/org.jboss.weld.se/weld-se-core@5.1.2.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld:weld-api:5.0.SP3)
Description:
Weld specifc extensions to the CDI API
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld/weld-api/pom.xml
MD5: 7535b464e97b6b5cfa49c62a0424a8ee
SHA1: 2e0e61f4d0a1e3c9deb0d2437e6b854ed478ee3f
SHA256: 3692c81ebbb0625fc3c4ced5ab89f465d3b9eded62e6926e31a39daa2074e170
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-api Low
Vendor pom groupid org.jboss.weld Highest
Vendor pom name Weld APIs High
Vendor pom parent-artifactid weld-api-parent Low
Vendor pom url http://weld.cdi-spec.org Highest
Product pom artifactid weld-api Highest
Product pom groupid org.jboss.weld Highest
Product pom name Weld APIs High
Product pom parent-artifactid weld-api-parent Medium
Product pom url http://weld.cdi-spec.org Medium
Version pom version 5.0.SP3 Highest
pkg:maven/org.jboss.weld/weld-api@5.0.SP3
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld:weld-core-impl:5.1.2.Final)
Description:
Weld's implementation of CDI
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld/weld-core-impl/pom.xml
MD5: a45d44ab4d9c17e2bda428dde49ddaa0
SHA1: 50562451172b72a1ef5cd98f4e29e98d7048966a
SHA256: 26ce9c4f98357cfda734400448424aa5c9ed85901e0084e08dab4b65acdfd872
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-core-impl Low
Vendor pom groupid org.jboss.weld Highest
Vendor pom name Weld Implementation (Core) High
Vendor pom parent-artifactid weld-core-parent Low
Vendor pom url http://weld.cdi-spec.org Highest
Product pom artifactid weld-core-impl Highest
Product pom groupid org.jboss.weld Highest
Product pom name Weld Implementation (Core) High
Product pom parent-artifactid weld-core-parent Medium
Product pom url http://weld.cdi-spec.org Medium
Version pom version 5.1.2.Final Highest
pkg:maven/org.jboss.weld/weld-core-impl@5.1.2.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld:weld-lite-extension-translator:5.1.2.Final)
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld/weld-lite-extension-translator/pom.xml
MD5: 2d831b08313f57adb87d3f48b98cc6b6
SHA1: 954f44b7a05c45193ec60227c3095b3a87ec0a75
SHA256: b3511247f05e0401ccc19bac1824c2dabc23ec9ba784d82055b378504f48d500
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-lite-extension-translator Low
Vendor pom groupid org.jboss.weld Highest
Vendor pom name CDI Lite Extension Translator High
Vendor pom parent-artifactid weld-core-parent Low
Product pom artifactid weld-lite-extension-translator Highest
Product pom groupid org.jboss.weld Highest
Product pom name CDI Lite Extension Translator High
Product pom parent-artifactid weld-core-parent Medium
Version pom version 5.1.2.Final Highest
pkg:maven/org.jboss.weld/weld-lite-extension-translator@5.1.2.Final
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar (shaded: org.jboss.weld:weld-spi:5.0.SP3)
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar/META-INF/maven/org.jboss.weld/weld-spi/pom.xml
MD5: afcc4af3e01d60487d884e45d8846cf5
SHA1: 521498d8bad32817a3f07d7f1487fce51a49a5dd
SHA256: 3732dcd6d6e0b678ef8963eb40d05178d9d5ba588e3b521e4f13baec8bba030f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid weld-spi Low
Vendor pom groupid org.jboss.weld Highest
Vendor pom name Weld SPIs for container integration High
Vendor pom parent-artifactid weld-api-parent Low
Vendor pom url http://weld.cdi-spec.org Highest
Product pom artifactid weld-spi Highest
Product pom groupid org.jboss.weld Highest
Product pom name Weld SPIs for container integration High
Product pom parent-artifactid weld-api-parent Medium
Product pom url http://weld.cdi-spec.org Medium
Version pom version 5.0.SP3 Highest
pkg:maven/org.jboss.weld/weld-spi@5.0.SP3
(Confidence :High)
weld-se-shaded-5.1.2.Final.jar
Description:
This jar bundles all the bits of Weld and CDI required for Java SE.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.jboss.weld.se/weld-se-shaded/5.1.2.Final/414cba66917ae1789744ac5dce6c6a420fde438a/weld-se-shaded-5.1.2.Final.jar
MD5: edbc4780b52be36780af5a49f5994da4
SHA1: 414cba66917ae1789744ac5dce6c6a420fde438a
SHA256: 5ea0b5e23e5132b86d5a48b0ea7ff049b6b5dcd9fbffee84c1d6c4fb91e529db
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
weld-se-shaded-5.1.2.Final.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name weld-se-shaded High
Vendor gradle artifactid weld-se-shaded Highest
Vendor gradle groupid org.jboss.weld.se Highest
Vendor jar package name jboss Highest
Vendor jar package name se Highest
Vendor jar package name weld Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest build-time 2023-10-05 18:48 Low
Vendor Manifest multi-release true Low
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest scm d1c990e5b0353c3324b3f406e41a7f2b1d19fcca Low
Vendor pom artifactid weld-se-shaded Low
Vendor pom groupid org.jboss.weld.se Highest
Vendor pom name Weld SE (Uber Jar) High
Vendor pom parent-artifactid weld-se-parent Low
Vendor pom url http://weld.cdi-spec.org Highest
Product file name weld-se-shaded High
Product gradle artifactid weld-se-shaded Highest
Product jar package name contexts Highest
Product jar package name injection Highest
Product jar package name jakarta Highest
Product jar package name jboss Highest
Product jar package name se Highest
Product jar package name weld Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest build-time 2023-10-05 18:48 Low
Product Manifest Implementation-Title Weld SE (Uber Jar) High
Product Manifest multi-release true Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest scm d1c990e5b0353c3324b3f406e41a7f2b1d19fcca Low
Product Manifest specification-title Jakarta EE 10 Contexts and Dependency Injection for Java Medium
Product pom artifactid weld-se-shaded Highest
Product pom groupid org.jboss.weld.se Highest
Product pom name Weld SE (Uber Jar) High
Product pom parent-artifactid weld-se-parent Medium
Product pom url http://weld.cdi-spec.org Medium
Version gradle version 5.1.2.Final Highest
Version Manifest Implementation-Version 5.1.2.Final High
Version pom version 5.1.2.Final Highest
pkg:maven/org.jboss.weld.se/weld-se-shaded@5.1.2.Final
(Confidence :High)
woden-core-1.0M10.jar
Description:
The Woden project is a subproject of the Apache Web Services Project to develop a Java class library for reading, manipulating, creating and writing WSDL documents, initially to support WSDL 2.0 but with the longer term aim of supporting past, present and future versions of WSDL. There are two main deliverables: an API and an implementation. The Woden API consists of a set of Java interfaces. The WSDL 2.0-specific portion of the Woden API conforms to the W3C WSDL 2.0 specification. The implementation will be a high performance implementation directly usable in other Apache projects such as Axis2.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.woden/woden-core/1.0M10/ffed89bc39eb7fce6b74765b3417c6844d8003a2/woden-core-1.0M10.jar
MD5: 7b04937efc02bbc6cb0b73afb5d48b78
SHA1: ffed89bc39eb7fce6b74765b3417c6844d8003a2
SHA256: 71ab01b4a4557e18c9c354546283bff1099121d62e64088961b368b290e17309
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
woden-core-1.0M10.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name woden-core High
Vendor gradle artifactid woden-core Highest
Vendor gradle groupid org.apache.woden Highest
Vendor jar package name apache Highest
Vendor jar package name woden Highest
Vendor Manifest bundle-docurl http://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.woden.core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid woden-core Low
Vendor pom groupid org.apache.woden Highest
Vendor pom name Woden - Core High
Vendor pom parent-artifactid woden Low
Product file name woden-core High
Product gradle artifactid woden-core Highest
Product jar package name apache Highest
Product jar package name woden Highest
Product Manifest bundle-docurl http://www.apache.org/ Low
Product Manifest Bundle-Name Woden - Core Medium
Product Manifest bundle-symbolicname org.apache.woden.core Medium
Product Manifest Implementation-Title Apache Woden High
Product Manifest specification-title Apache Woden Medium
Product pom artifactid woden-core Highest
Product pom groupid org.apache.woden Highest
Product pom name Woden - Core High
Product pom parent-artifactid woden Medium
Version gradle version 1.0M10 Highest
Version Manifest Implementation-Version 1.0M10 High
Version pom version 1.0M10 Highest
pkg:maven/org.apache.woden/woden-core@1.0M10
(Confidence :High)
woodstox-core-7.1.1.jar (shaded: com.sun.xml.bind.jaxb:isorelax:20090621)
Description:
Unknown version of isorelax library used in JAXB project
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/7.1.1/76baad1b94513ea896e0a17388890a4c81edd0e0/woodstox-core-7.1.1.jar/META-INF/maven/com.sun.xml.bind.jaxb/isorelax/pom.xml
MD5: 6fbb4bc95fbf2072bc6e3b790553fe81
SHA1: 314ec72948d5c1fc71d553cbbd7a130caa6f9f13
SHA256: cda6451d0231a973352b592ff950e39224ba6ba1a2f35eeab66511b5c225dff1
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid isorelax Low
Vendor pom groupid com.sun.xml.bind.jaxb Highest
Vendor pom name JAXB isorelax library High
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom parent-groupid net.java Medium
Product pom artifactid isorelax Highest
Product pom groupid com.sun.xml.bind.jaxb Highest
Product pom name JAXB isorelax library High
Product pom parent-artifactid jvnet-parent Medium
Product pom parent-groupid net.java Medium
Version pom parent-version 20090621 Low
Version pom version 20090621 Highest
pkg:maven/com.sun.xml.bind.jaxb/isorelax@20090621
(Confidence :High)
woodstox-core-7.1.1.jar (shaded: net.java.dev.msv:xsdlib:2022.7)
Description:
XML Schema datatypes library
License:
BSD
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/7.1.1/76baad1b94513ea896e0a17388890a4c81edd0e0/woodstox-core-7.1.1.jar/META-INF/maven/net.java.dev.msv/xsdlib/pom.xml
MD5: f82c4c4c46c8a27ee68f031373064bf9
SHA1: 1b9b8fe3901f3556ed99a477af66f0f645c16cf0
SHA256: 8649b880ac5dbb3549022c40eff4053930ea209c4aaf998925fb3d6dd75fb6c3
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid xsdlib Low
Vendor pom groupid net.java.dev.msv Highest
Vendor pom name MSV XML Schema Datatype Library High
Vendor pom parent-artifactid msv Low
Product pom artifactid xsdlib Highest
Product pom groupid net.java.dev.msv Highest
Product pom name MSV XML Schema Datatype Library High
Product pom parent-artifactid msv Medium
Version pom version 2022.7 Highest
pkg:maven/net.java.dev.msv/xsdlib@2022.7
(Confidence :High)
cpe:2.3:a:xml_library_project:xml_library:2022.7:*:*:*:*:*:*:*
(Confidence :Low)
suppress
woodstox-core-7.1.1.jar
Description:
Woodstox is a high-performance XML processor that implements Stax (JSR-173),
SAX2 and Stax2 APIs
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/7.1.1/76baad1b94513ea896e0a17388890a4c81edd0e0/woodstox-core-7.1.1.jar
MD5: 971ff236679f7b35a7c13c0d02c0170e
SHA1: 76baad1b94513ea896e0a17388890a4c81edd0e0
SHA256: 02b9d022e9d47704ff8a7a859a0dbfd3b2882a8311eb7ff1e180f760ccda2712
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
woodstox-core-7.1.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name woodstox-core High
Vendor gradle artifactid woodstox-core Highest
Vendor gradle groupid com.fasterxml.woodstox Highest
Vendor jar package name stax Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/woodstox Low
Vendor Manifest bundle-symbolicname com.fasterxml.woodstox.woodstox-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.woodstox Medium
Vendor Manifest provide-capability osgi.service;objectClass:List="javax.xml.stream.XMLEventFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLInputFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLOutputFactory";effective:=active,osgi.service;objectClass:List="org.codehaus.stax2.validation.XMLValidationSchemaFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLEventFactory";register:="com.ctc.wstx.stax.WstxEventFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLInputFactory";register:="com.ctc.wstx.stax.WstxInputFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLOutputFactory";register:="com.ctc.wstx.stax.WstxOutputFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.dtd.DTDSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.RelaxNGSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.W3CSchemaFactory" Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid woodstox-core Low
Vendor pom developer email tatu@fasterxml.com Low
Vendor pom developer id cowtowncoder Medium
Vendor pom developer name Tatu Saloranta Medium
Vendor pom groupid com.fasterxml.woodstox Highest
Vendor pom name Woodstox High
Vendor pom organization name FasterXML High
Vendor pom organization url http://fasterxml.com Medium
Vendor pom parent-artifactid oss-parent Low
Vendor pom parent-groupid com.fasterxml Medium
Vendor pom url FasterXML/woodstox Highest
Product file name woodstox-core High
Product gradle artifactid woodstox-core Highest
Product jar package name dtd Highest
Product jar package name dtdschemafactory Highest
Product jar package name msv Highest
Product jar package name osgi Highest
Product jar package name relaxngschemafactory Highest
Product jar package name stax Highest
Product jar package name w3cschemafactory Highest
Product jar package name wstx Highest
Product jar package name wstxeventfactory Highest
Product jar package name wstxinputfactory Highest
Product jar package name wstxoutputfactory Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/FasterXML/woodstox Low
Product Manifest Bundle-Name Woodstox Medium
Product Manifest bundle-symbolicname com.fasterxml.woodstox.woodstox-core Medium
Product Manifest Implementation-Title Woodstox High
Product Manifest provide-capability osgi.service;objectClass:List="javax.xml.stream.XMLEventFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLInputFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLOutputFactory";effective:=active,osgi.service;objectClass:List="org.codehaus.stax2.validation.XMLValidationSchemaFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLEventFactory";register:="com.ctc.wstx.stax.WstxEventFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLInputFactory";register:="com.ctc.wstx.stax.WstxInputFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLOutputFactory";register:="com.ctc.wstx.stax.WstxOutputFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.dtd.DTDSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.RelaxNGSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.W3CSchemaFactory" Low
Product Manifest specification-title Woodstox Medium
Product pom artifactid woodstox-core Highest
Product pom developer email tatu@fasterxml.com Low
Product pom developer id cowtowncoder Low
Product pom developer name Tatu Saloranta Low
Product pom groupid com.fasterxml.woodstox Highest
Product pom name Woodstox High
Product pom organization name FasterXML Low
Product pom organization url http://fasterxml.com Low
Product pom parent-artifactid oss-parent Medium
Product pom parent-groupid com.fasterxml Medium
Product pom url FasterXML/woodstox High
Version file version 7.1.1 High
Version gradle version 7.1.1 Highest
Version Manifest Bundle-Version 7.1.1 High
Version Manifest Implementation-Version 7.1.1 High
Version pom parent-version 7.1.1 Low
Version pom version 7.1.1 Highest
wsdl4j-1.6.3.jar
Description:
Java stub generator for WSDL
License:
CPL: http://www.opensource.org/licenses/cpl1.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/wsdl4j/wsdl4j/1.6.3/6d106a6845a3d3477a1560008479312888e94f2f/wsdl4j-1.6.3.jar
MD5: cfc28d89625c5e88589aec7a9aee0208
SHA1: 6d106a6845a3d3477a1560008479312888e94f2f
SHA256: 740f448e6b3bc110e02f4a1e56fb57672e732d2ecaf29ae15835051ae8af4725
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:webapps
server-start:runtimeClasspath
wsdl4j-1.6.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wsdl4j High
Vendor gradle artifactid wsdl4j Highest
Vendor gradle groupid wsdl4j Highest
Vendor jar package name extensions Low
Vendor jar package name ibm Highest
Vendor jar package name ibm Low
Vendor jar package name wsdl Low
Vendor Manifest Implementation-Vendor IBM High
Vendor Manifest specification-vendor IBM (Java Community Process) Low
Vendor pom artifactid wsdl4j Low
Vendor pom developer email wsdl4j-discuss@sourceforge.net Low
Vendor pom developer id wsdl4j Medium
Vendor pom developer name WSDL4J Medium
Vendor pom groupid wsdl4j Highest
Vendor pom name WSDL4J High
Vendor pom url http://sf.net/projects/wsdl4j Highest
Product file name wsdl4j High
Product gradle artifactid wsdl4j Highest
Product jar package name extensions Low
Product jar package name wsdl Low
Product Manifest Implementation-Title WSDL4J High
Product Manifest specification-title JWSDL Medium
Product pom artifactid wsdl4j Highest
Product pom developer email wsdl4j-discuss@sourceforge.net Low
Product pom developer id wsdl4j Low
Product pom developer name WSDL4J Low
Product pom groupid wsdl4j Highest
Product pom name WSDL4J High
Product pom url http://sf.net/projects/wsdl4j Medium
Version file version 1.6.3 High
Version gradle version 1.6.3 Highest
Version Manifest Implementation-Version 1.6.3 High
Version pom version 1.6.3 Highest
pkg:maven/wsdl4j/wsdl4j@1.6.3
(Confidence :High)
wss4j-bindings-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-bindings/4.0.0/3c5962bd8423c2ec4e0733e6cc714d9f8e36471/wss4j-bindings-4.0.0.jar
MD5: eebc66a992407cb8c6262a285f149ae9
SHA1: 03c5962bd8423c2ec4e0733e6cc714d9f8e36471
SHA256: 3a9bb7b5aa03b29cc794c45e211ab8458b368f7ca964fab813e1fec101c620f9
Referenced In Project/Scope: server-start:webapps
wss4j-bindings-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-bindings High
Vendor gradle artifactid wss4j-bindings Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor jar package name apache Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.bindings Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-bindings Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-bindings Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J WS-Security Bindings High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-bindings High
Product gradle artifactid wss4j-bindings Highest
Product jar package name apache Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.bindings Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J WS-Security Bindings Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-bindings Medium
Product Manifest Implementation-Title Apache WSS4J WS-Security Bindings High
Product Manifest specification-title Apache WSS4J WS-Security Bindings Medium
Product pom artifactid wss4j-bindings Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J WS-Security Bindings High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
wss4j-policy-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-policy/4.0.0/1917547139082f3541f1ab489e01e0b4f6f22848/wss4j-policy-4.0.0.jar
MD5: 7f1e7dda8be8cefd597602ac90dae686
SHA1: 1917547139082f3541f1ab489e01e0b4f6f22848
SHA256: 57c41cb631e5f759110ca0b723cafc1dd0355164b0dc1af930323bc3638ce500
Referenced In Project/Scope: server-start:webapps
wss4j-policy-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-policy High
Vendor gradle artifactid wss4j-policy Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor jar package name apache Highest
Vendor jar package name model Highest
Vendor jar package name policy Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.policy Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-policy Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-policy Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J WS-SecurityPolicy model High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-policy High
Product gradle artifactid wss4j-policy Highest
Product jar package name apache Highest
Product jar package name model Highest
Product jar package name policy Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.policy Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J WS-SecurityPolicy model Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-policy Medium
Product Manifest Implementation-Title Apache WSS4J WS-SecurityPolicy model High
Product Manifest specification-title Apache WSS4J WS-SecurityPolicy model Medium
Product pom artifactid wss4j-policy Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J WS-SecurityPolicy model High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
wss4j-ws-security-common-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-ws-security-common/4.0.0/efe08b8adf1e2bfa2da514e012017a10f85cb47f/wss4j-ws-security-common-4.0.0.jar
MD5: 2766c4057dc93a11806c0a6ce5543dca
SHA1: efe08b8adf1e2bfa2da514e012017a10f85cb47f
SHA256: bb1c0f112332f26add1abc1fb1bb4e368dd57fdd9132d2cfdcc2a5b151c11c2a
Referenced In Project/Scope: server-start:webapps
wss4j-ws-security-common-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-ws-security-common High
Vendor gradle artifactid wss4j-ws-security-common Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name common Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.common Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-common Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-ws-security-common Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J WS-Security Common High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-ws-security-common High
Product gradle artifactid wss4j-ws-security-common Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name common Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.common Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J WS-Security Common Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-common Medium
Product Manifest Implementation-Title Apache WSS4J WS-Security Common High
Product Manifest specification-title Apache WSS4J WS-Security Common Medium
Product pom artifactid wss4j-ws-security-common Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J WS-Security Common High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
wss4j-ws-security-dom-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-ws-security-dom/4.0.0/1e0d7e56b66080f9cfcdf104048d6b0dc423d12/wss4j-ws-security-dom-4.0.0.jar
MD5: d682afa0a0b6ad24424ba3ec7dcc0a59
SHA1: 01e0d7e56b66080f9cfcdf104048d6b0dc423d12
SHA256: f69b9c674eebb8d71bbd6bba2d70d144b4f91243789485bdfbf4ec5e20f9a8ca
Referenced In Project/Scope: server-start:webapps
wss4j-ws-security-dom-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-ws-security-dom High
Vendor gradle artifactid wss4j-ws-security-dom Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name dom Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.dom Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-dom Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-ws-security-dom Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J DOM WS-Security High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-ws-security-dom High
Product gradle artifactid wss4j-ws-security-dom Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name dom Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.dom Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J DOM WS-Security Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-dom Medium
Product Manifest Implementation-Title Apache WSS4J DOM WS-Security High
Product Manifest specification-title Apache WSS4J DOM WS-Security Medium
Product pom artifactid wss4j-ws-security-dom Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J DOM WS-Security High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
wss4j-ws-security-policy-stax-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-ws-security-policy-stax/4.0.0/51aa22853ebb6eb9b44a9ff894a2603643be389c/wss4j-ws-security-policy-stax-4.0.0.jar
MD5: def13f19cbcf66e91d7f6cf60d3b0889
SHA1: 51aa22853ebb6eb9b44a9ff894a2603643be389c
SHA256: fb4276d0979056eeb6cd3f0d19222db9bf0ac58691c74a3ff113d68c813df291
Referenced In Project/Scope: server-start:webapps
wss4j-ws-security-policy-stax-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-ws-security-policy-stax High
Vendor gradle artifactid wss4j-ws-security-policy-stax Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name policy Highest
Vendor jar package name stax Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.policystax Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-policy-stax Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-ws-security-policy-stax Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J Streaming WS-SecurityPolicy High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-ws-security-policy-stax High
Product gradle artifactid wss4j-ws-security-policy-stax Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name policy Highest
Product jar package name stax Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.policystax Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J Streaming WS-SecurityPolicy Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-policy-stax Medium
Product Manifest Implementation-Title Apache WSS4J Streaming WS-SecurityPolicy High
Product Manifest specification-title Apache WSS4J Streaming WS-SecurityPolicy Medium
Product pom artifactid wss4j-ws-security-policy-stax Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J Streaming WS-SecurityPolicy High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
wss4j-ws-security-stax-4.0.0.jar
Description:
Apache WSS4J parent pom
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.wss4j/wss4j-ws-security-stax/4.0.0/93f367e23737ee4d1e9cc767f6d20f140c4bc21e/wss4j-ws-security-stax-4.0.0.jar
MD5: 1f36b3b738ffd79ad6896d1917ccd997
SHA1: 93f367e23737ee4d1e9cc767f6d20f140c4bc21e
SHA256: fc0989821033a0088fd2e533d1805c8e991db906f9af51a025a8d55c7653e36b
Referenced In Project/Scope: server-start:webapps
wss4j-ws-security-stax-4.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name wss4j-ws-security-stax High
Vendor gradle artifactid wss4j-ws-security-stax Highest
Vendor gradle groupid org.apache.wss4j Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name stax Highest
Vendor jar package name wss4j Highest
Vendor Manifest automatic-module-name org.apache.wss4j.stax Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl http://ws.apache.org/wss4j Low
Vendor Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-stax Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid wss4j-ws-security-stax Low
Vendor pom groupid org.apache.wss4j Highest
Vendor pom name Apache WSS4J Streaming WS-Security High
Vendor pom parent-artifactid wss4j-parent Low
Product file name wss4j-ws-security-stax High
Product gradle artifactid wss4j-ws-security-stax Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name stax Highest
Product jar package name wss4j Highest
Product Manifest automatic-module-name org.apache.wss4j.stax Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl http://ws.apache.org/wss4j Low
Product Manifest Bundle-Name Apache WSS4J Streaming WS-Security Medium
Product Manifest bundle-symbolicname org.apache.wss4j.wss4j-ws-security-stax Medium
Product Manifest Implementation-Title Apache WSS4J Streaming WS-Security High
Product Manifest specification-title Apache WSS4J Streaming WS-Security Medium
Product pom artifactid wss4j-ws-security-stax Highest
Product pom groupid org.apache.wss4j Highest
Product pom name Apache WSS4J Streaming WS-Security High
Product pom parent-artifactid wss4j-parent Medium
Version file version 4.0.0 High
Version gradle version 4.0.0 Highest
Version Manifest Bundle-Version 4.0.0 High
Version Manifest Implementation-Version 4.0.0 High
Version pom version 4.0.0 Highest
xalan-2.7.3.jar (shaded: org.apache.bcel:bcel:6.7.0)
Description:
Apache Commons Bytecode Engineering Library
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xalan/xalan/2.7.3/5095bedf29e73756fb5729f2241fd5ffa33d87e0/xalan-2.7.3.jar/META-INF/maven/org.apache.bcel/bcel/pom.xml
MD5: d295c30370ff8cf96227ecff62fcb78d
SHA1: 38983d16d320ff710f8898e2dd342299d76939a7
SHA256: b0a59c14c26bdb4c7a5a2b13b8dcbd9acebf55e67fe91497140d8894de2fdeae
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Evidence
Type Source Name Value Confidence
Vendor pom artifactid bcel Low
Vendor pom developer email dbrosius at mebigfatguy.com Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email jason at zenplex.com Low
Vendor pom developer email m.dahm at gmx.de Low
Vendor pom developer email tcurdt at apache.org Low
Vendor pom developer id dbrosius Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id mdahm Medium
Vendor pom developer id tcurdt Medium
Vendor pom developer name Dave Brosius Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Jason van Zyl Medium
Vendor pom developer name Markus Dahm Medium
Vendor pom developer name Torsten Curdt Medium
Vendor pom developer org ASF Medium
Vendor pom developer org it-frameworksolutions Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL http://www.apache.org/ Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid org.apache.bcel Highest
Vendor pom name Apache Commons BCEL High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-bcel Highest
Product pom artifactid bcel Highest
Product pom developer email dbrosius at mebigfatguy.com Low
Product pom developer email ggregory at apache.org Low
Product pom developer email jason at zenplex.com Low
Product pom developer email m.dahm at gmx.de Low
Product pom developer email tcurdt at apache.org Low
Product pom developer id dbrosius Low
Product pom developer id ggregory Low
Product pom developer id mdahm Low
Product pom developer id tcurdt Low
Product pom developer name Dave Brosius Low
Product pom developer name Gary Gregory Low
Product pom developer name Jason van Zyl Low
Product pom developer name Markus Dahm Low
Product pom developer name Torsten Curdt Low
Product pom developer org ASF Low
Product pom developer org it-frameworksolutions Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL http://www.apache.org/ Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid org.apache.bcel Highest
Product pom name Apache Commons BCEL High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-bcel Medium
Version pom parent-version 6.7.0 Low
Version pom version 6.7.0 Highest
pkg:maven/org.apache.bcel/bcel@6.7.0
(Confidence :High)
cpe:2.3:a:apache:commons_bcel:6.7.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
xalan-2.7.3.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xalan/xalan/2.7.3/5095bedf29e73756fb5729f2241fd5ffa33d87e0/xalan-2.7.3.jar
MD5: e384223db0825925765f2bf66839d26d
SHA1: 5095bedf29e73756fb5729f2241fd5ffa33d87e0
SHA256: febd48bb133a96c447282213951a6b74ea7fb45c0d896121296c014316bda6b0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
xalan-2.7.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xalan High
Vendor gradle artifactid xalan Highest
Vendor gradle groupid xalan Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor manifest: java_cup/runtime/ Implementation-Vendor Princeton University Medium
Vendor manifest: org/apache/bcel/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/regexp/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xalan/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xalan/xsltc/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xml/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid xalan Low
Vendor pom groupid xalan Highest
Product file name xalan High
Product gradle artifactid xalan Highest
Product jar package name apache Highest
Product jar package name bcel Highest
Product jar package name expression Highest
Product jar package name regexp Highest
Product jar package name runtime Highest
Product jar package name xalan Highest
Product jar package name xml Highest
Product jar package name xpath Highest
Product jar package name xsltc Highest
Product manifest: java_cup/runtime/ Implementation-Title runtime Medium
Product manifest: java_cup/runtime/ Specification-Title Runtime component of JCup Medium
Product manifest: org/apache/bcel/ Implementation-Title org.apache.bcel Medium
Product manifest: org/apache/bcel/ Specification-Title Apache Commons BCEL Medium
Product manifest: org/apache/regexp/ Implementation-Title org.apache.regexp Medium
Product manifest: org/apache/regexp/ Specification-Title Java Regular Expression package Medium
Product manifest: org/apache/xalan/ Implementation-Title org.apache.xalan Medium
Product manifest: org/apache/xalan/ Specification-Title Java API for XML Processing Medium
Product manifest: org/apache/xalan/xsltc/ Implementation-Title org.apache.xalan.xsltc Medium
Product manifest: org/apache/xalan/xsltc/ Specification-Title Java API for XML Processing Medium
Product manifest: org/apache/xml/ Implementation-Title org.apache.xml Medium
Product manifest: org/apache/xpath/ Implementation-Title org.apache.xpath Medium
Product pom artifactid xalan Highest
Product pom groupid xalan Highest
Version file version 2.7.3 High
Version gradle version 2.7.3 Highest
Version manifest: java_cup/runtime/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/bcel/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/regexp/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/xalan/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/xalan/xsltc/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/xml/ Implementation-Version 2.7.3 Medium
Version manifest: org/apache/xpath/ Implementation-Version 2.7.3 Medium
Version pom version 2.7.3 Highest
xercesImpl-2.12.2.jar
Description:
Xerces2 provides high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces continues to build upon the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program.
The Apache Xerces2 parser is the reference implementation of XNI but other parser components, configurations, and parsers can be written using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.
Xerces2 provides fully conforming XML Schema 1.0 and 1.1 processors. An experimental implementation of the "XML Schema Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010)" is also provided for evaluation. For more information, refer to the XML Schema page.
Xerces2 also provides a complete implementation of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML Catalogs v1.1.
Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that it does not yet provide an option to enable normalization checking as described in section 2.13 of this specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xerces/xercesImpl/2.12.2/f051f988aa2c9b4d25d05f95742ab0cc3ed789e2/xercesImpl-2.12.2.jar
MD5: 40e4f2d5aacfbf51a9a1572d77a0e5e9
SHA1: f051f988aa2c9b4d25d05f95742ab0cc3ed789e2
SHA256: 6fc991829af1708d15aea50c66f0beadcd2cfeb6968e0b2f55c1b0909883fe16
Referenced In Project/Scope: server-start:runtimeClasspath
xercesImpl-2.12.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xercesImpl High
Vendor gradle artifactid xercesImpl Highest
Vendor gradle groupid xerces Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name xerces Low
Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xerces/impl/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium
Vendor pom artifactid xercesImpl Low
Vendor pom developer email j-dev@xerces.apache.org Low
Vendor pom developer id xerces Medium
Vendor pom developer name Apache Software Foundation Medium
Vendor pom developer org Apache Software Foundation Medium
Vendor pom developer org URL http://www.apache.org Medium
Vendor pom groupid xerces Highest
Vendor pom name Xerces2-j High
Vendor pom url https://xerces.apache.org/xerces2-j/ Highest
Product file name xercesImpl High
Product gradle artifactid xercesImpl Highest
Product hint analyzer product xerces-j Highest
Product jar package name apache Highest
Product jar package name datatype Highest
Product jar package name dom Highest
Product jar package name impl Highest
Product jar package name parsers Highest
Product jar package name validation Highest
Product jar package name version Highest
Product jar package name w3c Highest
Product jar package name xerces Highest
Product jar package name xerces Low
Product jar package name xml Highest
Product jar package name xni Highest
Product jar package name xpath Highest
Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium
Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium
Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium
Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium
Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML Medium
Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium
Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium
Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium
Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium
Product manifest: org/apache/xerces/impl/ Implementation-Title org.apache.xerces.impl.Version Medium
Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium
Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium
Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium
Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium
Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium
Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium
Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium
Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium
Product pom artifactid xercesImpl Highest
Product pom developer email j-dev@xerces.apache.org Low
Product pom developer id xerces Low
Product pom developer name Apache Software Foundation Low
Product pom developer org Apache Software Foundation Low
Product pom developer org URL http://www.apache.org Low
Product pom groupid xerces Highest
Product pom name Xerces2-j High
Product pom url https://xerces.apache.org/xerces2-j/ Medium
Version file version 2.12.2 High
Version gradle version 2.12.2 Highest
Version manifest: org/apache/xerces/impl/ Implementation-Version 2.12.2 Medium
Version pom version 2.12.2 Highest
pkg:maven/xerces/xercesImpl@2.12.2
(Confidence :High)
cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*
(Confidence :Low)
suppress
xmemcached-2.4.9.jar
Description:
Extreme performance modern memcached client for java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/com.googlecode.xmemcached/xmemcached/2.4.9/f59b0a35b9362a8ccaed6932080cd638e3a14b44/xmemcached-2.4.9.jar
MD5: 2909d08ce9bf912e23717c72db7445d1
SHA1: f59b0a35b9362a8ccaed6932080cd638e3a14b44
SHA256: e33eba7fbc892e01be81d19c1bf6a420ef42ad2ad89312c5b7b87ee48f6ef94c
Referenced In Project/Scope: server-start:runtimeClasspath
xmemcached-2.4.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xmemcached High
Vendor gradle artifactid xmemcached Highest
Vendor gradle groupid com.googlecode.xmemcached Highest
Vendor jar package name xmemcached Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor pom artifactid xmemcached Low
Vendor pom developer name dennis zhuang Medium
Vendor pom groupid com.googlecode.xmemcached Highest
Vendor pom name xmemcached High
Vendor pom url killme2008/xmemcached Highest
Product file name xmemcached High
Product gradle artifactid xmemcached Highest
Product jar package name xmemcached Highest
Product Manifest build-jdk-spec 1.8 Low
Product pom artifactid xmemcached Highest
Product pom developer name dennis zhuang Low
Product pom groupid com.googlecode.xmemcached Highest
Product pom name xmemcached High
Product pom url killme2008/xmemcached High
Version file version 2.4.9 High
Version gradle version 2.4.9 Highest
Version pom version 2.4.9 Highest
pkg:maven/com.googlecode.xmemcached/xmemcached@2.4.9
(Confidence :High)
xml-resolver-1.2.jar
Description:
xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xml-resolver/xml-resolver/1.2/3d0f97750b3a03e0971831566067754ba4bfd68c/xml-resolver-1.2.jar
MD5: 706c533146c1f4ee46b66659ea14583a
SHA1: 3d0f97750b3a03e0971831566067754ba4bfd68c
SHA256: 47dcde8986019314ef78ae7280a94973a21d2ed95075a40a000b42da956429e1
Referenced In Projects/Scopes:
server-start:webapps
server-start:runtimeClasspath
xml-resolver-1.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xml-resolver High
Vendor gradle artifactid xml-resolver Highest
Vendor gradle groupid xml-resolver Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name resolver Low
Vendor jar package name xml Low
Vendor manifest: org/apache/xml/resolver Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid xml-resolver Low
Vendor pom groupid xml-resolver Highest
Vendor pom name XML Commons Resolver Component High
Vendor pom parent-artifactid apache Low
Vendor pom parent-groupid org.apache Medium
Vendor pom url http://xml.apache.org/commons/components/resolver/ Highest
Product file name xml-resolver High
Product gradle artifactid xml-resolver Highest
Product jar package name apache Highest
Product jar package name catalog Highest
Product jar package name resolver Highest
Product jar package name resolver Low
Product jar package name xml Highest
Product jar package name xml Low
Product manifest: org/apache/xml/resolver Implementation-Title org.apache.xml.resolver.Catalog Medium
Product pom artifactid xml-resolver Highest
Product pom groupid xml-resolver Highest
Product pom name XML Commons Resolver Component High
Product pom parent-artifactid apache Medium
Product pom parent-groupid org.apache Medium
Product pom url http://xml.apache.org/commons/components/resolver/ Medium
Version file version 1.2 High
Version gradle version 1.2 Highest
Version manifest: org/apache/xml/resolver Implementation-Version 1.2 Medium
Version pom parent-version 1.2 Low
Version pom version 1.2 Highest
pkg:maven/xml-resolver/xml-resolver@1.2
(Confidence :High)
xmlbeans-3.1.0.jar
Description:
XmlBeans main jar
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.xmlbeans/xmlbeans/3.1.0/6dac1f897dfb3e3f17fc79b18a3353b2e51c464e/xmlbeans-3.1.0.jar
MD5: 408902d943e5bd51a4813dae131681a3
SHA1: 6dac1f897dfb3e3f17fc79b18a3353b2e51c464e
SHA256: a19ea1ec835a101165f7aa3c55427e81b5f2b187bfe7689a19277c51402620b0
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
xmlbeans-3.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xmlbeans High
Vendor gradle artifactid xmlbeans Highest
Vendor gradle groupid org.apache.xmlbeans Highest
Vendor jar package name apache Highest
Vendor jar package name apache Low
Vendor jar package name impl Low
Vendor jar package name xmlbeans Low
Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid xmlbeans Low
Vendor pom developer email cezar.andrei@no#spam#!gma|l.com Low
Vendor pom developer email jacob.danner@nos#pam.oracle.com Low
Vendor pom developer email radu.preotiuc-pietro@nos#pam.bea.com Low
Vendor pom developer email radupr@nos#pam.gm@il.com Low
Vendor pom developer email user@poi.apache.org Low
Vendor pom developer email wing-yew.poon@nos#pam.oracle.com Low
Vendor pom developer id cezar Medium
Vendor pom developer id jdanner Medium
Vendor pom developer id poi Medium
Vendor pom developer id radup Medium
Vendor pom developer id wpoon Medium
Vendor pom developer name Cezar Andrei Medium
Vendor pom developer name Jacob Danner Medium
Vendor pom developer name POI Team Medium
Vendor pom developer name Radu Preotiuc Medium
Vendor pom developer name Wing Yew Poon Medium
Vendor pom developer org Apache POI Medium
Vendor pom groupid org.apache.xmlbeans Highest
Vendor pom name XmlBeans High
Vendor pom organization name XmlBeans High
Vendor pom organization url https://xmlbeans.apache.org/ Medium
Vendor pom url https://xmlbeans.apache.org/ Highest
Product file name xmlbeans High
Product gradle artifactid xmlbeans Highest
Product jar package name apache Highest
Product jar package name impl Low
Product jar package name xmlbeans Highest
Product jar package name xmlbeans Low
Product manifest: org/apache/xmlbeans/ Implementation-Title org.apache.xmlbeans Medium
Product pom artifactid xmlbeans Highest
Product pom developer email cezar.andrei@no#spam#!gma|l.com Low
Product pom developer email jacob.danner@nos#pam.oracle.com Low
Product pom developer email radu.preotiuc-pietro@nos#pam.bea.com Low
Product pom developer email radupr@nos#pam.gm@il.com Low
Product pom developer email user@poi.apache.org Low
Product pom developer email wing-yew.poon@nos#pam.oracle.com Low
Product pom developer id cezar Low
Product pom developer id jdanner Low
Product pom developer id poi Low
Product pom developer id radup Low
Product pom developer id wpoon Low
Product pom developer name Cezar Andrei Low
Product pom developer name Jacob Danner Low
Product pom developer name POI Team Low
Product pom developer name Radu Preotiuc Low
Product pom developer name Wing Yew Poon Low
Product pom developer org Apache POI Low
Product pom groupid org.apache.xmlbeans Highest
Product pom name XmlBeans High
Product pom organization name XmlBeans Low
Product pom organization url https://xmlbeans.apache.org/ Low
Product pom url https://xmlbeans.apache.org/ Medium
Version file version 3.1.0 High
Version gradle version 3.1.0 Highest
Version manifest: org/apache/xmlbeans/ Implementation-Version 3.1.0 Medium
Version pom version 3.1.0 Highest
xmlschema-core-2.3.0.jar
Description:
Commons XMLSchema is a light weight schema object model that can be used to manipulate or
generate XML schema.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.xmlschema/xmlschema-core/2.3.0/5b99c4a647ee7155fcab0f7ec2a8737129281d68/xmlschema-core-2.3.0.jar
MD5: b8993a59697b293e5b1f123990df0020
SHA1: 5b99c4a647ee7155fcab0f7ec2a8737129281d68
SHA256: ab4ca02ae5634caf114161e40df94cb7e6bec2b33d372d46bd78189a4cb27dfa
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
xmlschema-core-2.3.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xmlschema-core High
Vendor gradle artifactid xmlschema-core Highest
Vendor gradle groupid org.apache.ws.xmlschema Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name ws Highest
Vendor Manifest bundle-docurl http://ws.apache.org/xmlschema/ Low
Vendor Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid xmlschema-core Low
Vendor pom groupid org.apache.ws.xmlschema Highest
Vendor pom name XmlSchema Core High
Vendor pom parent-artifactid xmlschema Low
Product file name xmlschema-core High
Product gradle artifactid xmlschema-core Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name ws Highest
Product Manifest bundle-docurl http://ws.apache.org/xmlschema/ Low
Product Manifest Bundle-Name XmlSchema Core Medium
Product Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium
Product pom artifactid xmlschema-core Highest
Product pom groupid org.apache.ws.xmlschema Highest
Product pom name XmlSchema Core High
Product pom parent-artifactid xmlschema Medium
Version file version 2.3.0 High
Version gradle version 2.3.0 Highest
Version Manifest Bundle-Version 2.3.0 High
Version pom version 2.3.0 Highest
pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.0
(Confidence :High)
xmlschema-core-2.3.1.jar
Description:
Commons XMLSchema is a light weight schema object model that can be used to manipulate or
generate XML schema.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.ws.xmlschema/xmlschema-core/2.3.1/5a83fc4e79d128f38c9e32138537060678151759/xmlschema-core-2.3.1.jar
MD5: 76e1deab5e6e1caa5fed31b3482cd266
SHA1: 5a83fc4e79d128f38c9e32138537060678151759
SHA256: 648f7f7e5228d89069cbc54c32404209f242581bc1c1e2e74229114f081071aa
Referenced In Project/Scope: server-start:webapps
xmlschema-core-2.3.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend.webservices/restapi@unspecified
pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xmlschema-core High
Vendor gradle artifactid xmlschema-core Highest
Vendor gradle groupid org.apache.ws.xmlschema Highest
Vendor hint analyzer vendor web services Medium
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name ws Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl http://ws.apache.org/xmlschema/ Low
Vendor Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid xmlschema-core Low
Vendor pom groupid org.apache.ws.xmlschema Highest
Vendor pom name XmlSchema Core High
Vendor pom parent-artifactid xmlschema Low
Product file name xmlschema-core High
Product gradle artifactid xmlschema-core Highest
Product hint analyzer product web services Medium
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name ws Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl http://ws.apache.org/xmlschema/ Low
Product Manifest Bundle-Name XmlSchema Core Medium
Product Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium
Product pom artifactid xmlschema-core Highest
Product pom groupid org.apache.ws.xmlschema Highest
Product pom name XmlSchema Core High
Product pom parent-artifactid xmlschema Medium
Version file version 2.3.1 High
Version gradle version 2.3.1 Highest
Version Manifest Bundle-Version 2.3.1 High
Version pom version 2.3.1 Highest
pkg:maven/org.apache.ws.xmlschema/xmlschema-core@2.3.1
(Confidence :High)
xmlsec-4.0.3.jar
Description:
Apache XML Security for Java supports XML-Signature Syntax and Processing,
W3C Recommendation 12 February 2002, and XML Encryption Syntax and
Processing, W3C Recommendation 10 December 2002. Since version 1.4,
the library supports the standard Java API JSR-105: XML Digital Signature APIs.
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.apache.santuario/xmlsec/4.0.3/34c05e3c1f13d9be69f54fafa0d31e116801c4b4/xmlsec-4.0.3.jar
MD5: 275e5f01c29d3f8987c36ff254929dd5
SHA1: 34c05e3c1f13d9be69f54fafa0d31e116801c4b4
SHA256: 7fe42f0b769a4e85cb6c7510f644107007453985d1f38d96390447948e71f1aa
Referenced In Project/Scope: server-start:webapps
xmlsec-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend.webservices/soapapi@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xmlsec High
Vendor gradle artifactid xmlsec Highest
Vendor gradle groupid org.apache.santuario Highest
Vendor jar package name apache Highest
Vendor jar package name encryption Highest
Vendor jar package name security Highest
Vendor jar package name signature Highest
Vendor jar package name xml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor Manifest bundle-symbolicname org.apache.santuario.xmlsec Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid xmlsec Low
Vendor pom groupid org.apache.santuario Highest
Vendor pom name Apache XML Security for Java High
Vendor pom organization name The Apache Software Foundation High
Vendor pom organization url https://www.apache.org/ Medium
Vendor pom parent-artifactid apache Low
Vendor pom parent-groupid org.apache Medium
Vendor pom url https://santuario.apache.org/ Highest
Product file name xmlsec High
Product gradle artifactid xmlsec Highest
Product jar package name apache Highest
Product jar package name encryption Highest
Product jar package name security Highest
Product jar package name signature Highest
Product jar package name xml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.apache.org/ Low
Product Manifest Bundle-Name Apache XML Security for Java Medium
Product Manifest bundle-symbolicname org.apache.santuario.xmlsec Medium
Product Manifest Implementation-Title Apache XML Security High
Product Manifest specification-title Apache XML Security Medium
Product pom artifactid xmlsec Highest
Product pom groupid org.apache.santuario Highest
Product pom name Apache XML Security for Java High
Product pom organization name The Apache Software Foundation Low
Product pom organization url https://www.apache.org/ Low
Product pom parent-artifactid apache Medium
Product pom parent-groupid org.apache Medium
Product pom url https://santuario.apache.org/ Medium
Version file version 4.0.3 High
Version gradle version 4.0.3 Highest
Version Manifest Bundle-Version 4.0.3 High
Version Manifest Implementation-Version 4.0.3 High
Version pom parent-version 4.0.3 Low
Version pom version 4.0.3 Highest
pkg:maven/org.apache.santuario/xmlsec@4.0.3
(Confidence :High)
cpe:2.3:a:apache:santuario_xml_security_for_java:4.0.3:*:*:*:*:*:*:*
(Confidence :Low)
suppress
cpe:2.3:a:apache:xml_security_for_java:4.0.3:*:*:*:*:*:*:*
(Confidence :Low)
suppress
xpp3-1.1.3.4.O.jar
Description:
MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs such as Hotspot in JDK 1.4+.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/xpp3/xpp3/1.1.3.4.O/1c165262edac1c1e4f0a67c1643c4b7476187034/xpp3-1.1.3.4.O.jar
MD5: 799105b1ea95641f626806717c1ef8a0
SHA1: 1c165262edac1c1e4f0a67c1643c4b7476187034
SHA256: ebcdef45cb16eeb113032b27c8537fd98d6f46b1071b6765febd596b8cac0f1a
Referenced In Project/Scope: server-start:runtimeClasspath
xpp3-1.1.3.4.O.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xpp3 High
Vendor gradle artifactid xpp3 Highest
Vendor gradle groupid xpp3 Highest
Vendor jar package name builder Low
Vendor jar package name v1 Low
Vendor jar package name xmlpull Low
Vendor pom artifactid xpp3 Low
Vendor pom groupid xpp3 Highest
Vendor pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Highest
Product file name xpp3 High
Product gradle artifactid xpp3 Highest
Product jar package name builder Low
Product jar package name v1 Low
Product pom artifactid xpp3 Highest
Product pom groupid xpp3 Highest
Product pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Medium
Version gradle version 1.1.3.4.O Highest
Version pom version 1.1.3.4.O Highest
pkg:maven/xpp3/xpp3@1.1.3.4.O
(Confidence :High)
xsom-2.3.6.jar
Description:
XML Schema Object Model (XSOM) is a Java library that allows applications to easily parse XML Schema
documents and inspect information in them. It is expected to be useful for applications that need to take XML
Schema as an input.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.glassfish.jaxb/xsom/2.3.6/ece5034aa8e11c16a1749deb5234e77be6f25ace/xsom-2.3.6.jar
MD5: de147221723225e46acca356cadc650e
SHA1: ece5034aa8e11c16a1749deb5234e77be6f25ace
SHA256: 227e7b49a1331847da6c61c8b14307acdd969b9f75842e4b4100b22bc15a4a69
Referenced In Project/Scope: server-start:runtimeClasspath
xsom-2.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name xsom High
Vendor gradle artifactid xsom Highest
Vendor gradle groupid org.glassfish.jaxb Highest
Vendor jar package name xml Highest
Vendor jar package name xsom Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname org.glassfish.jaxb.xsom Medium
Vendor Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor pom artifactid xsom Low
Vendor pom groupid org.glassfish.jaxb Highest
Vendor pom name XSOM High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest
Product file name xsom High
Product gradle artifactid xsom Highest
Product jar package name xml Highest
Product jar package name xsom Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name XSOM Medium
Product Manifest bundle-symbolicname org.glassfish.jaxb.xsom Medium
Product Manifest implementation-build-id 2.3.6 - e9f7f5f Low
Product Manifest Implementation-Title XSOM High
Product pom artifactid xsom Highest
Product pom groupid org.glassfish.jaxb Highest
Product pom name XSOM High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium
Version file version 2.3.6 High
Version gradle version 2.3.6 Highest
Version Manifest Bundle-Version 2.3.6 High
Version Manifest implementation-build-id 2.3.6 Low
Version Manifest Implementation-Version 2.3.6 High
Version pom parent-version 2.3.6 Low
Version pom version 2.3.6 Highest
pkg:maven/org.glassfish.jaxb/xsom@2.3.6
(Confidence :High)
zip4j-1.3.2.jar
Description:
An open source java library to handle zip files
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/net.lingala.zip4j/zip4j/1.3.2/4ba84e98ee017b74cb52f45962f929a221f3074c/zip4j-1.3.2.jar
MD5: 67577b0541256ea89d15e0edb6d2a7b8
SHA1: 4ba84e98ee017b74cb52f45962f929a221f3074c
SHA256: c67098d430c574311432728ebd4c7c45672f9ccf5c64702eb6afb8816c22ad08
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
zip4j-1.3.2.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name zip4j High
Vendor gradle artifactid zip4j Highest
Vendor gradle groupid net.lingala.zip4j Highest
Vendor jar package name lingala Highest
Vendor jar package name net Highest
Vendor jar package name zip4j Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Vendor Manifest bundle-symbolicname net.lingala.zip4j Medium
Vendor pom artifactid zip4j Low
Vendor pom developer email lsr_hyd@yahoo.com Low
Vendor pom developer id Srikanth Medium
Vendor pom developer name Srikanth Lingala Medium
Vendor pom groupid net.lingala.zip4j Highest
Vendor pom name zip4j High
Vendor pom url http://www.lingala.net/zip4j/ Highest
Product file name zip4j High
Product gradle artifactid zip4j Highest
Product jar package name lingala Highest
Product jar package name net Highest
Product jar package name zip4j Highest
Product Manifest Bundle-Name Zip4j Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Product Manifest bundle-symbolicname net.lingala.zip4j Medium
Product pom artifactid zip4j Highest
Product pom developer email lsr_hyd@yahoo.com Low
Product pom developer id Srikanth Low
Product pom developer name Srikanth Lingala Low
Product pom groupid net.lingala.zip4j Highest
Product pom name zip4j High
Product pom url http://www.lingala.net/zip4j/ Medium
Version file version 1.3.2 High
Version gradle version 1.3.2 Highest
Version Manifest Bundle-Version 1.3.2 High
Version pom version 1.3.2 Highest
CVE-2018-1002202 suppress
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: MEDIUM (6.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.8)
Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:P
References:
Vulnerable Software & Versions:
CVE-2023-22899 suppress
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
CWE-346 Origin Validation Error
CVSSv3:
Base Score: MEDIUM (5.9)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A
References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,TECHNICAL_DESCRIPTION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - EXPLOIT,TECHNICAL_DESCRIPTION,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
Vulnerable Software & Versions:
CVE-2022-24615 suppress
zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.
CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions:
Suppressed Vulnerabilities
keycloak-common-26.5.3.jar
Description:
Common library and dependencies shared with server and all adapters
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-common/26.5.3/ff3d6da60ef168aee18abcbcaeab21ca9cbc1799/keycloak-common-26.5.3.jar
MD5: d486873d9fc5eb70034b4e6739e66acd
SHA1: ff3d6da60ef168aee18abcbcaeab21ca9cbc1799
SHA256: 72c4da697c498cb576b7746b60a3ae23561a1713518582f6c82b368212208860
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-common-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-common High
Vendor gradle artifactid keycloak-common Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name common Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-common Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-common Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Common High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-common High
Product gradle artifactid keycloak-common Highest
Product jar package name common Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Common High
Product Manifest implementation-url http://keycloak.org/keycloak-common Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Common Medium
Product pom artifactid keycloak-common Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Common High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
keycloak-core-26.5.3.jar
Description:
Keycloak Core
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/org.keycloak/keycloak-core/26.5.3/7a7dabe1e2a3fbf4859bf8fd919aa334315668e9/keycloak-core-26.5.3.jar
MD5: f4bb445f9fa5e8f5c4a6112d19493209
SHA1: 7a7dabe1e2a3fbf4859bf8fd919aa334315668e9
SHA256: 72ad05ce844fe11c176ac2e844566e28f768a8ce55fcb835c9be3afbc8e565e4
Referenced In Project/Scope: server-start:runtimeClasspath
keycloak-core-26.5.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name keycloak-core High
Vendor gradle artifactid keycloak-core Highest
Vendor gradle groupid org.keycloak Highest
Vendor hint analyzer vendor redhat Highest
Vendor jar package name keycloak Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest implementation-url http://keycloak.org/keycloak-core Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-arch amd64 Low
Vendor Manifest os-name Linux Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid keycloak-core Low
Vendor pom groupid org.keycloak Highest
Vendor pom name Keycloak Core High
Vendor pom parent-artifactid keycloak-parent Low
Product file name keycloak-core High
Product gradle artifactid keycloak-core Highest
Product jar package name keycloak Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Keycloak Core High
Product Manifest implementation-url http://keycloak.org/keycloak-core Low
Product Manifest os-arch amd64 Low
Product Manifest os-name Linux Medium
Product Manifest specification-title Keycloak Core Medium
Product pom artifactid keycloak-core Highest
Product pom groupid org.keycloak Highest
Product pom name Keycloak Core High
Product pom parent-artifactid keycloak-parent Medium
Version file version 26.5.3 High
Version gradle version 26.5.3 Highest
Version Manifest Implementation-Version 26.5.3 High
Version pom version 26.5.3 Highest
netty-buffer-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-buffer/4.1.126.Final/6141cd8f9b7def2d29b2ae6b433a751d6f20120e/netty-buffer-4.1.126.Final.jar
MD5: 80f12bc73a4906611c7b202d93626ca7
SHA1: 6141cd8f9b7def2d29b2ae6b433a751d6f20120e
SHA256: d741726adcc76107553092d456d0da5837daad39919c8a40df15327d7fa3296d
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-buffer High
Vendor gradle artifactid netty-buffer Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name buffer Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.buffer Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.buffer Medium
Vendor Manifest implementation-url https://netty.io/netty-buffer/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-buffer Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Buffer High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-buffer High
Product gradle artifactid netty-buffer Highest
Product jar package name buffer Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.buffer Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Buffer Medium
Product Manifest bundle-symbolicname io.netty.buffer Medium
Product Manifest Implementation-Title Netty/Buffer High
Product Manifest implementation-url https://netty.io/netty-buffer/ Low
Product Manifest specification-title Netty/Buffer Medium
Product pom artifactid netty-buffer Highest
Product pom groupid io.netty Highest
Product pom name Netty/Buffer High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-codec-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec/4.1.126.Final/b265a097073120638ef468eda9e5a1e04a2e09e9/netty-codec-4.1.126.Final.jar
MD5: 971941ee869ae1b09410a48142244d12
SHA1: b265a097073120638ef468eda9e5a1e04a2e09e9
SHA256: 8ebb8284cc76b26025d892ff8bc1a90cc4ae7492dae0e3794068cd8ebc452600
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec High
Vendor gradle artifactid netty-codec Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec Medium
Vendor Manifest implementation-url https://netty.io/netty-codec/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec High
Product gradle artifactid netty-codec Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec Medium
Product Manifest bundle-symbolicname io.netty.codec Medium
Product Manifest Implementation-Title Netty/Codec High
Product Manifest implementation-url https://netty.io/netty-codec/ Low
Product Manifest specification-title Netty/Codec Medium
Product pom artifactid netty-codec Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-codec-http-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.126.Final/e8a7293c3f4891e7f6b0ede23bc808559dff0abd/netty-codec-http-4.1.126.Final.jar
MD5: 45cd0a79615257f803dc42e5a28d29f8
SHA1: e8a7293c3f4891e7f6b0ede23bc808559dff0abd
SHA256: 0a32369bbd7278f1066048fc0830f2a6df1f0f72de6ae7f5386976c4d2f6788f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http High
Vendor gradle artifactid netty-codec-http Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http High
Product gradle artifactid netty-codec-http Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP Medium
Product Manifest bundle-symbolicname io.netty.codec-http Medium
Product Manifest Implementation-Title Netty/Codec/HTTP High
Product Manifest implementation-url https://netty.io/netty-codec-http/ Low
Product Manifest specification-title Netty/Codec/HTTP Medium
Product pom artifactid netty-codec-http Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-codec-http2-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-http2/4.1.126.Final/652d70562d88d4de20071e3e2f4963e02e68c74/netty-codec-http2-4.1.126.Final.jar
MD5: 952f1e0a27f4b9383f30274bd55eec8e
SHA1: 0652d70562d88d4de20071e3e2f4963e02e68c74
SHA256: bb5eb960f552d9b90a98c8bc40e40b89316294c1dd1e67b2728ad047f2da3bbe
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http2 High
Vendor gradle artifactid netty-codec-http2 Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http2 Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http2 Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP2 High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http2 High
Product gradle artifactid netty-codec-http2 Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP2 Medium
Product Manifest bundle-symbolicname io.netty.codec-http2 Medium
Product Manifest Implementation-Title Netty/Codec/HTTP2 High
Product Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Product Manifest specification-title Netty/Codec/HTTP2 Medium
Product pom artifactid netty-codec-http2 Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP2 High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-codec-socks-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-codec-socks/4.1.126.Final/6b3eca94ad8b00917c52187a8c48e48657a4ad1e/netty-codec-socks-4.1.126.Final.jar
MD5: 1a28b97638dbd9d0fc80c147cc3c3876
SHA1: 6b3eca94ad8b00917c52187a8c48e48657a4ad1e
SHA256: 1f1d56665f4793dbbadab34c604597a680f60425de0027434f9499c183da9df5
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-socks High
Vendor gradle artifactid netty-codec-socks Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.socks Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-socks Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-socks Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/Socks High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-socks High
Product gradle artifactid netty-codec-socks Highest
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.socks Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/Socks Medium
Product Manifest bundle-symbolicname io.netty.codec-socks Medium
Product Manifest Implementation-Title Netty/Codec/Socks High
Product Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Product Manifest specification-title Netty/Codec/Socks Medium
Product pom artifactid netty-codec-socks Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/Socks High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-common-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-common/4.1.126.Final/e600bd7cef9b2b151606529166534b99220ea149/netty-common-4.1.126.Final.jar
MD5: 227bc8a7f0f4e99159e4c63eadbb637a
SHA1: e600bd7cef9b2b151606529166534b99220ea149
SHA256: ac2b777562723a94962ea30a30d968fa5678455141ede64100b9d0530426db9c
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-common High
Vendor gradle artifactid netty-common Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.common Medium
Vendor Manifest implementation-url https://netty.io/netty-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-common High
Product gradle artifactid netty-common Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Common Medium
Product Manifest bundle-symbolicname io.netty.common Medium
Product Manifest Implementation-Title Netty/Common High
Product Manifest implementation-url https://netty.io/netty-common/ Low
Product Manifest specification-title Netty/Common Medium
Product pom artifactid netty-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Common High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-handler-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-handler/4.1.126.Final/9bd071585b16a9aa28caec956fd77a4375ff3193/netty-handler-4.1.126.Final.jar
MD5: 61dccb38a3443847dcf9785067b67233
SHA1: 9bd071585b16a9aa28caec956fd77a4375ff3193
SHA256: 1846e8e770288aab3a203a16f78e2515ddba0bf9df1c26665ceffc38c9fc875b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler High
Vendor gradle artifactid netty-handler Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.handler Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler Medium
Vendor Manifest implementation-url https://netty.io/netty-handler/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler High
Product gradle artifactid netty-handler Highest
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.handler Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler Medium
Product Manifest bundle-symbolicname io.netty.handler Medium
Product Manifest Implementation-Title Netty/Handler High
Product Manifest implementation-url https://netty.io/netty-handler/ Low
Product Manifest specification-title Netty/Handler Medium
Product pom artifactid netty-handler Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-handler-proxy-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-handler-proxy/4.1.126.Final/567fbccddd46ce3793e1475bbaffc2038315bc35/netty-handler-proxy-4.1.126.Final.jar
MD5: f76c5d740a87169c8d93309f990f8d2f
SHA1: 567fbccddd46ce3793e1475bbaffc2038315bc35
SHA256: 7b715cbad91daf9cde48105e1ab5cc45e06b3b19523f536c2d27a3b908f6d41b
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler-proxy High
Vendor gradle artifactid netty-handler-proxy Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name proxy Highest
Vendor Manifest automatic-module-name io.netty.handler.proxy Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler-proxy Medium
Vendor Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler-proxy Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler/Proxy High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler-proxy High
Product gradle artifactid netty-handler-proxy Highest
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name proxy Highest
Product Manifest automatic-module-name io.netty.handler.proxy Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler/Proxy Medium
Product Manifest bundle-symbolicname io.netty.handler-proxy Medium
Product Manifest Implementation-Title Netty/Handler/Proxy High
Product Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Product Manifest specification-title Netty/Handler/Proxy Medium
Product pom artifactid netty-handler-proxy Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler/Proxy High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-resolver-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-resolver/4.1.126.Final/9e46079201a3f050670924d8b3326b3d4453763d/netty-resolver-4.1.126.Final.jar
MD5: 04867ccad29777970cd1b0d4cec07b98
SHA1: 9e46079201a3f050670924d8b3326b3d4453763d
SHA256: c66be4ca4e37c263af785253449024b7ef150093257490c208bdc1d774e2c6d7
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver High
Vendor gradle artifactid netty-resolver Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver High
Product gradle artifactid netty-resolver Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver Medium
Product Manifest bundle-symbolicname io.netty.resolver Medium
Product Manifest Implementation-Title Netty/Resolver High
Product Manifest implementation-url https://netty.io/netty-resolver/ Low
Product Manifest specification-title Netty/Resolver Medium
Product pom artifactid netty-resolver Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-transport-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport/4.1.126.Final/3078db67315cb25a87938da7e868b734413be15d/netty-transport-4.1.126.Final.jar
MD5: 9c3f4f52507b206c28e51e65bbcc6774
SHA1: 3078db67315cb25a87938da7e868b734413be15d
SHA256: 30065562b7708e88cdf7c3fd192be9083651be538676ba27c8631e255825f315
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport High
Vendor gradle artifactid netty-transport Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport Medium
Vendor Manifest implementation-url https://netty.io/netty-transport/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport High
Product gradle artifactid netty-transport Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport Medium
Product Manifest bundle-symbolicname io.netty.transport Medium
Product Manifest Implementation-Title Netty/Transport High
Product Manifest implementation-url https://netty.io/netty-transport/ Low
Product Manifest specification-title Netty/Transport Medium
Product pom artifactid netty-transport Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-transport-classes-epoll-4.1.126.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-classes-epoll/4.1.126.Final/c518513a1c7bdaf67462a1062b873a04fbf2b157/netty-transport-classes-epoll-4.1.126.Final.jar
MD5: 123d48e51696efa02bfdbd0c83c04ac9
SHA1: c518513a1c7bdaf67462a1062b873a04fbf2b157
SHA256: d7e0684969dad68e224e4fbf3e8e0de6b5191b25d820f8d6ae05201c70b33654
Referenced In Project/Scope: server-start:runtimeClasspath
netty-transport-classes-epoll-4.1.126.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-epoll High
Vendor gradle artifactid netty-transport-classes-epoll Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name epoll Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-epoll High
Product gradle artifactid netty-transport-classes-epoll Highest
Product jar package name epoll Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/Epoll Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Product Manifest Implementation-Title Netty/Transport/Classes/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Product Manifest specification-title Netty/Transport/Classes/Epoll Medium
Product pom artifactid netty-transport-classes-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/Epoll High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-native-epoll/4.1.126.Final/53309e2477909db42957fac5b103b86fc709789c/netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar
MD5: 90f058169bb47367be1268ec8d093acd
SHA1: 53309e2477909db42957fac5b103b86fc709789c
SHA256: 4ea5268f375d01f494dad06ba45f47953d5c4648a16f1b89c8a04358064d3690
Referenced In Project/Scope: server-start:runtimeClasspath
netty-transport-native-epoll-4.1.126.Final-linux-x86_64.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-epoll High
Vendor gradle artifactid netty-transport-native-epoll Highest
Vendor gradle groupid io.netty Highest
Vendor Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-epoll Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-epoll High
Product gradle artifactid netty-transport-native-epoll Highest
Product Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Epoll Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Product Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-epoll Low
Product Manifest Implementation-Title Netty/Transport/Native/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/Epoll Medium
Product pom artifactid netty-transport-native-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Epoll High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
netty-transport-native-unix-common-4.1.126.Final.jar
Description:
Static library which contains common unix utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.netty/netty-transport-native-unix-common/4.1.126.Final/fd579d0e8f9f6509d201920a35f51aa49e638f5e/netty-transport-native-unix-common-4.1.126.Final.jar
MD5: 090afea4551d0c22d4b538723133c97a
SHA1: fd579d0e8f9f6509d201920a35f51aa49e638f5e
SHA256: b6578df0ad9092f4e846d34976a5f887b067ebaa71307eb90653d3a1898c1f5f
Referenced In Projects/Scopes:
server-start:compileClasspath
server-start:runtimeClasspath
Included by:
pkg:maven/TRANSCONNECT.backend/server@unspecified
pkg:maven/TRANSCONNECT.backend/server@unspecified
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-unix-common High
Vendor gradle artifactid netty-transport-native-unix-common Highest
Vendor gradle groupid io.netty Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name unix Highest
Vendor Manifest automatic-module-name io.netty.transport.unix.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-unix-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Unix/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-unix-common High
Product gradle artifactid netty-transport-native-unix-common Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name unix Highest
Product Manifest automatic-module-name io.netty.transport.unix.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Unix/Common Medium
Product Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Product Manifest Implementation-Title Netty/Transport/Native/Unix/Common High
Product Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Product Manifest specification-title Netty/Transport/Native/Unix/Common Medium
Product pom artifactid netty-transport-native-unix-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Unix/Common High
Product pom parent-artifactid netty-parent Medium
Version gradle version 4.1.126.Final Highest
Version Manifest Bundle-Version 4.1.126.Final High
Version Manifest Implementation-Version 4.1.126.Final High
Version pom version 4.1.126.Final Highest
cpe:2.3:a:netty:netty:4.1.126:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: azure-identity-1.18.1.jar
Description:
This module contains client library for Microsoft Azure Identity.
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/azure-identity-1.18.1.jar
MD5: e97bf19449e6bd37e4ebbf6e5bf03c37
SHA1: 38a431597ec940dd77f425443135deb6991b640d
SHA256: 8f4b36c6bf7472220d6b052364bd0cad441f2d9328a119ecdcf423a4ab4331c1
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name azure-identity High
Vendor jar package name azure Highest
Vendor jar package name identity Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest Implementation-Vendor Microsoft Corporation High
Vendor pom artifactid azure-identity Low
Vendor pom groupid com.azure Highest
Vendor pom name Microsoft Azure client library for Identity High
Vendor pom parent-artifactid azure-client-sdk-parent Low
Vendor pom url Azure/azure-sdk-for-java Highest
Product file name azure-identity High
Product jar package name azure Highest
Product jar package name identity Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest Implementation-Title Microsoft Azure client library for Identity High
Product pom artifactid azure-identity Highest
Product pom groupid com.azure Highest
Product pom name Microsoft Azure client library for Identity High
Product pom parent-artifactid azure-client-sdk-parent Medium
Product pom url Azure/azure-sdk-for-java High
Version file version 1.18.1 High
Version Manifest Implementation-Version 1.18.1 High
Version pom parent-version 1.18.1 Low
Version pom version 1.18.1 Highest
cpe:2.3:a:microsoft:azure_identity_sdk:1.18.1:*:*:*:*:*:*:* suppressed
(Confidence :Low)
Notes: false positive, it probably matches against the Javascript vector that is affected up to version 3.3.1
However, we are not using this component.
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: azure-identity-1.18.1.jar
CVE-2023-36415 suppressed
Azure Identity SDK Remote Code Execution Vulnerability
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection'), NVD-CWE-noinfo
CVSSv3:
HIGH (8.8)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2024-35255 suppressed
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-buffer-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-buffer-4.1.127.Final.jar
MD5: 4b5c9cc04745c23c4238a3a7a05f9272
SHA1: 356b4f2e759d36fec774cd17e583a7609d8ec15d
SHA256: 4a0a17dc5a58d910c56545be6912b9923cfe902522dc1df268e774bc22443eb6
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-buffer High
Vendor jar package name buffer Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.buffer Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.buffer Medium
Vendor Manifest implementation-url https://netty.io/netty-buffer/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-buffer Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Buffer High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-buffer High
Product jar package name buffer Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.buffer Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Buffer Medium
Product Manifest bundle-symbolicname io.netty.buffer Medium
Product Manifest Implementation-Title Netty/Buffer High
Product Manifest implementation-url https://netty.io/netty-buffer/ Low
Product Manifest specification-title Netty/Buffer Medium
Product pom artifactid netty-buffer Highest
Product pom groupid io.netty Highest
Product pom name Netty/Buffer High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-codec-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-4.1.127.Final.jar
MD5: 29493708bfdee16a32c4d5a26a7a88af
SHA1: b05d16b459b6c6042197a1f3aef671cf535767c3
SHA256: 187d21cee1a114f43b87be235f66c83828bdd0a3e0c1cdfebedaa37748e6e470
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec Medium
Vendor Manifest implementation-url https://netty.io/netty-codec/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec Medium
Product Manifest bundle-symbolicname io.netty.codec Medium
Product Manifest Implementation-Title Netty/Codec High
Product Manifest implementation-url https://netty.io/netty-codec/ Low
Product Manifest specification-title Netty/Codec Medium
Product pom artifactid netty-codec Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-codec-dns-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-dns-4.1.127.Final.jar
MD5: 1184c9fd3cb612a5d579f7f1270bb157
SHA1: bcb5a439fc94dacaf98bac2426e40f21376a8e1a
SHA256: 4398b97193aad6bf2a9a90ad86a83b892b62589a4a2c90d0d0a3d94a71b47976
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-dns High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.dns Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-dns Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-dns/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-dns Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/DNS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-dns High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.dns Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/DNS Medium
Product Manifest bundle-symbolicname io.netty.codec-dns Medium
Product Manifest Implementation-Title Netty/Codec/DNS High
Product Manifest implementation-url https://netty.io/netty-codec-dns/ Low
Product Manifest specification-title Netty/Codec/DNS Medium
Product pom artifactid netty-codec-dns Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/DNS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-codec-http-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-http-4.1.127.Final.jar
MD5: 309fabe1546e66ff9842dd4ae569902f
SHA1: c4c3fa12be76064a7a96631959641bcd600e6556
SHA256: 2408776c87c1808b5522298c25e8290427123763f4addfda02dff6a24a538f61
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP Medium
Product Manifest bundle-symbolicname io.netty.codec-http Medium
Product Manifest Implementation-Title Netty/Codec/HTTP High
Product Manifest implementation-url https://netty.io/netty-codec-http/ Low
Product Manifest specification-title Netty/Codec/HTTP Medium
Product pom artifactid netty-codec-http Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-codec-http2-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-http2-4.1.127.Final.jar
MD5: a134e194077ed67bfc94ad24cadf8c7e
SHA1: 39cf7a8790047fecda2c1fe87ee54d2f32aefb45
SHA256: 0eb1befa55f785b47729d58d4fce72abea73b7f48fc1c434d71953e6a558ffaa
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-http2 High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.http2 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-http2 Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-http2 Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/HTTP2 High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-http2 High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.http2 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/HTTP2 Medium
Product Manifest bundle-symbolicname io.netty.codec-http2 Medium
Product Manifest Implementation-Title Netty/Codec/HTTP2 High
Product Manifest implementation-url https://netty.io/netty-codec-http2/ Low
Product Manifest specification-title Netty/Codec/HTTP2 Medium
Product pom artifactid netty-codec-http2 Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/HTTP2 High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-codec-socks-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-codec-socks-4.1.127.Final.jar
MD5: bc40c14c9acde31c0cb32a49a97d071f
SHA1: c664f38b0f004e6b4ecf64f826939e24a56cbe9c
SHA256: d3d251f9239951a845f22e39191f95471fb2eb7951b9878ea4555ccac99529fb
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-codec-socks High
Vendor jar package name codec Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.codec.socks Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.codec-socks Medium
Vendor Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-codec-socks Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Codec/Socks High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-codec-socks High
Product jar package name codec Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.codec.socks Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Codec/Socks Medium
Product Manifest bundle-symbolicname io.netty.codec-socks Medium
Product Manifest Implementation-Title Netty/Codec/Socks High
Product Manifest implementation-url https://netty.io/netty-codec-socks/ Low
Product Manifest specification-title Netty/Codec/Socks Medium
Product pom artifactid netty-codec-socks Highest
Product pom groupid io.netty Highest
Product pom name Netty/Codec/Socks High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-common-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-common-4.1.127.Final.jar
MD5: 2a00ede31389e68fa4bb5cb7ff0c6f13
SHA1: ada4ab671678f956e1cd5067ba94bc340af1d8bf
SHA256: a6732bb70dc15ed96aa33ecca82c0d7b20f8ff41adf04f74f168f626adf359e8
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-common High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.common Medium
Vendor Manifest implementation-url https://netty.io/netty-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-common High
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Common Medium
Product Manifest bundle-symbolicname io.netty.common Medium
Product Manifest Implementation-Title Netty/Common High
Product Manifest implementation-url https://netty.io/netty-common/ Low
Product Manifest specification-title Netty/Common Medium
Product pom artifactid netty-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Common High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-handler-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-handler-4.1.127.Final.jar
MD5: 34add5070e2132ea2238d27aca710dc7
SHA1: 5e9ee8931666a12b52340309f92d51d0b49611de
SHA256: 88b6892bc1321d32409392e5b9f94e59d8e800678c029c71e7c0d76daf6050d0
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler High
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.handler Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler Medium
Vendor Manifest implementation-url https://netty.io/netty-handler/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler High
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.handler Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler Medium
Product Manifest bundle-symbolicname io.netty.handler Medium
Product Manifest Implementation-Title Netty/Handler High
Product Manifest implementation-url https://netty.io/netty-handler/ Low
Product Manifest specification-title Netty/Handler Medium
Product pom artifactid netty-handler Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-handler-proxy-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-handler-proxy-4.1.127.Final.jar
MD5: 9334275c874e64d715ce7e9deb891b5d
SHA1: 85cfd39769b7f12ae56b7e46ed506a9ac0daeef4
SHA256: 2c0c8046e5d737e08f40a7c2907526648860d0434e125bd51de3c2cf390453fb
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-handler-proxy High
Vendor jar package name handler Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name proxy Highest
Vendor Manifest automatic-module-name io.netty.handler.proxy Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.handler-proxy Medium
Vendor Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-handler-proxy Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Handler/Proxy High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-handler-proxy High
Product jar package name handler Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name proxy Highest
Product Manifest automatic-module-name io.netty.handler.proxy Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Handler/Proxy Medium
Product Manifest bundle-symbolicname io.netty.handler-proxy Medium
Product Manifest Implementation-Title Netty/Handler/Proxy High
Product Manifest implementation-url https://netty.io/netty-handler-proxy/ Low
Product Manifest specification-title Netty/Handler/Proxy Medium
Product pom artifactid netty-handler-proxy Highest
Product pom groupid io.netty Highest
Product pom name Netty/Handler/Proxy High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-resolver-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-4.1.127.Final.jar
MD5: 6b5b753699903056c1ebb650b4fb7e24
SHA1: 2b34a14b6ec23761d6d2300a1c261914401f2553
SHA256: a57ee62deb54ed99690db2696039f0f768a65c974677946ed48b2a2d8510ded3
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver High
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver Medium
Product Manifest bundle-symbolicname io.netty.resolver Medium
Product Manifest Implementation-Title Netty/Resolver High
Product Manifest implementation-url https://netty.io/netty-resolver/ Low
Product Manifest specification-title Netty/Resolver Medium
Product pom artifactid netty-resolver Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-4.1.127.Final.jar
MD5: e90fc410d21b69b25d1417deddec7359
SHA1: 568ff6c6a899ffc64d4a7a461059291dcc502062
SHA256: a9b619a902ede5ced0579082734011111d099a52f512d03a17f9a7d79afa3c69
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns High
Vendor jar package name dns Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver.dns Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns High
Product jar package name dns Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver.dns Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS Medium
Product Manifest bundle-symbolicname io.netty.resolver-dns Medium
Product Manifest Implementation-Title Netty/Resolver/DNS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns/ Low
Product Manifest specification-title Netty/Resolver/DNS Medium
Product pom artifactid netty-resolver-dns Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-classes-macos-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-classes-macos-4.1.127.Final.jar
MD5: 900628972c3c9cd7c2a003e8dac00887
SHA1: 21c93bc3a412afeac8deb10874d6dc7cfb961ea0
SHA256: 2ac04be6bee607331e0f09a57c9f724ae0947a39702d98b23ec1b6a74dd82076
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns-classes-macos High
Vendor jar package name dns Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name resolver Highest
Vendor Manifest automatic-module-name io.netty.resolver.dns.classes.macos Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns-classes-macos Medium
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns-classes-macos/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns-classes-macos Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS/Classes/MacOS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns-classes-macos High
Product jar package name dns Highest
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name resolver Highest
Product Manifest automatic-module-name io.netty.resolver.dns.classes.macos Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS/Classes/MacOS Medium
Product Manifest bundle-symbolicname io.netty.resolver-dns-classes-macos Medium
Product Manifest Implementation-Title Netty/Resolver/DNS/Classes/MacOS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns-classes-macos/ Low
Product Manifest specification-title Netty/Resolver/DNS/Classes/MacOS Medium
Product pom artifactid netty-resolver-dns-classes-macos Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS/Classes/MacOS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-resolver-dns-native-macos-4.1.127.Final-osx-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-resolver-dns-native-macos-4.1.127.Final-osx-x86_64.jar
MD5: 5b0d0e5bad46b47cd3a5e5a2740b2111
SHA1: 310929708225c05f4dd99015523eccabf1493bc2
SHA256: 85956fdc92618f3880c612f0943d4e91c9dcd543f4c58fa055d04dfa64bf8f66
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-resolver-dns-native-macos High
Vendor Manifest automatic-module-name io.netty.resolver.dns.macos.osx.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_resolver_dns_native_macos_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Vendor Manifest bundle-symbolicname io.netty.resolver-dns-native-macos.osx-x86_64 Medium
Vendor Manifest fragment-host io.netty.resolver-dns-classes-macos Low
Vendor Manifest implementation-url https://netty.io/netty-resolver-dns-native-macos/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-resolver-dns-native-macos Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Resolver/DNS/Native/MacOS High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-resolver-dns-native-macos High
Product Manifest automatic-module-name io.netty.resolver.dns.macos.osx.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Resolver/DNS/Native/MacOS Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_resolver_dns_native_macos_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Product Manifest bundle-symbolicname io.netty.resolver-dns-native-macos.osx-x86_64 Medium
Product Manifest fragment-host io.netty.resolver-dns-classes-macos Low
Product Manifest Implementation-Title Netty/Resolver/DNS/Native/MacOS High
Product Manifest implementation-url https://netty.io/netty-resolver-dns-native-macos/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Resolver/DNS/Native/MacOS Medium
Product pom artifactid netty-resolver-dns-native-macos Highest
Product pom groupid io.netty Highest
Product pom name Netty/Resolver/DNS/Native/MacOS High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-4.1.127.Final.jar
MD5: c3034b7b846baad3128f2d588532ecd9
SHA1: 9925d9d6be72436b661ba6a71cc8d2897fe83cf0
SHA256: 0d1ad82bc658f9919ca750cebe2571d4b0ae4514ec781964091f405343760e92
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport Medium
Vendor Manifest implementation-url https://netty.io/netty-transport/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport High
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport Medium
Product Manifest bundle-symbolicname io.netty.transport Medium
Product Manifest Implementation-Title Netty/Transport High
Product Manifest implementation-url https://netty.io/netty-transport/ Low
Product Manifest specification-title Netty/Transport Medium
Product pom artifactid netty-transport Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-classes-epoll-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-classes-epoll-4.1.127.Final.jar
MD5: 6570ebf4f6207c854b3fabde2c5d0943
SHA1: 03e1f9af9f34817b9cf613eedbaf87dfcdd3ccd9
SHA256: a39452eb911cb60068da6cdfd00e513b0a06e195b064fc44bd6fbfbc43c9527e
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-epoll High
Vendor jar package name epoll Highest
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-epoll High
Product jar package name epoll Highest
Product jar package name io Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.epoll Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/Epoll Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-epoll Medium
Product Manifest Implementation-Title Netty/Transport/Classes/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-classes-epoll/ Low
Product Manifest specification-title Netty/Transport/Classes/Epoll Medium
Product pom artifactid netty-transport-classes-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/Epoll High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-classes-kqueue-4.1.127.Final.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-classes-kqueue-4.1.127.Final.jar
MD5: f36ce4994ddd2880d73efaf9928421d6
SHA1: 6a3d4ccfa70e58130d626ef7f5a3f95b5d1903b3
SHA256: 9428ce83fb5c6b482bfe2d8ce244a5d2370674aff6e7ff30ee89ce0d962964db
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-classes-kqueue High
Vendor jar package name io Highest
Vendor jar package name kqueue Highest
Vendor jar package name netty Highest
Vendor Manifest automatic-module-name io.netty.transport.classes.kqueue Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-classes-kqueue Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-classes-kqueue/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-classes-kqueue Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Classes/KQueue High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-classes-kqueue High
Product jar package name io Highest
Product jar package name kqueue Highest
Product jar package name netty Highest
Product Manifest automatic-module-name io.netty.transport.classes.kqueue Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Classes/KQueue Medium
Product Manifest bundle-symbolicname io.netty.transport-classes-kqueue Medium
Product Manifest Implementation-Title Netty/Transport/Classes/KQueue High
Product Manifest implementation-url https://netty.io/netty-transport-classes-kqueue/ Low
Product Manifest specification-title Netty/Transport/Classes/KQueue Medium
Product pom artifactid netty-transport-classes-kqueue Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Classes/KQueue High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-native-epoll-4.1.127.Final-linux-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-epoll-4.1.127.Final-linux-x86_64.jar
MD5: 59fc2eed3eb5b82ebb663e5f4d6e2270
SHA1: 9a4657cd5fa3b7ac19698727b0891353c3ea1ce3
SHA256: 3d03f27eea1cd23357a56a96e1eeedfeb3d74fa0ba4d5c36a862bd035056275b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-epoll High
Vendor Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-epoll Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-epoll Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Epoll High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-epoll High
Product Manifest automatic-module-name io.netty.transport.epoll.linux.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Epoll Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_epoll_x86_64.so; osname=Linux; processor=x86_64,* Low
Product Manifest bundle-symbolicname io.netty.transport-native-epoll.linux-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-epoll Low
Product Manifest Implementation-Title Netty/Transport/Native/Epoll High
Product Manifest implementation-url https://netty.io/netty-transport-native-epoll/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/Epoll Medium
Product pom artifactid netty-transport-native-epoll Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Epoll High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-native-kqueue-4.1.127.Final-osx-x86_64.jar
Description:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-kqueue-4.1.127.Final-osx-x86_64.jar
MD5: cad5b26cde5b0d3d6801c43076ebc3d8
SHA1: 17031c708423849f8563b2f0705c17aa562e1c14
SHA256: d7d806a9f245492ec5898440478e1795a9ec95389a6de9aae53f13aae3276b71
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-kqueue High
Vendor Manifest automatic-module-name io.netty.transport.kqueue.osx.x86_64 Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-nativecode META-INF/native/libnetty_transport_native_kqueue_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-kqueue.osx-x86_64 Medium
Vendor Manifest fragment-host io.netty.transport-classes-kqueue Low
Vendor Manifest implementation-url https://netty.io/netty-transport-native-kqueue/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-kqueue Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/KQueue High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-kqueue High
Product Manifest automatic-module-name io.netty.transport.kqueue.osx.x86_64 Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/KQueue Medium
Product Manifest bundle-nativecode META-INF/native/libnetty_transport_native_kqueue_x86_64.jnilib; osname=MacOSX; processor=x86_64 Low
Product Manifest bundle-symbolicname io.netty.transport-native-kqueue.osx-x86_64 Medium
Product Manifest fragment-host io.netty.transport-classes-kqueue Low
Product Manifest Implementation-Title Netty/Transport/Native/KQueue High
Product Manifest implementation-url https://netty.io/netty-transport-native-kqueue/ Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.8 Low
Product Manifest specification-title Netty/Transport/Native/KQueue Medium
Product pom artifactid netty-transport-native-kqueue Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/KQueue High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: netty-transport-native-unix-common-4.1.127.Final.jar
Description:
Static library which contains common unix utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/netty-transport-native-unix-common-4.1.127.Final.jar
MD5: 9b41d899ea5338fd618fead158d243df
SHA1: 9cc0512d2ddfe9ae76c6db796e1980a8bdbadae1
SHA256: 0e3a45e3ce1fe034ca8b32c1579afa5f06729ca6427b7b0610528c4ef37c6e50
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name netty-transport-native-unix-common High
Vendor jar package name io Highest
Vendor jar package name netty Highest
Vendor jar package name unix Highest
Vendor Manifest automatic-module-name io.netty.transport.unix.common Medium
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://netty.io/ Low
Vendor Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Vendor Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Vendor Manifest Implementation-Vendor The Netty Project High
Vendor Manifest Implementation-Vendor-Id io.netty Medium
Vendor Manifest specification-vendor The Netty Project Low
Vendor pom artifactid netty-transport-native-unix-common Low
Vendor pom groupid io.netty Highest
Vendor pom name Netty/Transport/Native/Unix/Common High
Vendor pom parent-artifactid netty-parent Low
Product file name netty-transport-native-unix-common High
Product jar package name io Highest
Product jar package name netty Highest
Product jar package name unix Highest
Product Manifest automatic-module-name io.netty.transport.unix.common Medium
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://netty.io/ Low
Product Manifest Bundle-Name Netty/Transport/Native/Unix/Common Medium
Product Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium
Product Manifest Implementation-Title Netty/Transport/Native/Unix/Common High
Product Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low
Product Manifest specification-title Netty/Transport/Native/Unix/Common Medium
Product pom artifactid netty-transport-native-unix-common Highest
Product pom groupid io.netty Highest
Product pom name Netty/Transport/Native/Unix/Common High
Product pom parent-artifactid netty-parent Medium
Version Manifest Bundle-Version 4.1.127.Final High
Version Manifest Implementation-Version 4.1.127.Final High
Version pom version 4.1.127.Final Highest
cpe:2.3:a:netty:netty:4.1.127:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: reactor-netty-core-1.2.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactor-netty-core-1.2.10.jar
MD5: d2a12596a679d8a996a5824a385e7e61
SHA1: a2c808ca5468f4b48f6baa1b2d6bc1f6b3637074
SHA256: f0e6cf567110cfe6da55abfcf5f41a7b98a82f20e531bf4519565c4163f9793b
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-netty-core High
Vendor jar package name netty Highest
Vendor jar package name netty Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.netty.core Medium
Vendor Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-core Medium
Vendor Manifest multi-release true Low
Product file name reactor-netty-core High
Product jar package name netty Highest
Product jar package name netty Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.netty.core Medium
Product Manifest Bundle-Name reactor-netty-core Medium
Product Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-core Medium
Product Manifest Implementation-Title reactor-netty-core High
Product Manifest multi-release true Low
Version file version 1.2.10 High
Version Manifest Implementation-Version 1.2.10 High
cpe:2.3:a:netty:netty:1.2.10:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2019-20444 suppressed
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (6.4)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r059b042bca47be53ff8a51fd04d95eb01bb683f1afa209db136e8cb7%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e%40%3Ccommits.camel.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0f5e72d5f69b4720dfe64fcbc2da9afae949ed1e9cbffa84bb7d92d7%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34912a9b1a5c269a77b8be94ef6fb6d1e9b3c69129719dc00f01cf0b%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r489886fe72a98768eed665474cba13bad8d6fe0654f24987706636c5%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4c675b2d0cc2a5e506b11ee10d60a378859ee340aca052e4c7ef4749%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r91e0fa345c86c128b75a4a791b4b503b53173ff4c13049ac7129d319%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-20444/5.0.0.Alpha1/exploit
cve@mitre.org - https://lists.apache.org/thread.html/r059b042bca47be53ff8a51fd04d95eb01bb683f1afa209db136e8cb7@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e@%3Ccommits.camel.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0f5e72d5f69b4720dfe64fcbc2da9afae949ed1e9cbffa84bb7d92d7@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d@%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r34912a9b1a5c269a77b8be94ef6fb6d1e9b3c69129719dc00f01cf0b@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r489886fe72a98768eed665474cba13bad8d6fe0654f24987706636c5@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4c675b2d0cc2a5e506b11ee10d60a378859ee340aca052e4c7ef4749@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r91e0fa345c86c128b75a4a791b4b503b53173ff4c13049ac7129d319@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f@%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f@%3Cdev.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2019-20445 suppressed
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (6.4)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r030beff88aeb6d7a2d6cd21342bd18686153ce6e26a4171d0e035663%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r46f93de62b1e199f3f9babb18128681677c53493546f532ed88c359d%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4ff40646e9ccce13560458419accdfc227b8b6ca4ead3a8a91decc74%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb5c065e7bd701b0744f9f28ad769943f91745102716c1eb516325f11%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbdb59c683d666130906a9c05a1d2b034c4cc08cda7ed41322bd54fe2%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://lists.apache.org/thread.html/r030beff88aeb6d7a2d6cd21342bd18686153ce6e26a4171d0e035663%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r46f93de62b1e199f3f9babb18128681677c53493546f532ed88c359d%40%3Creviews.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4ff40646e9ccce13560458419accdfc227b8b6ca4ead3a8a91decc74%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45%40%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb5c065e7bd701b0744f9f28ad769943f91745102716c1eb516325f11%40%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rbdb59c683d666130906a9c05a1d2b034c4cc08cda7ed41322bd54fe2%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-55163 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.2)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2015-2156 suppressed
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
CWE-20 Improper Input Validation
CVSSv3:
HIGH (7.5)
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2019-16869 suppressed
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/0acadfb96176768caac79b404110df62d14d30aa9d53b6dbdb1407ac%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/19fed892608db1efe5a5ce14372137669ff639df0205323959af7de3%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/2494a2ac7f66af6e4646a4937b17972a4ec7cd3c7333c66ffd6c639d%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/2e1cf538b502713c2c42ffa46d81f4688edb5676eb55bd9fc4b4fed7%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/35961d1ae00849974353a932b4fef12ebce074541552eceefa04f1fd%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/37ed432b8eb35d8bd757f53783ec3e334bd51f514534432bea7f1c3d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/380f6d2730603a2cd6b0a8bea9bcb21a86c199147e77e448c5f7390b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/3e6d7aae1cca10257e3caf2d69b22f74c875f12a1314155af422569d%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/51923a9ba513b2e816e02a9d1fd8aa6f12e3e4e99bbd9dc884bccbbe%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/6063699b87b501ecca8dd3b0e82251bfc85f29363a9b46ac5ace80cf%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/64b10f49c68333aaecf00348c5670fe182e49fd60d45c4a3ab241f8b%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/681493a2f9b63f5b468f741d88d1aa51b2cfcf7a1c5b74ea8c4343fb%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/6e1e34c0d5635a987d595df9e532edac212307243bb1b49eead6d55b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/76540c8b0ed761bfa6c81fa28c13057f13a5448aed079d656f6a3c79%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/799eb85d67cbddc1851a3e63a07b55e95b2f44f1685225d38570ce89%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/860acce024d79837e963a51a42bab2cef8e8d017aad2b455ecd1dcf0%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/9128111213b7b734ffc85db08d8f789b00a85a7f241b708e55debbd0%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/a0f77c73af32cbe4ff0968bfcbbe80ae6361f3dccdd46f3177547266%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/af6e9c2d716868606523857a4cd7a5ee506e6d1710f5fb0d567ec030%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b264fa5801e87698e9f43f2b5585fbc5ebdc26c6f4aad861b258fb69%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b2cd51795f938632c6f60a4c59d9e587fbacd7f7d0e0a3684850a30f%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b3dda6399a0ea2b647624b899fd330fca81834e41b13e3e11e1002d8%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b3ddeebbfaf8a288d7de8ab2611cf2609ab76b9809f0633248546b7c%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/bdf7a5e597346a75d2d884ca48c767525e35137ad59d8f10b8fc943c%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/cbf6e6a04cb37e9320ad20e437df63beeab1755fc0761918ed5c5a6e%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/cf5aa087632ead838f8ac3a42e9837684e7afe6e0fcb7704e0c73bc0%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d14f721e0099b914daebe29bca199fde85d8354253be9d6d3d46507a%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d3eb0dbea75ef5c400bd49dfa1901ad50be606cca3cb29e0d01b6a54%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d7d530599dc7813056c712213e367b68cdf56fb5c9b73f864870bc4c%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/e192fe8797c192679759ffa6b15e4d0806546945a41d8ebfbc6ee3ac%40%3Ccommits.tinkerpop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/e39931d7cdd17241e69a0a09a89d99d7435bcc59afee8a9628d67769%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ee6faea9e542c0b90afd70297a9daa203e20d41aa2ac7fca6703662f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f6c5ebfb018787c764f000362d59e4b231c0a36b6253aa866de8c64e%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e%40%3Ccommits.camel.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3225f7dfe6b8a37e800ecb8e31abd7ac6c4312dbd3223dd8139c37bb%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r73c400ab66d79821dec9e3472f0e2c048d528672bdb0f8bf44d7cb1f%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r831e0548fad736a98140d0b3b7dc575af0c50faea0b266434ba813cc%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb25b42f666d2cac5e6e6b3f771faf60d1f1aa58073dcdd8db14edf8a%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcddf723a4b4117f8ed6042e9ac25e8c5110a617bab77694b61b14833%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-16869/5.0.0.Alpha1/exploit
cve@mitre.org - https://lists.apache.org/thread.html/0acadfb96176768caac79b404110df62d14d30aa9d53b6dbdb1407ac@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/19fed892608db1efe5a5ce14372137669ff639df0205323959af7de3@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/2494a2ac7f66af6e4646a4937b17972a4ec7cd3c7333c66ffd6c639d@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/2e1cf538b502713c2c42ffa46d81f4688edb5676eb55bd9fc4b4fed7@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/35961d1ae00849974353a932b4fef12ebce074541552eceefa04f1fd@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/37ed432b8eb35d8bd757f53783ec3e334bd51f514534432bea7f1c3d@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/380f6d2730603a2cd6b0a8bea9bcb21a86c199147e77e448c5f7390b@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/3e6d7aae1cca10257e3caf2d69b22f74c875f12a1314155af422569d@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/51923a9ba513b2e816e02a9d1fd8aa6f12e3e4e99bbd9dc884bccbbe@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/6063699b87b501ecca8dd3b0e82251bfc85f29363a9b46ac5ace80cf@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/64b10f49c68333aaecf00348c5670fe182e49fd60d45c4a3ab241f8b@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/681493a2f9b63f5b468f741d88d1aa51b2cfcf7a1c5b74ea8c4343fb@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/6e1e34c0d5635a987d595df9e532edac212307243bb1b49eead6d55b@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/76540c8b0ed761bfa6c81fa28c13057f13a5448aed079d656f6a3c79@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/799eb85d67cbddc1851a3e63a07b55e95b2f44f1685225d38570ce89@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/860acce024d79837e963a51a42bab2cef8e8d017aad2b455ecd1dcf0@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/9128111213b7b734ffc85db08d8f789b00a85a7f241b708e55debbd0@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/a0f77c73af32cbe4ff0968bfcbbe80ae6361f3dccdd46f3177547266@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/af6e9c2d716868606523857a4cd7a5ee506e6d1710f5fb0d567ec030@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b264fa5801e87698e9f43f2b5585fbc5ebdc26c6f4aad861b258fb69@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b2cd51795f938632c6f60a4c59d9e587fbacd7f7d0e0a3684850a30f@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b3dda6399a0ea2b647624b899fd330fca81834e41b13e3e11e1002d8@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b3ddeebbfaf8a288d7de8ab2611cf2609ab76b9809f0633248546b7c@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/bdf7a5e597346a75d2d884ca48c767525e35137ad59d8f10b8fc943c@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/cbf6e6a04cb37e9320ad20e437df63beeab1755fc0761918ed5c5a6e@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/cf5aa087632ead838f8ac3a42e9837684e7afe6e0fcb7704e0c73bc0@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d14f721e0099b914daebe29bca199fde85d8354253be9d6d3d46507a@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d3eb0dbea75ef5c400bd49dfa1901ad50be606cca3cb29e0d01b6a54@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d7d530599dc7813056c712213e367b68cdf56fb5c9b73f864870bc4c@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/e192fe8797c192679759ffa6b15e4d0806546945a41d8ebfbc6ee3ac@%3Ccommits.tinkerpop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/e39931d7cdd17241e69a0a09a89d99d7435bcc59afee8a9628d67769@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ee6faea9e542c0b90afd70297a9daa203e20d41aa2ac7fca6703662f@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f6c5ebfb018787c764f000362d59e4b231c0a36b6253aa866de8c64e@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e@%3Ccommits.camel.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r3225f7dfe6b8a37e800ecb8e31abd7ac6c4312dbd3223dd8139c37bb@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r73c400ab66d79821dec9e3472f0e2c048d528672bdb0f8bf44d7cb1f@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r831e0548fad736a98140d0b3b7dc575af0c50faea0b266434ba813cc@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb25b42f666d2cac5e6e6b3f771faf60d1f1aa58073dcdd8db14edf8a@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcddf723a4b4117f8ed6042e9ac25e8c5110a617bab77694b61b14833@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f@%3Cdev.flink.apache.org%3E
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppressed
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2022-41881 suppressed
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
CWE-674 Uncontrolled Recursion
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2023-44487 suppressed
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
134c704f-9b21-4f2e-91b3-4a467353bcc0 - US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
cve@mitre.org - BROKEN_LINK
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
cve@mitre.org - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,PATCH,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,VENDOR_ADVISORY
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT,RELEASE_NOTES
cve@mitre.org - PRODUCT,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-58057 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4:
MEDIUM (6.9)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2023-34462 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2021-21295 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (5.9)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A
CVSSv2:
Base Score: LOW (2.6)
Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2021-21409 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (5.9)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0b09f3e31e004fe583f677f7afa46bd30110904576c13c5ac818ac2c%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0ca82fec33334e571fe5b388272260778883e307e15415d7b1443de2%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r101f82d8f3b5af0bf79aecbd5b2dd3b404f6bb51d1a54c2c3d29bed9%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b3cb056364794f919aaf26ceaf7423de64e7fdd05a914066e7d5219%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2732aa3884cacfecac4c54cfaa77c279ba815cad44b464a567216f83%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r31044fb995e894749cb821c6fe56f487c16a97028e6e360e59f09d58%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4a98827bb4a7edbd69ef862f2351391845697c40711820d10df52ca5%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4b8be87acf5b9c098a2ee350b5ca5716fe7afeaf0a21a4ee45a90687%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4ea2f1a9d79d4fc1896e085f31fb60a21b1770d0a26a5250f849372d%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5baac01f9e06c40ff7aab209d5751b3b58802c63734e33324b70a06a%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5cbea8614812289a9b98d0cfc54b47f54cef424ac98d5e315b791795%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5f2f120b2b8d099226473db1832ffb4d7c1d6dc2d228a164bf293a8e%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r602e98daacc98934f097f07f2eed6eb07c18bfc1949c8489dc7bfcf5%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r61564d86a75403b854cdafee67fc69c8b88c5f6802c2c838f4282cc8%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r69efd8ef003f612c43e4154e788ca3b1f837feaacd16d97854402355%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6dac9bd799ceac499c7a7e152a9b0dc7f2fe7f89ec5605d129bb047b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70c3a7bfa904f06a1902f4df20ee26e4f09a46b8fd3eb304dc57a2de%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7879ddcb990c835c6b246654770d836f9d031dee982be836744e50ed%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7b54563abebe3dbbe421e1ba075c2030d8d460372f8c79b7789684b6%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r823d4b27fcba8dad5fe945bdefce3ca5a0031187966eb6ef3cc22ba9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r855b4b6814ac829ce2d48dd9d8138d07f33387e710de798ee92c011e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r967002f0939e69bdec58f070735a19dd57c1f2b8f817949ca17cddae%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9ec78dc409f3f1edff88f21cab53737f36aad46f582a9825389092e0%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9fe840c36b74f92b8d4a089ada1f9fd1d6293742efa18b10e06b66d2%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra64d56a8a331ffd7bdcd24a9aaaeeedeacd5d639f5a683389123f898%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra655e5cec74d1ddf62adacb71d398abd96f3ea2c588f6bbf048348eb%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra66e93703e3f4bd31bdfd0b6fb0c32ae96b528259bb1aa2b6d38e401%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raa413040db6d2197593cc03edecfd168732e697119e6447b0a25d525%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rac8cf45a1bab9ead5c9a860cbadd6faaeb7792203617b6ec3874736d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rafc77f9f03031297394f3d372ccea751b23576f8a2ae9b6b053894c5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rba2a9ef1d0af882ab58fadb336a58818495245dda43d32a7d7837187%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbde2f13daf4911504f0eaea43eee4f42555241b5f6d9d71564b6c5fa%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rca0978b634a0c3ebee4126ec29c7f570b165fae3f8f3658754c1cbd3%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcae42fba06979934208bbd515584b241d3ad01d1bb8b063512644362%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd4a6b7dec38ea6cd28b6f94bd4b312629a52b80be3786d5fb0e474bc%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd206d9dd7eb894cc089b37fe6edde2932de88d63a6d8368b44f5101%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5715f3ee5e3216d5e0083a07994f67da6dbb9731ce9e7a6389b18e%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re1911e05c08f3ec2bab85744d788773519a0afb27272a31ac2a0b4e8%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re39391adcb863f0e9f3f15e7986255948f263f02e4700b82453e7102%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re4b0141939370304d676fe23774d0c6fbc584b648919825402d0cb39%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re7c69756a102bebce8b8681882844a53e2f23975a189363e68ad0324%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re9e6ed60941da831675de2f8f733c026757fb4fa28a7b6c9f3dfb575%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/redef0fb5474fd686781007de9ddb852b24f1b04131a248d9a4789183%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf148b2bf6c2754153a8629bc7495e216bd0bd4c915695486542a10b4%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf38e4dcdefc7c59f7ba0799a399d6d6e37b555d406a1dfc2fcbf0b35%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf521ff2be2e2dd38984174d3451e6ee935c845948845c8fccd86371d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf934292a4a1c189827f625d567838d2c1001e4739b158638d844105b%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - https://lists.apache.org/thread.html/r0b09f3e31e004fe583f677f7afa46bd30110904576c13c5ac818ac2c%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r0ca82fec33334e571fe5b388272260778883e307e15415d7b1443de2%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r101f82d8f3b5af0bf79aecbd5b2dd3b404f6bb51d1a54c2c3d29bed9%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r1b3cb056364794f919aaf26ceaf7423de64e7fdd05a914066e7d5219%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2732aa3884cacfecac4c54cfaa77c279ba815cad44b464a567216f83%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r31044fb995e894749cb821c6fe56f487c16a97028e6e360e59f09d58%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4a98827bb4a7edbd69ef862f2351391845697c40711820d10df52ca5%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4b8be87acf5b9c098a2ee350b5ca5716fe7afeaf0a21a4ee45a90687%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4ea2f1a9d79d4fc1896e085f31fb60a21b1770d0a26a5250f849372d%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5baac01f9e06c40ff7aab209d5751b3b58802c63734e33324b70a06a%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5cbea8614812289a9b98d0cfc54b47f54cef424ac98d5e315b791795%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5f2f120b2b8d099226473db1832ffb4d7c1d6dc2d228a164bf293a8e%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r602e98daacc98934f097f07f2eed6eb07c18bfc1949c8489dc7bfcf5%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r61564d86a75403b854cdafee67fc69c8b88c5f6802c2c838f4282cc8%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r69efd8ef003f612c43e4154e788ca3b1f837feaacd16d97854402355%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r6dac9bd799ceac499c7a7e152a9b0dc7f2fe7f89ec5605d129bb047b%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r70c3a7bfa904f06a1902f4df20ee26e4f09a46b8fd3eb304dc57a2de%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7879ddcb990c835c6b246654770d836f9d031dee982be836744e50ed%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7b54563abebe3dbbe421e1ba075c2030d8d460372f8c79b7789684b6%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r823d4b27fcba8dad5fe945bdefce3ca5a0031187966eb6ef3cc22ba9%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r855b4b6814ac829ce2d48dd9d8138d07f33387e710de798ee92c011e%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r967002f0939e69bdec58f070735a19dd57c1f2b8f817949ca17cddae%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9ec78dc409f3f1edff88f21cab53737f36aad46f582a9825389092e0%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9fe840c36b74f92b8d4a089ada1f9fd1d6293742efa18b10e06b66d2%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra64d56a8a331ffd7bdcd24a9aaaeeedeacd5d639f5a683389123f898%40%3Cdev.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra655e5cec74d1ddf62adacb71d398abd96f3ea2c588f6bbf048348eb%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra66e93703e3f4bd31bdfd0b6fb0c32ae96b528259bb1aa2b6d38e401%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/raa413040db6d2197593cc03edecfd168732e697119e6447b0a25d525%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rac8cf45a1bab9ead5c9a860cbadd6faaeb7792203617b6ec3874736d%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rafc77f9f03031297394f3d372ccea751b23576f8a2ae9b6b053894c5%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rba2a9ef1d0af882ab58fadb336a58818495245dda43d32a7d7837187%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rbde2f13daf4911504f0eaea43eee4f42555241b5f6d9d71564b6c5fa%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rca0978b634a0c3ebee4126ec29c7f570b165fae3f8f3658754c1cbd3%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rcae42fba06979934208bbd515584b241d3ad01d1bb8b063512644362%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rd4a6b7dec38ea6cd28b6f94bd4b312629a52b80be3786d5fb0e474bc%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdd206d9dd7eb894cc089b37fe6edde2932de88d63a6d8368b44f5101%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdd5715f3ee5e3216d5e0083a07994f67da6dbb9731ce9e7a6389b18e%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re1911e05c08f3ec2bab85744d788773519a0afb27272a31ac2a0b4e8%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re39391adcb863f0e9f3f15e7986255948f263f02e4700b82453e7102%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re4b0141939370304d676fe23774d0c6fbc584b648919825402d0cb39%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re7c69756a102bebce8b8681882844a53e2f23975a189363e68ad0324%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re9e6ed60941da831675de2f8f733c026757fb4fa28a7b6c9f3dfb575%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/redef0fb5474fd686781007de9ddb852b24f1b04131a248d9a4789183%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf148b2bf6c2754153a8629bc7495e216bd0bd4c915695486542a10b4%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf38e4dcdefc7c59f7ba0799a399d6d6e37b555d406a1dfc2fcbf0b35%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf521ff2be2e2dd38984174d3451e6ee935c845948845c8fccd86371d%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf934292a4a1c189827f625d567838d2c1001e4739b158638d844105b%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2021-21290 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: LOW (1.9)
Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0053443ce19ff125981559f8c51cf66e3ab4350f47812b8cf0733a05%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0857b613604c696bf9743f0af047360baaded48b1c75cf6945a083c5%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r10308b625e49d4e9491d7e079606ca0df2f0a4d828f1ad1da64ba47b%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2748097ea4b774292539cf3de6e3b267fc7a88d6c8ec40f4e2e87bd4%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2936730ef0a06e724b96539bc7eacfcd3628987c16b1b99c790e7b87%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2fda4dab73097051977f2ab818f75e04fbcb15bb1003c8530eac1059%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r326ec431f06eab7cb7113a7a338e59731b8d556d05258457f12bac1b%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4efed2c501681cb2e8d629da16e48d9eac429624fd4c9a8c6b8e7020%40%3Cdev.tinkerpop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5bf303d7c04da78f276765da08559fdc62420f1df539b277ca31f63b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5c701840aa2845191721e39821445e1e8c59711e71942b7796a6ec29%40%3Cusers.activemq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5e4a540089760c8ecc2c411309d74264f1dad634ad93ad583ca16214%40%3Ccommits.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r71dbb66747ff537640bb91eb0b2b24edef21ac07728097016f58b01f%40%3Ccommits.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r743149dcc8db1de473e6bff0b3ddf10140a7357bc2add75f7d1fbb12%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra0fc2b4553dd7aaf75febb61052b7f1243ac3a180a71c01f29093013%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra503756ced78fdc2136bd33e87cb7553028645b261b1f5c6186a121e%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc488f80094872ad925f0c73d283d4c00d32def81977438e27a3dc2bb%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdba4f78ac55f803893a1a2265181595e79e3aa027e2e651dfba98c18%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - https://lists.apache.org/thread.html/r0053443ce19ff125981559f8c51cf66e3ab4350f47812b8cf0733a05%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f%40%3Cdev.ranger.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r0857b613604c696bf9743f0af047360baaded48b1c75cf6945a083c5%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r10308b625e49d4e9491d7e079606ca0df2f0a4d828f1ad1da64ba47b%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2748097ea4b774292539cf3de6e3b267fc7a88d6c8ec40f4e2e87bd4%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2936730ef0a06e724b96539bc7eacfcd3628987c16b1b99c790e7b87%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2fda4dab73097051977f2ab818f75e04fbcb15bb1003c8530eac1059%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r326ec431f06eab7cb7113a7a338e59731b8d556d05258457f12bac1b%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4efed2c501681cb2e8d629da16e48d9eac429624fd4c9a8c6b8e7020%40%3Cdev.tinkerpop.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5bf303d7c04da78f276765da08559fdc62420f1df539b277ca31f63b%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5c701840aa2845191721e39821445e1e8c59711e71942b7796a6ec29%40%3Cusers.activemq.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5e4a540089760c8ecc2c411309d74264f1dad634ad93ad583ca16214%40%3Ccommits.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r71dbb66747ff537640bb91eb0b2b24edef21ac07728097016f58b01f%40%3Ccommits.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r743149dcc8db1de473e6bff0b3ddf10140a7357bc2add75f7d1fbb12%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890%40%3Cissues.bookkeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5%40%3Cdev.ranger.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra0fc2b4553dd7aaf75febb61052b7f1243ac3a180a71c01f29093013%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra503756ced78fdc2136bd33e87cb7553028645b261b1f5c6186a121e%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rc488f80094872ad925f0c73d283d4c00d32def81977438e27a3dc2bb%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdba4f78ac55f803893a1a2265181595e79e3aa027e2e651dfba98c18%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - EXPLOIT,THIRD_PARTY_ADVISORY
security-advisories@github.com - MAILING_LIST,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2022-24823 suppressed
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: LOW (1.9)
Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2024-47535 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2025-25193 suppressed
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2024-29025 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2014-3488 suppressed
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-58056 suppressed
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
sharepoint-online-connector-0.9.4.war: reactor-netty-http-1.2.10.jar
File Path: /builds/transconnect/product/server/.gradle.userhome/caches/modules-2/files-2.1/io.transconnect.connector/sharepoint-online-connector/0.9.4/4345fb71be8bf878916835e7b99d225041448fb8/sharepoint-online-connector-0.9.4.war/WEB-INF/lib/reactor-netty-http-1.2.10.jar
MD5: 1722742824e774911edf15e23ddb517c
SHA1: e60ff32fe2e13c0be741378b85d810e99e49c80e
SHA256: bf4df02ab9db60232ffeda74304cc06a4217ab278fd1a78557a1494a9cbc645a
Referenced In Project/Scope: server-start:webapps
Evidence
Type Source Name Value Confidence
Vendor file name reactor-netty-http High
Vendor jar package name http Highest
Vendor jar package name http Low
Vendor jar package name netty Highest
Vendor jar package name netty Low
Vendor jar package name reactor Highest
Vendor jar package name reactor Low
Vendor Manifest automatic-module-name reactor.netty.http Medium
Vendor Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-http Medium
Product file name reactor-netty-http High
Product jar package name http Highest
Product jar package name http Low
Product jar package name netty Highest
Product jar package name netty Low
Product jar package name reactor Highest
Product Manifest automatic-module-name reactor.netty.http Medium
Product Manifest Bundle-Name reactor-netty-http Medium
Product Manifest bundle-symbolicname io.projectreactor.netty.reactor-netty-http Medium
Product Manifest Implementation-Title reactor-netty-http High
Version file version 1.2.10 High
Version Manifest Implementation-Version 1.2.10 High
cpe:2.3:a:netty:netty:1.2.10:*:*:*:*:*:*:* suppressed
(Confidence :Highest)
Notes: false positive, "io.projectreactor.netty.reactor-netty-core" should not match against "io.netty:netty-all"
file name: sharepoint-online-connector-0.9.0-candidate-4-5-0-SNAPSHOT.war: reactor-netty-core-1.2.10.jar
CVE-2026-42581 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.8)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2019-20444 suppressed
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (6.4)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r059b042bca47be53ff8a51fd04d95eb01bb683f1afa209db136e8cb7%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e%40%3Ccommits.camel.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0f5e72d5f69b4720dfe64fcbc2da9afae949ed1e9cbffa84bb7d92d7%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r34912a9b1a5c269a77b8be94ef6fb6d1e9b3c69129719dc00f01cf0b%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r489886fe72a98768eed665474cba13bad8d6fe0654f24987706636c5%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4c675b2d0cc2a5e506b11ee10d60a378859ee340aca052e4c7ef4749%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r91e0fa345c86c128b75a4a791b4b503b53173ff4c13049ac7129d319%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-20444/5.0.0.Alpha1/exploit
cve@mitre.org - https://lists.apache.org/thread.html/r059b042bca47be53ff8a51fd04d95eb01bb683f1afa209db136e8cb7@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e@%3Ccommits.camel.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0f5e72d5f69b4720dfe64fcbc2da9afae949ed1e9cbffa84bb7d92d7@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d@%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r34912a9b1a5c269a77b8be94ef6fb6d1e9b3c69129719dc00f01cf0b@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r489886fe72a98768eed665474cba13bad8d6fe0654f24987706636c5@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4c675b2d0cc2a5e506b11ee10d60a378859ee340aca052e4c7ef4749@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r91e0fa345c86c128b75a4a791b4b503b53173ff4c13049ac7129d319@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f@%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f@%3Cdev.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b@%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2019-20445 suppressed
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (6.4)
Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r030beff88aeb6d7a2d6cd21342bd18686153ce6e26a4171d0e035663%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r46f93de62b1e199f3f9babb18128681677c53493546f532ed88c359d%40%3Creviews.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4ff40646e9ccce13560458419accdfc227b8b6ca4ead3a8a91decc74%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb5c065e7bd701b0744f9f28ad769943f91745102716c1eb516325f11%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbdb59c683d666130906a9c05a1d2b034c4cc08cda7ed41322bd54fe2%40%3Cissues.flume.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://lists.apache.org/thread.html/r030beff88aeb6d7a2d6cd21342bd18686153ce6e26a4171d0e035663%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc12e01faafb2fb5%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef6ce1b118d34d8d%40%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r2f2989b7815d809ff3fda8ce330f553e5f133505afd04ffbc135f35f%40%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r46f93de62b1e199f3f9babb18128681677c53493546f532ed88c359d%40%3Creviews.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4ff40646e9ccce13560458419accdfc227b8b6ca4ead3a8a91decc74%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r6945f3c346b7af89bbd3526a7c9b705b1e3569070ebcd0964bcedd7d%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45%40%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r819aaeb9944bdcfca438dcc51f05650dc728daf64dfd7d774fc2499b%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986%40%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra1a71b576a45426af5ee65255be9596ff3181a342f4ba73b800db78f%40%3Cdev.geode.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593%40%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb5c065e7bd701b0744f9f28ad769943f91745102716c1eb516325f11%40%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb84c57670ec48ef23f4d07973b7fa69f629b8e7fcfb48874362feb6f%40%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rbdb59c683d666130906a9c05a1d2b034c4cc08cda7ed41322bd54fe2%40%3Cissues.flume.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb%40%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b%40%3Cnotifications.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114%40%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2026-42579 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte)
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42584 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
CRITICAL (9.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-33871 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.7)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-55163 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
HIGH (8.2)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2015-2156 suppressed
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
CWE-20 Improper Input Validation
CVSSv3:
HIGH (7.5)
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2019-16869 suppressed
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/0acadfb96176768caac79b404110df62d14d30aa9d53b6dbdb1407ac%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/19fed892608db1efe5a5ce14372137669ff639df0205323959af7de3%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/2494a2ac7f66af6e4646a4937b17972a4ec7cd3c7333c66ffd6c639d%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/2e1cf538b502713c2c42ffa46d81f4688edb5676eb55bd9fc4b4fed7%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/35961d1ae00849974353a932b4fef12ebce074541552eceefa04f1fd%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/37ed432b8eb35d8bd757f53783ec3e334bd51f514534432bea7f1c3d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/380f6d2730603a2cd6b0a8bea9bcb21a86c199147e77e448c5f7390b%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/3e6d7aae1cca10257e3caf2d69b22f74c875f12a1314155af422569d%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/51923a9ba513b2e816e02a9d1fd8aa6f12e3e4e99bbd9dc884bccbbe%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/6063699b87b501ecca8dd3b0e82251bfc85f29363a9b46ac5ace80cf%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/64b10f49c68333aaecf00348c5670fe182e49fd60d45c4a3ab241f8b%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/681493a2f9b63f5b468f741d88d1aa51b2cfcf7a1c5b74ea8c4343fb%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/6e1e34c0d5635a987d595df9e532edac212307243bb1b49eead6d55b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/76540c8b0ed761bfa6c81fa28c13057f13a5448aed079d656f6a3c79%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/799eb85d67cbddc1851a3e63a07b55e95b2f44f1685225d38570ce89%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/860acce024d79837e963a51a42bab2cef8e8d017aad2b455ecd1dcf0%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/9128111213b7b734ffc85db08d8f789b00a85a7f241b708e55debbd0%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/a0f77c73af32cbe4ff0968bfcbbe80ae6361f3dccdd46f3177547266%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/af6e9c2d716868606523857a4cd7a5ee506e6d1710f5fb0d567ec030%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b264fa5801e87698e9f43f2b5585fbc5ebdc26c6f4aad861b258fb69%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b2cd51795f938632c6f60a4c59d9e587fbacd7f7d0e0a3684850a30f%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b3dda6399a0ea2b647624b899fd330fca81834e41b13e3e11e1002d8%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/b3ddeebbfaf8a288d7de8ab2611cf2609ab76b9809f0633248546b7c%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/bdf7a5e597346a75d2d884ca48c767525e35137ad59d8f10b8fc943c%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/cbf6e6a04cb37e9320ad20e437df63beeab1755fc0761918ed5c5a6e%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/cf5aa087632ead838f8ac3a42e9837684e7afe6e0fcb7704e0c73bc0%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d14f721e0099b914daebe29bca199fde85d8354253be9d6d3d46507a%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d3eb0dbea75ef5c400bd49dfa1901ad50be606cca3cb29e0d01b6a54%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/d7d530599dc7813056c712213e367b68cdf56fb5c9b73f864870bc4c%40%3Cdev.olingo.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/e192fe8797c192679759ffa6b15e4d0806546945a41d8ebfbc6ee3ac%40%3Ccommits.tinkerpop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/e39931d7cdd17241e69a0a09a89d99d7435bcc59afee8a9628d67769%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ee6faea9e542c0b90afd70297a9daa203e20d41aa2ac7fca6703662f%40%3Cissues.spark.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f6c5ebfb018787c764f000362d59e4b231c0a36b6253aa866de8c64e%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e%40%3Ccommits.camel.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r3225f7dfe6b8a37e800ecb8e31abd7ac6c4312dbd3223dd8139c37bb%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r73c400ab66d79821dec9e3472f0e2c048d528672bdb0f8bf44d7cb1f%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r831e0548fad736a98140d0b3b7dc575af0c50faea0b266434ba813cc%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb25b42f666d2cac5e6e6b3f771faf60d1f1aa58073dcdd8db14edf8a%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05%40%3Ccommits.cassandra.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcddf723a4b4117f8ed6042e9ac25e8c5110a617bab77694b61b14833%40%3Cdev.rocketmq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9%40%3Ccommon-commits.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948%40%3Ccommits.druid.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41%40%3Ccommon-issues.hadoop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
cve@mitre.org - https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-16869/5.0.0.Alpha1/exploit
cve@mitre.org - https://lists.apache.org/thread.html/0acadfb96176768caac79b404110df62d14d30aa9d53b6dbdb1407ac@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/19fed892608db1efe5a5ce14372137669ff639df0205323959af7de3@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/2494a2ac7f66af6e4646a4937b17972a4ec7cd3c7333c66ffd6c639d@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/2e1cf538b502713c2c42ffa46d81f4688edb5676eb55bd9fc4b4fed7@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/35961d1ae00849974353a932b4fef12ebce074541552eceefa04f1fd@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/37ed432b8eb35d8bd757f53783ec3e334bd51f514534432bea7f1c3d@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/380f6d2730603a2cd6b0a8bea9bcb21a86c199147e77e448c5f7390b@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/3e6d7aae1cca10257e3caf2d69b22f74c875f12a1314155af422569d@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/51923a9ba513b2e816e02a9d1fd8aa6f12e3e4e99bbd9dc884bccbbe@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/6063699b87b501ecca8dd3b0e82251bfc85f29363a9b46ac5ace80cf@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/64b10f49c68333aaecf00348c5670fe182e49fd60d45c4a3ab241f8b@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/681493a2f9b63f5b468f741d88d1aa51b2cfcf7a1c5b74ea8c4343fb@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/6e1e34c0d5635a987d595df9e532edac212307243bb1b49eead6d55b@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/76540c8b0ed761bfa6c81fa28c13057f13a5448aed079d656f6a3c79@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/799eb85d67cbddc1851a3e63a07b55e95b2f44f1685225d38570ce89@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/860acce024d79837e963a51a42bab2cef8e8d017aad2b455ecd1dcf0@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/9128111213b7b734ffc85db08d8f789b00a85a7f241b708e55debbd0@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/a0f77c73af32cbe4ff0968bfcbbe80ae6361f3dccdd46f3177547266@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/af6e9c2d716868606523857a4cd7a5ee506e6d1710f5fb0d567ec030@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b264fa5801e87698e9f43f2b5585fbc5ebdc26c6f4aad861b258fb69@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b2cd51795f938632c6f60a4c59d9e587fbacd7f7d0e0a3684850a30f@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b3dda6399a0ea2b647624b899fd330fca81834e41b13e3e11e1002d8@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/b3ddeebbfaf8a288d7de8ab2611cf2609ab76b9809f0633248546b7c@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/bdf7a5e597346a75d2d884ca48c767525e35137ad59d8f10b8fc943c@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/cbf6e6a04cb37e9320ad20e437df63beeab1755fc0761918ed5c5a6e@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/cf5aa087632ead838f8ac3a42e9837684e7afe6e0fcb7704e0c73bc0@%3Ccommits.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d14f721e0099b914daebe29bca199fde85d8354253be9d6d3d46507a@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d3eb0dbea75ef5c400bd49dfa1901ad50be606cca3cb29e0d01b6a54@%3Cissues.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/d7d530599dc7813056c712213e367b68cdf56fb5c9b73f864870bc4c@%3Cdev.olingo.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/e192fe8797c192679759ffa6b15e4d0806546945a41d8ebfbc6ee3ac@%3Ccommits.tinkerpop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/e39931d7cdd17241e69a0a09a89d99d7435bcc59afee8a9628d67769@%3Cdev.zookeeper.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/ee6faea9e542c0b90afd70297a9daa203e20d41aa2ac7fca6703662f@%3Cissues.spark.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f6c5ebfb018787c764f000362d59e4b231c0a36b6253aa866de8c64e@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed762e253401106e@%3Ccommits.camel.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1c552ef1b7923a5@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r3225f7dfe6b8a37e800ecb8e31abd7ac6c4312dbd3223dd8139c37bb@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r73c400ab66d79821dec9e3472f0e2c048d528672bdb0f8bf44d7cb1f@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r7790b9d99696d9eddce8a8c96f13bb68460984294ea6fea3800143e4@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r831e0548fad736a98140d0b3b7dc575af0c50faea0b266434ba813cc@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r832724df393a7ef25ca4c7c2eb83ad2d6c21c74569acda5233f9f1ec@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r8402d67fdfe9cf169f859d52a7670b28a08eff31e54b522cc1432532@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r86befa74c5cd1482c711134104aec339bf7ae879f2c4437d7ec477d4@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r90030b0117490caed526e57271bf4d7f9b012091ac5083c895d16543@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/r959474dcf7f88565ed89f6252ca5a274419006cb71348f14764b183d@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/raaac04b7567c554786132144bea3dcb72568edd410c1e6f0101742e7@%3Cissues.flink.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb25b42f666d2cac5e6e6b3f771faf60d1f1aa58073dcdd8db14edf8a@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rb3361f6c6a5f834ad3db5e998c352760d393c0891b8d3bea90baa836@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc7eb5634b71d284483e58665b22bf274a69bd184d9bd7ede52015d91@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05@%3Ccommits.cassandra.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcb2c59428f34d4757702f9ae739a8795bda7bea97b857e708a9c62c6@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rcddf723a4b4117f8ed6042e9ac25e8c5110a617bab77694b61b14833@%3Cdev.rocketmq.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdb69125652311d0c41f6066ff44072a3642cf33a4b5e3c4f9c1ec9c2@%3Ccommits.pulsar.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rdd5d243a5f8ed8b83c0104e321aa420e5e98792a95749e3c9a54c0b9@%3Ccommon-commits.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re0b78a3d0a4ba2cf9f4e14e1d05040bde9051d5c78071177186336c9@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/re78eaef7d01ad65c370df30e45c686fffff00b37f7bfd78b26a08762@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf2bf8e2eb0a03227f5bc100b544113f8cafea01e887bb068e8d1fa41@%3Ccommon-issues.hadoop.apache.org%3E
cve@mitre.org - https://lists.apache.org/thread.html/rf5b2dfb7401666a19915f8eaef3ba9f5c3386e2066fcd2ae66e16a2f@%3Cdev.flink.apache.org%3E
cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppressed
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2022-41881 suppressed
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
CWE-674 Uncontrolled Recursion
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2023-44487 suppressed
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e - THIRD_PARTY_ADVISORY
134c704f-9b21-4f2e-91b3-4a467353bcc0 - US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY
cve@mitre.org - BROKEN_LINK
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING
cve@mitre.org - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PATCH
cve@mitre.org - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE
cve@mitre.org - ISSUE_TRACKING,THIRD_PARTY_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST
cve@mitre.org - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,PATCH,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY
cve@mitre.org - MITIGATION,VENDOR_ADVISORY
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PATCH,VENDOR_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT
cve@mitre.org - PRODUCT,RELEASE_NOTES
cve@mitre.org - PRODUCT,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES
cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY
cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
cve@mitre.org - VENDOR_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2026-33870 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42582 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-42583 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42585 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42587 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-44248 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42586 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
HIGH (7.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2025-58057 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4:
MEDIUM (6.9)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2023-34462 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2025-67735 suppressed
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42580 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound
CVSSv3:
MEDIUM (6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2021-21295 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (5.9)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A
CVSSv2:
Base Score: LOW (2.6)
Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N
References:
Vulnerable Software & Versions: (show all )
CVE-2021-21409 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
MEDIUM (5.9)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A
CVSSv2:
Base Score: MEDIUM (4.3)
Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0b09f3e31e004fe583f677f7afa46bd30110904576c13c5ac818ac2c%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0ca82fec33334e571fe5b388272260778883e307e15415d7b1443de2%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r101f82d8f3b5af0bf79aecbd5b2dd3b404f6bb51d1a54c2c3d29bed9%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1b3cb056364794f919aaf26ceaf7423de64e7fdd05a914066e7d5219%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2732aa3884cacfecac4c54cfaa77c279ba815cad44b464a567216f83%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r31044fb995e894749cb821c6fe56f487c16a97028e6e360e59f09d58%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4a98827bb4a7edbd69ef862f2351391845697c40711820d10df52ca5%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4b8be87acf5b9c098a2ee350b5ca5716fe7afeaf0a21a4ee45a90687%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4ea2f1a9d79d4fc1896e085f31fb60a21b1770d0a26a5250f849372d%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5baac01f9e06c40ff7aab209d5751b3b58802c63734e33324b70a06a%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5cbea8614812289a9b98d0cfc54b47f54cef424ac98d5e315b791795%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5f2f120b2b8d099226473db1832ffb4d7c1d6dc2d228a164bf293a8e%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r602e98daacc98934f097f07f2eed6eb07c18bfc1949c8489dc7bfcf5%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r61564d86a75403b854cdafee67fc69c8b88c5f6802c2c838f4282cc8%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r69efd8ef003f612c43e4154e788ca3b1f837feaacd16d97854402355%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r6dac9bd799ceac499c7a7e152a9b0dc7f2fe7f89ec5605d129bb047b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r70c3a7bfa904f06a1902f4df20ee26e4f09a46b8fd3eb304dc57a2de%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7879ddcb990c835c6b246654770d836f9d031dee982be836744e50ed%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7b54563abebe3dbbe421e1ba075c2030d8d460372f8c79b7789684b6%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r823d4b27fcba8dad5fe945bdefce3ca5a0031187966eb6ef3cc22ba9%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r855b4b6814ac829ce2d48dd9d8138d07f33387e710de798ee92c011e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r967002f0939e69bdec58f070735a19dd57c1f2b8f817949ca17cddae%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9ec78dc409f3f1edff88f21cab53737f36aad46f582a9825389092e0%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9fe840c36b74f92b8d4a089ada1f9fd1d6293742efa18b10e06b66d2%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra64d56a8a331ffd7bdcd24a9aaaeeedeacd5d639f5a683389123f898%40%3Cdev.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra655e5cec74d1ddf62adacb71d398abd96f3ea2c588f6bbf048348eb%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra66e93703e3f4bd31bdfd0b6fb0c32ae96b528259bb1aa2b6d38e401%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/raa413040db6d2197593cc03edecfd168732e697119e6447b0a25d525%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rac8cf45a1bab9ead5c9a860cbadd6faaeb7792203617b6ec3874736d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rafc77f9f03031297394f3d372ccea751b23576f8a2ae9b6b053894c5%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rba2a9ef1d0af882ab58fadb336a58818495245dda43d32a7d7837187%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rbde2f13daf4911504f0eaea43eee4f42555241b5f6d9d71564b6c5fa%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rca0978b634a0c3ebee4126ec29c7f570b165fae3f8f3658754c1cbd3%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcae42fba06979934208bbd515584b241d3ad01d1bb8b063512644362%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd4a6b7dec38ea6cd28b6f94bd4b312629a52b80be3786d5fb0e474bc%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd206d9dd7eb894cc089b37fe6edde2932de88d63a6d8368b44f5101%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdd5715f3ee5e3216d5e0083a07994f67da6dbb9731ce9e7a6389b18e%40%3Ccommits.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re1911e05c08f3ec2bab85744d788773519a0afb27272a31ac2a0b4e8%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re39391adcb863f0e9f3f15e7986255948f263f02e4700b82453e7102%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re4b0141939370304d676fe23774d0c6fbc584b648919825402d0cb39%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re7c69756a102bebce8b8681882844a53e2f23975a189363e68ad0324%40%3Cissues.flink.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/re9e6ed60941da831675de2f8f733c026757fb4fa28a7b6c9f3dfb575%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/redef0fb5474fd686781007de9ddb852b24f1b04131a248d9a4789183%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf148b2bf6c2754153a8629bc7495e216bd0bd4c915695486542a10b4%40%3Cnotifications.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf38e4dcdefc7c59f7ba0799a399d6d6e37b555d406a1dfc2fcbf0b35%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf521ff2be2e2dd38984174d3451e6ee935c845948845c8fccd86371d%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rf934292a4a1c189827f625d567838d2c1001e4739b158638d844105b%40%3Cissues.kudu.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - https://lists.apache.org/thread.html/r0b09f3e31e004fe583f677f7afa46bd30110904576c13c5ac818ac2c%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r0ca82fec33334e571fe5b388272260778883e307e15415d7b1443de2%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r101f82d8f3b5af0bf79aecbd5b2dd3b404f6bb51d1a54c2c3d29bed9%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r1b3cb056364794f919aaf26ceaf7423de64e7fdd05a914066e7d5219%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2732aa3884cacfecac4c54cfaa77c279ba815cad44b464a567216f83%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r31044fb995e894749cb821c6fe56f487c16a97028e6e360e59f09d58%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4a98827bb4a7edbd69ef862f2351391845697c40711820d10df52ca5%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4b8be87acf5b9c098a2ee350b5ca5716fe7afeaf0a21a4ee45a90687%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4ea2f1a9d79d4fc1896e085f31fb60a21b1770d0a26a5250f849372d%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5baac01f9e06c40ff7aab209d5751b3b58802c63734e33324b70a06a%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5cbea8614812289a9b98d0cfc54b47f54cef424ac98d5e315b791795%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5f2f120b2b8d099226473db1832ffb4d7c1d6dc2d228a164bf293a8e%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r602e98daacc98934f097f07f2eed6eb07c18bfc1949c8489dc7bfcf5%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r61564d86a75403b854cdafee67fc69c8b88c5f6802c2c838f4282cc8%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r69efd8ef003f612c43e4154e788ca3b1f837feaacd16d97854402355%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r6dac9bd799ceac499c7a7e152a9b0dc7f2fe7f89ec5605d129bb047b%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r70c3a7bfa904f06a1902f4df20ee26e4f09a46b8fd3eb304dc57a2de%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7879ddcb990c835c6b246654770d836f9d031dee982be836744e50ed%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7b54563abebe3dbbe421e1ba075c2030d8d460372f8c79b7789684b6%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r823d4b27fcba8dad5fe945bdefce3ca5a0031187966eb6ef3cc22ba9%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r855b4b6814ac829ce2d48dd9d8138d07f33387e710de798ee92c011e%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r967002f0939e69bdec58f070735a19dd57c1f2b8f817949ca17cddae%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9ec78dc409f3f1edff88f21cab53737f36aad46f582a9825389092e0%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9fe840c36b74f92b8d4a089ada1f9fd1d6293742efa18b10e06b66d2%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra64d56a8a331ffd7bdcd24a9aaaeeedeacd5d639f5a683389123f898%40%3Cdev.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra655e5cec74d1ddf62adacb71d398abd96f3ea2c588f6bbf048348eb%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra66e93703e3f4bd31bdfd0b6fb0c32ae96b528259bb1aa2b6d38e401%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/raa413040db6d2197593cc03edecfd168732e697119e6447b0a25d525%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rac8cf45a1bab9ead5c9a860cbadd6faaeb7792203617b6ec3874736d%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rafc77f9f03031297394f3d372ccea751b23576f8a2ae9b6b053894c5%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rba2a9ef1d0af882ab58fadb336a58818495245dda43d32a7d7837187%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rbde2f13daf4911504f0eaea43eee4f42555241b5f6d9d71564b6c5fa%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rca0978b634a0c3ebee4126ec29c7f570b165fae3f8f3658754c1cbd3%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rcae42fba06979934208bbd515584b241d3ad01d1bb8b063512644362%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rd4a6b7dec38ea6cd28b6f94bd4b312629a52b80be3786d5fb0e474bc%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rd8f72411fb75b98d366400ae789966373b5c3eb3f511e717caf3e49e%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdd206d9dd7eb894cc089b37fe6edde2932de88d63a6d8368b44f5101%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdd5715f3ee5e3216d5e0083a07994f67da6dbb9731ce9e7a6389b18e%40%3Ccommits.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re1911e05c08f3ec2bab85744d788773519a0afb27272a31ac2a0b4e8%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re39391adcb863f0e9f3f15e7986255948f263f02e4700b82453e7102%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re4b0141939370304d676fe23774d0c6fbc584b648919825402d0cb39%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re7c69756a102bebce8b8681882844a53e2f23975a189363e68ad0324%40%3Cissues.flink.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/re9e6ed60941da831675de2f8f733c026757fb4fa28a7b6c9f3dfb575%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/redef0fb5474fd686781007de9ddb852b24f1b04131a248d9a4789183%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf148b2bf6c2754153a8629bc7495e216bd0bd4c915695486542a10b4%40%3Cnotifications.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf38e4dcdefc7c59f7ba0799a399d6d6e37b555d406a1dfc2fcbf0b35%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf521ff2be2e2dd38984174d3451e6ee935c845948845c8fccd86371d%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rf934292a4a1c189827f625d567838d2c1001e4739b158638d844105b%40%3Cissues.kudu.apache.org%3E
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2021-21290 suppressed
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: LOW (1.9)
Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0053443ce19ff125981559f8c51cf66e3ab4350f47812b8cf0733a05%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r0857b613604c696bf9743f0af047360baaded48b1c75cf6945a083c5%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r10308b625e49d4e9491d7e079606ca0df2f0a4d828f1ad1da64ba47b%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2748097ea4b774292539cf3de6e3b267fc7a88d6c8ec40f4e2e87bd4%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2936730ef0a06e724b96539bc7eacfcd3628987c16b1b99c790e7b87%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r2fda4dab73097051977f2ab818f75e04fbcb15bb1003c8530eac1059%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r326ec431f06eab7cb7113a7a338e59731b8d556d05258457f12bac1b%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r4efed2c501681cb2e8d629da16e48d9eac429624fd4c9a8c6b8e7020%40%3Cdev.tinkerpop.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5bf303d7c04da78f276765da08559fdc62420f1df539b277ca31f63b%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5c701840aa2845191721e39821445e1e8c59711e71942b7796a6ec29%40%3Cusers.activemq.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5e4a540089760c8ecc2c411309d74264f1dad634ad93ad583ca16214%40%3Ccommits.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r71dbb66747ff537640bb91eb0b2b24edef21ac07728097016f58b01f%40%3Ccommits.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r743149dcc8db1de473e6bff0b3ddf10140a7357bc2add75f7d1fbb12%40%3Cdev.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890%40%3Cissues.bookkeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5%40%3Cdev.ranger.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra0fc2b4553dd7aaf75febb61052b7f1243ac3a180a71c01f29093013%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/ra503756ced78fdc2136bd33e87cb7553028645b261b1f5c6186a121e%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4%40%3Cdev.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528%40%3Cissues.zookeeper.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rc488f80094872ad925f0c73d283d4c00d32def81977438e27a3dc2bb%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d%40%3Ccommits.pulsar.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - https://lists.apache.org/thread.html/rdba4f78ac55f803893a1a2265181595e79e3aa027e2e651dfba98c18%40%3Cjira.kafka.apache.org%3E
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - https://lists.apache.org/thread.html/r0053443ce19ff125981559f8c51cf66e3ab4350f47812b8cf0733a05%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f%40%3Cdev.ranger.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r0857b613604c696bf9743f0af047360baaded48b1c75cf6945a083c5%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r10308b625e49d4e9491d7e079606ca0df2f0a4d828f1ad1da64ba47b%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2748097ea4b774292539cf3de6e3b267fc7a88d6c8ec40f4e2e87bd4%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2936730ef0a06e724b96539bc7eacfcd3628987c16b1b99c790e7b87%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r2fda4dab73097051977f2ab818f75e04fbcb15bb1003c8530eac1059%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r326ec431f06eab7cb7113a7a338e59731b8d556d05258457f12bac1b%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r4efed2c501681cb2e8d629da16e48d9eac429624fd4c9a8c6b8e7020%40%3Cdev.tinkerpop.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r584cf871f188c406d8bd447ff4e2fd9817fca862436c064d0951a071%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5bf303d7c04da78f276765da08559fdc62420f1df539b277ca31f63b%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5c701840aa2845191721e39821445e1e8c59711e71942b7796a6ec29%40%3Cusers.activemq.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5e4a540089760c8ecc2c411309d74264f1dad634ad93ad583ca16214%40%3Ccommits.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r71dbb66747ff537640bb91eb0b2b24edef21ac07728097016f58b01f%40%3Ccommits.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r743149dcc8db1de473e6bff0b3ddf10140a7357bc2add75f7d1fbb12%40%3Cdev.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890%40%3Cissues.bookkeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5%40%3Cdev.ranger.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra0fc2b4553dd7aaf75febb61052b7f1243ac3a180a71c01f29093013%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/ra503756ced78fdc2136bd33e87cb7553028645b261b1f5c6186a121e%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4%40%3Cdev.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528%40%3Cissues.zookeeper.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rc488f80094872ad925f0c73d283d4c00d32def81977438e27a3dc2bb%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d%40%3Ccommits.pulsar.apache.org%3E
security-advisories@github.com - https://lists.apache.org/thread.html/rdba4f78ac55f803893a1a2265181595e79e3aa027e2e651dfba98c18%40%3Cjira.kafka.apache.org%3E
security-advisories@github.com - EXPLOIT,THIRD_PARTY_ADVISORY
security-advisories@github.com - MAILING_LIST,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2022-24823 suppressed
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
Base Score: LOW (1.9)
Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N
References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY
af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY
security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY
security-advisories@github.com - THIRD_PARTY_ADVISORY
Vulnerable Software & Versions: (show all )
CVE-2024-47535 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2025-25193 suppressed
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
MEDIUM (5.5)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2024-29025 suppressed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions:
CVE-2026-41417 suppressed
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
MEDIUM (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2014-3488 suppressed
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (5.0)
Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P
References:
Vulnerable Software & Versions: (show all )
CVE-2025-58056 suppressed
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-42578 suppressed
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv4:
LOW (2.9)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
HIGH (7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )