Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 13.0.0
Report Generated On : Sun, 13 Sep 2026 00:29:42 GMT
Dependencies Scanned : 103 (56 unique)
Vulnerable Dependencies : 5
Vulnerabilities Found : 52
Vulnerabilities Suppressed : 0
...
NVD API Last Checked : 2026-09-13T00:18:53Z
NVD API Last Modified : 2026-09-13T00:17:07Z
Summary
Summary of Vulnerable Dependencies (click to show all)
caffeine-3.2.4.jar
Description:
A high performance caching library
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.4/caffeine-3.2.4.jar
MD5: 04d655feb58be297a86fa2814a1f1ef8
SHA1: c63b303adf59c733d2a96125ad6670e938a2c15d
SHA256: 9d9d2cfd681fd9272ded3d27c9930db12f89f732345975aa113ebc223bbf1224
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
caffeine-3.2.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-tomcat10@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name caffeine High
Vendor jar package name cache Highest
Vendor jar package name caffeine Highest
Vendor jar package name github Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Vendor pom artifactid caffeine Highest
Vendor pom artifactid caffeine Low
Vendor pom developer email ben.manes@gmail.com Low
Vendor pom developer id ben-manes Medium
Vendor pom developer name Ben Manes Medium
Vendor pom groupid com.github.ben-manes.caffeine Highest
Vendor pom name Caffeine cache High
Vendor pom url ben-manes/caffeine Highest
Product file name caffeine High
Product jar package name cache Highest
Product jar package name caffeine Highest
Product jar package name github Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium
Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Product Manifest Implementation-Title A high performance caching library High
Product pom artifactid caffeine Highest
Product pom developer email ben.manes@gmail.com Low
Product pom developer id ben-manes Low
Product pom developer name Ben Manes Low
Product pom groupid com.github.ben-manes.caffeine Highest
Product pom name Caffeine cache High
Product pom url ben-manes/caffeine High
Version file version 3.2.4 High
Version Manifest Bundle-Version 3.2.4 High
Version Manifest Implementation-Version 3.2.4 High
Version pom version 3.2.4 Highest
pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.4
(Confidence :High)
checker-qual-4.2.3.jar
Description:
checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.
License:
The MIT License: https://opensource.org/licenses/MIT
File Path: /home/runner/.m2/repository/org/checkerframework/checker-qual/4.2.3/checker-qual-4.2.3.jar
MD5: d9e63a451931be32bd29cfc3ac5674c1
SHA1: d2a10af5c8574adfe24f5e35ff56cca92af2e916
SHA256: f868f731f6e37db3e1c2140d06016477989959a2d13fc5bed9c46760cffd5ba0
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
checker-qual-4.2.3.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.hazendaz.jmockit/jmockit@2.3.0
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checkerframework Highest
Vendor jar package name framework Highest
Vendor jar package name qual Highest
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Vendor pom artifactid checker-qual Highest
Vendor pom artifactid checker-qual Low
Vendor pom developer email mernst@cs.washington.edu Low
Vendor pom developer email smillst@cs.washington.edu Low
Vendor pom developer id mernst Medium
Vendor pom developer id smillst Medium
Vendor pom developer name Michael Ernst Medium
Vendor pom developer name Suzanne Millstein Medium
Vendor pom developer org University of Washington Medium
Vendor pom developer org URL https://www.cs.washington.edu/ Medium
Vendor pom groupid org.checkerframework Highest
Vendor pom name Checker Qual High
Vendor pom url https://checkerframework.org/ Highest
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checkerframework Highest
Product jar package name framework Highest
Product jar package name qual Highest
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Product pom artifactid checker-qual Highest
Product pom developer email mernst@cs.washington.edu Low
Product pom developer email smillst@cs.washington.edu Low
Product pom developer id mernst Low
Product pom developer id smillst Low
Product pom developer name Michael Ernst Low
Product pom developer name Suzanne Millstein Low
Product pom developer org University of Washington Low
Product pom developer org URL https://www.cs.washington.edu/ Low
Product pom groupid org.checkerframework Highest
Product pom name Checker Qual High
Product pom url https://checkerframework.org/ Medium
Version file version 4.2.3 High
Version Manifest Bundle-Version 4.2.3 High
Version Manifest Implementation-Version 4.2.3 High
Version pom version 4.2.3 Highest
pkg:maven/org.checkerframework/checker-qual@4.2.3
(Confidence :High)
com.github.waffle:waffle-jna-jakarta:3.6.1-SNAPSHOT
Description:
WAFFLE JNA Jakarta Pakage implementation
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-jna-jakarta/pom.xml
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta
waffle-demo-form-jakarta
waffle-demo-jaas-jakarta
waffle-demo-mixed-jakarta
waffle-demo-mixed-post-jakarta
waffle-demo-negotiate-jakarta
waffle-demo-spring-boot-filter3
waffle-demo-spring-boot-filter4
waffle-demo-spring-filter-jakarta
waffle-demo-spring-form-jakarta
com.github.waffle:waffle-jna-jakarta:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-form-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-jaas-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-jna-jakarta Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-jna-jakarta Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-boot-autoconfigure3:3.6.1-SNAPSHOT
Description:
Spring Boot 3 Autoconfigure for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot3/waffle-spring-boot-autoconfigure3/pom.xml
Referenced In Project/Scope: waffle-demo-spring-boot-filter3
com.github.waffle:waffle-spring-boot-autoconfigure3:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-boot-autoconfigure3 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-boot-autoconfigure3 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure3@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-boot-autoconfigure4:3.6.1-SNAPSHOT
Description:
Spring Boot 4 Autoconfigure for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot4/waffle-spring-boot-autoconfigure4/pom.xml
Referenced In Project/Scope: waffle-demo-spring-boot-filter4
com.github.waffle:waffle-spring-boot-autoconfigure4:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-boot-autoconfigure4 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-boot-autoconfigure4 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-boot-starter3:3.6.1-SNAPSHOT
Description:
Spring Boot 3 Starter for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot3/waffle-spring-boot-starter3/pom.xml
Referenced In Project/Scope: waffle-demo-spring-boot-filter3
com.github.waffle:waffle-spring-boot-starter3:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-boot-starter3 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-boot-starter3 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-boot-starter3@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-boot-starter4:3.6.1-SNAPSHOT
Description:
Spring Boot 4 Starter for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot4/waffle-spring-boot-starter4/pom.xml
Referenced In Project/Scope: waffle-demo-spring-boot-filter4
com.github.waffle:waffle-spring-boot-starter4:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-boot-starter4 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-boot-starter4 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-security6:3.6.1-SNAPSHOT
Description:
Spring Security 6 integration for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-security6/pom.xml
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3
waffle-demo-spring-filter-jakarta
waffle-demo-spring-form-jakarta
com.github.waffle:waffle-spring-security6:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-security6 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-security6 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-security7:3.6.1-SNAPSHOT
Description:
Spring Security 7 integration for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-security7/pom.xml
Referenced In Project/Scope: waffle-demo-spring-boot-filter4
com.github.waffle:waffle-spring-security7:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-security7 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-security7 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-security7@3.6.1-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-tomcat10:3.6.1-SNAPSHOT
Description:
Tomcat 10 integration for WAFFLE
License:
MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-tomcat10/pom.xml
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta
waffle-demo-mixed-jakarta
waffle-demo-mixed-post-jakarta
waffle-demo-negotiate-jakarta
com.github.waffle:waffle-tomcat10:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-tomcat10 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-tomcat10 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-tomcat10@3.6.1-SNAPSHOT
(Confidence :Highest)
commons-logging-1.3.6.jar
Description:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well-known logging systems.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.3.6/commons-logging-1.3.6.jar
MD5: fe0ccbe8971fed954a0ad6528fe3ef24
SHA1: 63e78ca6cd446c0ad166d14f03ed99e7efb3896d
SHA256: f8ead8943401081dea0aa824b5b1ba40a0e4ed297a572a0f02258150a0b62357
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
commons-logging-1.3.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name commons-logging High
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name logging Highest
Vendor Manifest automatic-module-name org.apache.commons.logging Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-logging Highest
Vendor pom artifactid commons-logging Low
Vendor pom developer email baliuka@apache.org Low
Vendor pom developer email costin@apache.org Low
Vendor pom developer email craigmcc@apache.org Low
Vendor pom developer email dennisl@apache.org Low
Vendor pom developer email donaldp@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email morgand@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email rsitze@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer email skitching@apache.org Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer id baliuka Medium
Vendor pom developer id bstansberry Medium
Vendor pom developer id costin Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id dennisl Medium
Vendor pom developer id donaldp Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id morgand Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rsitze Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id skitching Medium
Vendor pom developer id tn Medium
Vendor pom developer name Brian Stansberry Medium
Vendor pom developer name Costin Manolache Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name Dennis Lundberg Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Juozas Baliuka Medium
Vendor pom developer name Morgan Delagrange Medium
Vendor pom developer name Peter Donald Medium
Vendor pom developer name Richard Sitze Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Simon Kitching Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer org Apache Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-logging Highest
Vendor pom name Apache Commons Logging High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-logging/ Highest
Product file name commons-logging High
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name logging Highest
Product Manifest automatic-module-name org.apache.commons.logging Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Product Manifest Bundle-Name Apache Commons Logging Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Product Manifest Implementation-Title Apache Commons Logging High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Logging Medium
Product pom artifactid commons-logging Highest
Product pom developer email baliuka@apache.org Low
Product pom developer email costin@apache.org Low
Product pom developer email craigmcc@apache.org Low
Product pom developer email dennisl@apache.org Low
Product pom developer email donaldp@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email morgand@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email rsitze@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer email skitching@apache.org Low
Product pom developer email tn@apache.org Low
Product pom developer id baliuka Low
Product pom developer id bstansberry Low
Product pom developer id costin Low
Product pom developer id craigmcc Low
Product pom developer id dennisl Low
Product pom developer id donaldp Low
Product pom developer id ggregory Low
Product pom developer id morgand Low
Product pom developer id rdonkin Low
Product pom developer id rsitze Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id skitching Low
Product pom developer id tn Low
Product pom developer name Brian Stansberry Low
Product pom developer name Costin Manolache Low
Product pom developer name Craig McClanahan Low
Product pom developer name Dennis Lundberg Low
Product pom developer name Gary Gregory Low
Product pom developer name Juozas Baliuka Low
Product pom developer name Morgan Delagrange Low
Product pom developer name Peter Donald Low
Product pom developer name Richard Sitze Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Simon Kitching Low
Product pom developer name Thomas Neidhart Low
Product pom developer org Apache Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-logging Highest
Product pom name Apache Commons Logging High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-logging/ Medium
Version file version 1.3.6 High
Version Manifest Bundle-Version 1.3.6 High
Version Manifest Implementation-Version 1.3.6 High
Version pom parent-version 1.3.6 Low
Version pom version 1.3.6 Highest
pkg:maven/commons-logging/commons-logging@1.3.6
(Confidence :High)
commons-logging-1.4.0.jar
Description:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well-known logging systems.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.4.0/commons-logging-1.4.0.jar
MD5: 954e27d33e55e587a4694d5952a0c5c6
SHA1: e8f6313365dfa0580e49c58837afc8caa9b4ce05
SHA256: d175dbd751dd782a63bde28c7a039520e971f25e84b79c19b8435edc3603e0dc
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
commons-logging-1.4.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-spring-boot-starter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name commons-logging High
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name logging Highest
Vendor Manifest automatic-module-name org.apache.commons.logging Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-logging Highest
Vendor pom artifactid commons-logging Low
Vendor pom developer email baliuka@apache.org Low
Vendor pom developer email costin@apache.org Low
Vendor pom developer email craigmcc@apache.org Low
Vendor pom developer email dennisl@apache.org Low
Vendor pom developer email donaldp@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email morgand@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email rsitze@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer email skitching@apache.org Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer id baliuka Medium
Vendor pom developer id bstansberry Medium
Vendor pom developer id costin Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id dennisl Medium
Vendor pom developer id donaldp Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id morgand Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rsitze Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id skitching Medium
Vendor pom developer id tn Medium
Vendor pom developer name Brian Stansberry Medium
Vendor pom developer name Costin Manolache Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name Dennis Lundberg Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Juozas Baliuka Medium
Vendor pom developer name Morgan Delagrange Medium
Vendor pom developer name Peter Donald Medium
Vendor pom developer name Richard Sitze Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Simon Kitching Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer org Apache Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-logging Highest
Vendor pom name Apache Commons Logging High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-logging/ Highest
Product file name commons-logging High
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name logging Highest
Product Manifest automatic-module-name org.apache.commons.logging Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Product Manifest Bundle-Name Apache Commons Logging Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Product Manifest Implementation-Title Apache Commons Logging High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Logging Medium
Product pom artifactid commons-logging Highest
Product pom developer email baliuka@apache.org Low
Product pom developer email costin@apache.org Low
Product pom developer email craigmcc@apache.org Low
Product pom developer email dennisl@apache.org Low
Product pom developer email donaldp@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email morgand@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email rsitze@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer email skitching@apache.org Low
Product pom developer email tn@apache.org Low
Product pom developer id baliuka Low
Product pom developer id bstansberry Low
Product pom developer id costin Low
Product pom developer id craigmcc Low
Product pom developer id dennisl Low
Product pom developer id donaldp Low
Product pom developer id ggregory Low
Product pom developer id morgand Low
Product pom developer id rdonkin Low
Product pom developer id rsitze Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id skitching Low
Product pom developer id tn Low
Product pom developer name Brian Stansberry Low
Product pom developer name Costin Manolache Low
Product pom developer name Craig McClanahan Low
Product pom developer name Dennis Lundberg Low
Product pom developer name Gary Gregory Low
Product pom developer name Juozas Baliuka Low
Product pom developer name Morgan Delagrange Low
Product pom developer name Peter Donald Low
Product pom developer name Richard Sitze Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Simon Kitching Low
Product pom developer name Thomas Neidhart Low
Product pom developer org Apache Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-logging Highest
Product pom name Apache Commons Logging High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-logging/ Medium
Version file version 1.4.0 High
Version Manifest Bundle-Version 1.4.0 High
Version Manifest Implementation-Version 1.4.0 High
Version pom parent-version 1.4.0 Low
Version pom version 1.4.0 Highest
pkg:maven/commons-logging/commons-logging@1.4.0
(Confidence :High)
error_prone_annotations-2.50.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/errorprone/error_prone_annotations/2.50.0/error_prone_annotations-2.50.0.jar
MD5: 1ded1848cfd4f5167e00824faf9c4d3b
SHA1: 74ba43e49ab1184d41634af2ef0047e82c4064b0
SHA256: 4667724877f1d37a689202da191e23efa7657c62eef93ccdac406eccfe5cdd0a
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:provided
waffle-demo-form-jakarta:provided
waffle-demo-jaas-jakarta:provided
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-parent-jakarta:provided
waffle-demo-spring-boot-filter3:provided
waffle-demo-spring-boot-filter4:provided
waffle-demo-spring-filter-jakarta:provided
waffle-demo-spring-form-jakarta:provided
error_prone_annotations-2.50.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-form-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-jaas-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-parent-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Highest
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.50.0 High
Version Manifest Bundle-Version 2.50.0 High
Version pom version 2.50.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.50.0
(Confidence :High)
j2objc-annotations-3.1.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/j2objc/j2objc-annotations/3.1/j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256: 84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:provided
waffle-demo-form-jakarta:provided
waffle-demo-jaas-jakarta:provided
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-parent-jakarta:provided
waffle-demo-spring-boot-filter3:provided
waffle-demo-spring-boot-filter4:provided
waffle-demo-spring-filter-jakarta:provided
waffle-demo-spring-form-jakarta:provided
j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-form-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-jaas-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-parent-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor jar package name annotations Highest
Vendor jar package name google Highest
Vendor jar package name j2objc Highest
Vendor Manifest build-jdk-spec 22 Low
Vendor Manifest multi-release true Low
Vendor pom artifactid j2objc-annotations Highest
Vendor pom artifactid j2objc-annotations Low
Vendor pom developer email tball@google.com Low
Vendor pom developer id tomball Medium
Vendor pom developer name Tom Ball Medium
Vendor pom developer org Google Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product jar package name annotations Highest
Product jar package name google Highest
Product jar package name j2objc Highest
Product Manifest build-jdk-spec 22 Low
Product Manifest multi-release true Low
Product pom artifactid j2objc-annotations Highest
Product pom developer email tball@google.com Low
Product pom developer id tomball Low
Product pom developer name Tom Ball Low
Product pom developer org Google Low
Product pom developer org URL https://www.google.com Low
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 3.1 High
Version pom version 3.1 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@3.1
(Confidence :High)
jackson-annotations-2.21.jar
Description:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.21/jackson-annotations-2.21.jar
MD5: e0d0c3e7300954f73e43c67d933aaea4
SHA1: b1bc1868bf02dc0bd6c7836257a036a331005309
SHA256: 53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
jackson-annotations-2.21.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-annotations High
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-annotations Highest
Vendor pom artifactid jackson-annotations Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-annotations High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest specification-title Jackson-annotations Medium
Product pom artifactid jackson-annotations Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-annotations High
Product pom parent-artifactid jackson-parent Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.21 High
Version Manifest Implementation-Version 2.21 High
Version pom version 2.21 Highest
jackson-core-2.21.4.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.21.4/jackson-core-2.21.4.jar
MD5: 2f3d2557bb48afa00fe924c9689ab3b6
SHA1: 56a503ba45016714394807ea89f95f5093760089
SHA256: 4b40a06396f239f8de2da57419adde6e94e5edc18a2171d471ea05eeed4e5c2d
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
jackson-core-2.21.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name com Highest
Vendor jar package name core Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Highest
Vendor pom artifactid jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name base Highest
Product jar package name com Highest
Product jar package name core Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 2.21.4 High
Version Manifest Bundle-Version 2.21.4 High
Version Manifest Implementation-Version 2.21.4 High
Version pom version 2.21.4 Highest
jackson-core-3.1.5.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/tools/jackson/core/jackson-core/3.1.5/jackson-core-3.1.5.jar
MD5: ed1c26680ceec80183239a74ef15a838
SHA1: ccd7eb3269b8d33bc097b36770f367cdfe2f1150
SHA256: 9431b7fa2673bbb618c11d865fe15e13222fd182a214ff998cb7e56afd8f35d2
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
jackson-core-3.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name core Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor jar package name tools Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname tools.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id tools.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Highest
Vendor pom artifactid jackson-core Low
Vendor pom developer email tatu@fasterxml.com Low
Vendor pom developer id cowtowncoder Medium
Vendor pom developer name Tatu Saloranta Medium
Vendor pom groupid tools.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid tools.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product jar package name 21 Highest
Product jar package name base Highest
Product jar package name core Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product jar package name tools Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname tools.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom developer email tatu@fasterxml.com Low
Product pom developer id cowtowncoder Low
Product pom developer name Tatu Saloranta Low
Product pom groupid tools.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid tools.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 3.1.5 High
Version Manifest Bundle-Version 3.1.5 High
Version Manifest Implementation-Version 3.1.5 High
Version pom version 3.1.5 Highest
jackson-databind-2.21.4.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.21.4/jackson-databind-2.21.4.jar
MD5: 99769ad660a66c43caee5d539d19ed96
SHA1: 09e495680be707d466527d734368ebf36e464da2
SHA256: 3888e9e69ab66fbacaacc9aea0e9ffbf15368288e4aca468b024dba11c09fbf9
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
jackson-databind-2.21.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Highest
Vendor pom artifactid jackson-databind Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name databind Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest multi-release true Low
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.21.4 High
Version Manifest Bundle-Version 2.21.4 High
Version Manifest Implementation-Version 2.21.4 High
Version pom version 2.21.4 Highest
CVE-2026-54515 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
jackson-databind-3.1.5.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/tools/jackson/core/jackson-databind/3.1.5/jackson-databind-3.1.5.jar
MD5: 7b399cbb2bea1429c46c1b8c73af42b9
SHA1: 782178f0b1fe088803c03b85eb9a406f60519044
SHA256: 3a2338d996fd3056791df8d335fa9ba8a62a706ed4245ecf81b3e583df37d08a
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
jackson-databind-3.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name jackson Highest
Vendor jar package name tools Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname tools.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id tools.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Highest
Vendor pom artifactid jackson-databind Low
Vendor pom groupid tools.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid tools.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product jar package name databind Highest
Product jar package name jackson Highest
Product jar package name tools Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname tools.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid tools.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid tools.jackson Medium
Product pom url FasterXML/jackson High
Version file version 3.1.5 High
Version Manifest Bundle-Version 3.1.5 High
Version Manifest Implementation-Version 3.1.5 High
Version pom version 3.1.5 Highest
jackson-datatype-jdk8-2.21.4.jar
Description:
Add-on module for Jackson (https://github.com/FasterXML/jackson) to support
JDK 8 data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.21.4/jackson-datatype-jdk8-2.21.4.jar
MD5: 282ec253ef93128ef2df436f02971b98
SHA1: 0a1b9fe3b6e8d4418fe09a1ba9a8f6640137cfb5
SHA256: 2dde4a8f1aad3306c040f56ff40da81c6d58dcef3434c00849c9bce09f56a074
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
jackson-datatype-jdk8-2.21.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name jackson-datatype-jdk8 High
Vendor jar package name datatype Highest
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor jar package name jdk8 Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-datatype-jdk8 Highest
Vendor pom artifactid jackson-datatype-jdk8 Low
Vendor pom groupid com.fasterxml.jackson.datatype Highest
Vendor pom name Jackson datatype: jdk8 High
Vendor pom parent-artifactid jackson-modules-java8 Low
Vendor pom parent-groupid com.fasterxml.jackson.module Medium
Product file name jackson-datatype-jdk8 High
Product jar package name datatype Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product jar package name jdk8 Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low
Product Manifest Bundle-Name Jackson datatype: jdk8 Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium
Product Manifest Implementation-Title Jackson datatype: jdk8 High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson datatype: jdk8 Medium
Product pom artifactid jackson-datatype-jdk8 Highest
Product pom groupid com.fasterxml.jackson.datatype Highest
Product pom name Jackson datatype: jdk8 High
Product pom parent-artifactid jackson-modules-java8 Medium
Product pom parent-groupid com.fasterxml.jackson.module Medium
Version file version 2.21.4 High
Version Manifest Bundle-Version 2.21.4 High
Version Manifest Implementation-Version 2.21.4 High
Version pom version 2.21.4 Highest
Related Dependencies
jackson-datatype-jsr310-2.21.4.jar
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jsr310/2.21.4/jackson-datatype-jsr310-2.21.4.jar
MD5: 8d64e799458e78f5d46765da252270fa
SHA1: 51f9ede30826b05cdf8a70b47bc68bd6271dfaaa
SHA256: d1ac4b98b70304e56448423589fde5e775b100889643ad1ead62cc7811633684
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.4
jackson-module-parameter-names-2.21.4.jar
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/module/jackson-module-parameter-names/2.21.4/jackson-module-parameter-names-2.21.4.jar
MD5: 525a10fe688f472c821e5779155e6023
SHA1: 5f1439ff7bebf7601e12a9ee7919b81ab9cb7c78
SHA256: 9510f91a4be2c700753ad244596b67424cb32c23659db1dc534219226e5df3a3
pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.21.4
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.21.4
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.4:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jakarta.annotation-api-2.1.1.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/annotation/jakarta.annotation-api/2.1.1/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
jakarta.annotation-api-2.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Highest
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 2.1.1 High
Version Manifest Bundle-Version 2.1.1 High
Version Manifest Implementation-Version 2.1.1 High
Version pom parent-version 2.1.1 Low
Version pom version 2.1.1 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1
(Confidence :High)
jakarta.annotation-api-3.0.0.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: https://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/annotation/jakarta.annotation-api/3.0.0/jakarta.annotation-api-3.0.0.jar
MD5: 7faffaab962918da4cf5ddfd76609dd2
SHA1: 54f928fadec906a99d558536756d171917b9d936
SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
jakarta.annotation-api-3.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 18 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Highest
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 18 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 3.0.0 High
Version Manifest Bundle-Version 3.0.0 High
Version Manifest Implementation-Version 3.0.0 High
Version pom parent-version 3.0.0 Low
Version pom version 3.0.0 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@3.0.0
(Confidence :High)
jakarta.servlet-api-6.1.0.jar
Description:
Jakarta Servlet 6.1
License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jakarta.servlet-api/6.1.0/jakarta.servlet-api-6.1.0.jar
MD5: 314c930b3e40ac1abc3529c7c9942f09
SHA1: 1169a246913fe3823782af7943e7a103634867c5
SHA256: 8a31f465f3593bf2351531a5c952014eb839da96a605b5825b93dd54714c48c4
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:provided
waffle-demo-form-jakarta:provided
waffle-demo-jaas-jakarta:provided
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-parent-jakarta:provided
waffle-demo-spring-boot-filter3:provided
waffle-demo-spring-boot-filter4:provided
waffle-demo-spring-filter-jakarta:provided
waffle-demo-spring-form-jakarta:provided
jakarta.servlet-api-6.1.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-form-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-jaas-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-parent-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.servlet-api High
Vendor jar package name jakarta Highest
Vendor jar package name servlet Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.servlet-api Medium
Vendor Manifest extension-name jakarta.servlet Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.eclipse Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.servlet-api Highest
Vendor pom artifactid jakarta.servlet-api Low
Vendor pom developer id yaminikb Medium
Vendor pom developer name Yamini K B Medium
Vendor pom developer org Oracle Corporation Medium
Vendor pom developer org URL http://www.oracle.com/ Medium
Vendor pom groupid jakarta.servlet Highest
Vendor pom name Jakarta Servlet High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.servlet Highest
Product file name jakarta.servlet-api High
Product jar package name jakarta Highest
Product jar package name servlet Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Servlet Medium
Product Manifest bundle-symbolicname jakarta.servlet-api Medium
Product Manifest extension-name jakarta.servlet Medium
Product pom artifactid jakarta.servlet-api Highest
Product pom developer id yaminikb Low
Product pom developer name Yamini K B Low
Product pom developer org Oracle Corporation Low
Product pom developer org URL http://www.oracle.com/ Low
Product pom groupid jakarta.servlet Highest
Product pom name Jakarta Servlet High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.servlet Medium
Version file version 6.1.0 High
Version Manifest Bundle-Version 6.1.0 High
Version Manifest Implementation-Version 6.1.0 High
Version pom parent-version 6.1.0 Low
Version pom version 6.1.0 Highest
pkg:maven/jakarta.servlet/jakarta.servlet-api@6.1.0
(Confidence :High)
jna-5.19.1.jar
Description:
Java Native Access
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar
MD5: cf327da3e9cf5a5d77c8a43540320929
SHA1: ca303052cd617c1af2e2c8d344c98a706fb63143
SHA256: 4fb141dd8ef6b0585ffceea4bc49602fbc6312fa977e2c488794ea3e6aafecae
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
jna-5.19.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-tomcat10@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna High
Vendor jar package name jna Highest
Vendor jar package name native Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna Medium
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=sparcv9;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=aarch64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname com.sun.jna Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna Highest
Vendor pom artifactid jna Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access High
Vendor pom url java-native-access/jna Highest
Product file name jna High
Product jar package name jna Highest
Product jar package name library Highest
Product jar package name native Highest
Product jar package name sun Highest
Product jar package name win32 Highest
Product Manifest automatic-module-name com.sun.jna Medium
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna Medium
Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=sparcv9;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=aarch64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname com.sun.jna Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access High
Product pom url java-native-access/jna High
Version file version 5.19.1 High
Version Manifest Bundle-Version 5.19.1 High
Version pom version 5.19.1 Highest
pkg:maven/net.java.dev.jna/jna@5.19.1
(Confidence :High)
jna-5.19.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256: b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.19.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256: 5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.19.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256: 752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-platform-5.19.1.jar
Description:
Java Native Access Platform
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna-platform/5.19.1/jna-platform-5.19.1.jar
MD5: 1d97b6103a9b3b7ddb671908683f4566
SHA1: d1e54d9231da5ca3fa730d52960deaa555475468
SHA256: 3b3864f5b449e9c3c24b16861524b622b086563f44e0cd8384c8efc5a6052f82
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
jna-platform-5.19.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-tomcat10@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna-platform High
Vendor jar package name jna Highest
Vendor jar package name platform Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna.platform Medium
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna-platform Highest
Vendor pom artifactid jna-platform Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access Platform High
Vendor pom url java-native-access/jna Highest
Product file name jna-platform High
Product jar package name jna Highest
Product jar package name platform Highest
Product jar package name sun Highest
Product Manifest automatic-module-name com.sun.jna.platform Medium
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna-platform Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Product Manifest bundle-symbolicname com.sun.jna.platform Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna-platform Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access Platform High
Product pom url java-native-access/jna High
Version file version 5.19.1 High
Version Manifest Bundle-Version 5.19.1 High
Version pom version 5.19.1 Highest
pkg:maven/net.java.dev.jna/jna-platform@5.19.1
(Confidence :High)
jspecify-1.0.0.jar
Description:
An artifact of well-named and well-specified annotations to power static analysis checks
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.4
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.1.3
Evidence
Type Source Name Value Confidence
Vendor file name jspecify High
Vendor jar package name annotations Highest
Vendor jar package name jspecify Highest
Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jspecify Highest
Vendor pom artifactid jspecify Low
Vendor pom developer email kevinb9n@gmail.com Low
Vendor pom developer id kevinb9n Medium
Vendor pom developer name Kevin Bourrillion Medium
Vendor pom groupid org.jspecify Highest
Vendor pom name JSpecify annotations High
Vendor pom url http://jspecify.org/ Highest
Product file name jspecify High
Product jar package name annotations Highest
Product jar package name jspecify Highest
Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Product Manifest Bundle-Name JSpecify annotations Medium
Product Manifest bundle-symbolicname org.jspecify.jspecify Medium
Product Manifest multi-release true Low
Product pom artifactid jspecify Highest
Product pom developer email kevinb9n@gmail.com Low
Product pom developer id kevinb9n Low
Product pom developer name Kevin Bourrillion Low
Product pom groupid org.jspecify Highest
Product pom name JSpecify annotations High
Product pom url http://jspecify.org/ Medium
Version file version 1.0.0 High
Version Manifest Bundle-Version 1.0.0 High
Version Manifest Implementation-Version 1.0.0 High
Version pom version 1.0.0 Highest
pkg:maven/org.jspecify/jspecify@1.0.0
(Confidence :High)
jspecify-1.0.1.jar
Description:
An artifact of well-named and well-specified annotations to power static analysis checks
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.1/jspecify-1.0.1.jar
MD5: d4fe1ea4d953b66fcb1d6043c22bffcf
SHA1: 3d60fd98eb8ade73004f4195c37b6317e02cf3d7
SHA256: 070d75f261fe4c5b8202508366715f7f2d4660f88c8ef7e6d3575e48c9683b66
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
jspecify-1.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.3
Evidence
Type Source Name Value Confidence
Vendor file name jspecify High
Vendor jar package name annotations Highest
Vendor jar package name jspecify Highest
Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium
Vendor pom artifactid jspecify Highest
Vendor pom artifactid jspecify Low
Vendor pom developer email cpovirk@google.com Low
Vendor pom developer email dpb@google.com Low
Vendor pom developer email kevinb9n@gmail.com Low
Vendor pom developer id cpovirk Medium
Vendor pom developer id kevinb9n Medium
Vendor pom developer id netdpb Medium
Vendor pom developer name Chris Povirk Medium
Vendor pom developer name David P. Baker Medium
Vendor pom developer name Kevin Bourrillion Medium
Vendor pom developer org Google Medium
Vendor pom groupid org.jspecify Highest
Vendor pom name JSpecify annotations High
Vendor pom url https://jspecify.dev/ Highest
Product file name jspecify High
Product jar package name annotations Highest
Product jar package name jspecify Highest
Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Product Manifest Bundle-Name JSpecify annotations Medium
Product Manifest bundle-symbolicname org.jspecify.jspecify Medium
Product pom artifactid jspecify Highest
Product pom developer email cpovirk@google.com Low
Product pom developer email dpb@google.com Low
Product pom developer email kevinb9n@gmail.com Low
Product pom developer id cpovirk Low
Product pom developer id kevinb9n Low
Product pom developer id netdpb Low
Product pom developer name Chris Povirk Low
Product pom developer name David P. Baker Low
Product pom developer name Kevin Bourrillion Low
Product pom developer org Google Low
Product pom groupid org.jspecify Highest
Product pom name JSpecify annotations High
Product pom url https://jspecify.dev/ Medium
Version file version 1.0.1 High
Version Manifest Bundle-Version 1.0.1 High
Version Manifest Implementation-Version 1.0.1 High
Version pom version 1.0.1 Highest
pkg:maven/org.jspecify/jspecify@1.0.1
(Confidence :High)
cpe:2.3:a:google:gmail:1.0.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:provided
waffle-demo-form-jakarta:provided
waffle-demo-jaas-jakarta:provided
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-parent-jakarta:provided
waffle-demo-spring-boot-filter3:provided
waffle-demo-spring-boot-filter4:provided
waffle-demo-spring-filter-jakarta:provided
waffle-demo-spring-form-jakarta:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.10.4
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Highest
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
jul-to-slf4j-2.0.18.jar
Description:
JUL to SLF4J bridge
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/jul-to-slf4j/2.0.18/jul-to-slf4j-2.0.18.jar
MD5: f339bf7648049b2105e180cab6c45c9d
SHA1: 79739c98001d5c9d078d087d5a348ec9e474ec8f
SHA256: cbb7d1aaaa9e871eb1a06594abd911bf97027152976edf1edc315be75239204e
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
jul-to-slf4j-2.0.18.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
pkg:maven/org.springframework.boot/spring-boot-starter@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name jul-to-slf4j High
Vendor jar package name bridge Highest
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname jul.to.slf4j Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jul-to-slf4j Highest
Vendor pom artifactid jul-to-slf4j Low
Vendor pom groupid org.slf4j Highest
Vendor pom name JUL to SLF4J bridge High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name jul-to-slf4j High
Product jar package name bridge Highest
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name JUL to SLF4J bridge Medium
Product Manifest bundle-symbolicname jul.to.slf4j Medium
Product Manifest Implementation-Title jul-to-slf4j High
Product Manifest multi-release true Low
Product pom artifactid jul-to-slf4j Highest
Product pom groupid org.slf4j Highest
Product pom name JUL to SLF4J bridge High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.18 High
Version Manifest Bundle-Version 2.0.18 High
Version Manifest Implementation-Version 2.0.18 High
Version pom version 2.0.18 Highest
pkg:maven/org.slf4j/jul-to-slf4j@2.0.18
(Confidence :High)
log4j-api-2.26.1.jar
Description:
The logging API of the Log4j project.
Library and application code can log through this API.
It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core.
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-api/2.26.1/log4j-api-2.26.1.jar
MD5: 8ed35fc9ea449bc9e21a8139842d6233
SHA1: b9864ed8d0c01f65f3b0bf70f1447e5cc1b49c24
SHA256: f1810a4704ccce019d02bba029dc02a4f2ac0c997f647b465e7d409c1927f822
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
log4j-api-2.26.1.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
pkg:maven/org.springframework.boot/spring-boot-starter@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name log4j-api High
Vendor jar package name apache Highest
Vendor jar package name log4j Highest
Vendor jar package name logging Highest
Vendor jar package name org Highest
Vendor jar package name simple Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid log4j-api Highest
Vendor pom artifactid log4j-api Low
Vendor pom groupid org.apache.logging.log4j Highest
Vendor pom name Apache Log4j API High
Vendor pom parent-artifactid log4j Low
Vendor pom url https://logging.apache.org/log4j/2.x/ Highest
Product file name log4j-api High
Product jar package name apache Highest
Product jar package name log4j Highest
Product jar package name logging Highest
Product jar package name org Highest
Product jar package name simple Highest
Product jar package name util Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest Bundle-Name Apache Log4j API Medium
Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium
Product Manifest Implementation-Title Apache Log4j API High
Product Manifest multi-release true Low
Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low
Product Manifest specification-title Apache Log4j API Medium
Product pom artifactid log4j-api Highest
Product pom groupid org.apache.logging.log4j Highest
Product pom name Apache Log4j API High
Product pom parent-artifactid log4j Medium
Product pom url https://logging.apache.org/log4j/2.x/ Medium
Version file version 2.26.1 High
Version Manifest Bundle-Version 2.26.1 High
Version Manifest Implementation-Version 2.26.1 High
Version pom version 2.26.1 Highest
Related Dependencies
log4j-to-slf4j-2.26.1.jar
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-to-slf4j/2.26.1/log4j-to-slf4j-2.26.1.jar
MD5: 61ffbed0e2c7adae88871b0013b7a69f
SHA1: a5100727b898c513fda177a4f388299a5fe5955f
SHA256: 6b10bc838a3c773b3fd02979c7ef4e7a443371fa89bda4415d89099bbee224df
pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.26.1
logback-core-1.5.34.jar
Description:
logback-core module
License:
https://www.eclipse.org/legal/epl-v20.html, https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-core/1.5.34/logback-core-1.5.34.jar
MD5: ef459237a22ab546dd001ff612dce80d
SHA1: 378692f76c337b3325c15bffb89e013dc1f897b4
SHA256: 42eda264c0c650c2bec59e66151a88b708a8663dc1b49d788202d53e78b8caae
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
logback-core-1.5.34.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/ch.qos.logback/logback-classic@1.6.3
Evidence
Type Source Name Value Confidence
Vendor file name logback-core High
Vendor jar package name ch Highest
Vendor jar package name core Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-core Highest
Vendor pom artifactid logback-core Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Core Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-core High
Product jar package name 21 Highest
Product jar package name ch Highest
Product jar package name core Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Core Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest Implementation-Title Logback Core Module High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Logback Core Module Medium
Product pom artifactid logback-core Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Core Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.5.34 High
Version Manifest Bundle-Version 1.5.34 High
Version Manifest Implementation-Version 1.5.34 High
Version pom version 1.5.34 Highest
logback-core-1.5.38.jar
Description:
logback-core module
License:
https://www.eclipse.org/legal/epl-v20.html, https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-core/1.5.38/logback-core-1.5.38.jar
MD5: a065b3893602a19f6f393a42c499c198
SHA1: 7b1d133b29bf42ff268cf3f71d1308b80480fb8d
SHA256: a855a0fc97b1d06f4efb1c3bba5ebd0eb508d8b58e68e89e4bbc23a85135c883
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
logback-core-1.5.38.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/ch.qos.logback/logback-classic@1.6.3
Evidence
Type Source Name Value Confidence
Vendor file name logback-core High
Vendor jar package name ch Highest
Vendor jar package name core Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-core Highest
Vendor pom artifactid logback-core Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Core Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-core High
Product jar package name ch Highest
Product jar package name core Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Core Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest Implementation-Title Logback Core Module High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Logback Core Module Medium
Product pom artifactid logback-core Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Core Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.5.38 High
Version Manifest Bundle-Version 1.5.38 High
Version Manifest Implementation-Version 1.5.38 High
Version pom version 1.5.38 Highest
logback-core-1.6.3.jar
Description:
logback-core module
License:
https://www.eclipse.org/legal/epl-v20.html, https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-core/1.6.3/logback-core-1.6.3.jar
MD5: 6d741138bccf87bb512572c44cc7f43f
SHA1: ae9a279c723035307735fc4daf527a9076ea3f77
SHA256: a6967a28c8b086dee75a694d2f6fb8830c71153539866d7d8af065c9b6df91e0
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:compile
waffle-demo-mixed-post-jakarta:compile
waffle-demo-negotiate-jakarta:compile
waffle-demo-parent-jakarta:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
logback-core-1.6.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/ch.qos.logback/logback-classic@1.6.3
Evidence
Type Source Name Value Confidence
Vendor file name logback-core High
Vendor jar package name ch Highest
Vendor jar package name core Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-core Highest
Vendor pom artifactid logback-core Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Core Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-core High
Product jar package name ch Highest
Product jar package name core Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Core Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest Implementation-Title Logback Core Module High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Logback Core Module Medium
Product pom artifactid logback-core Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Core Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.6.3 High
Version Manifest Bundle-Version 1.6.3 High
Version Manifest Implementation-Version 1.6.3 High
Version pom version 1.6.3 Highest
Related Dependencies
logback-classic-1.6.3.jar
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-classic/1.6.3/logback-classic-1.6.3.jar
MD5: c4c3210a25faea352ecfe9ea2c219c14
SHA1: a8fc332633a9da2e543afb20357b7a015437f0a9
SHA256: beebede8db065fe1b72909ecc66bb49acda618901635d86c25fce14a5915e37e
pkg:maven/ch.qos.logback/logback-classic@1.6.3
micrometer-commons-1.15.12.jar
Description:
Module containing common code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-commons/1.15.12/micrometer-commons-1.15.12.jar
MD5: 8172f342d797138ec7a1a20e0332568c
SHA1: eb539638d48571fa6ce4ea3eb8417cab37a63438
SHA256: 4b779cf7acb0534bb1f8e964f25200037ecb3944368f859a630fa637d6d5d7c0
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
micrometer-commons-1.15.12.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-commons High
Vendor jar package name common Highest
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor Manifest automatic-module-name micrometer.commons Medium
Vendor Manifest branch HEAD Low
Vendor Manifest build-date 2026-06-08_05:57:33 Low
Vendor Manifest build-date-utc 2026-06-08T05:57:33.437169978Z Low
Vendor Manifest build-host 320eea4f7654 Low
Vendor Manifest build-job deploy Low
Vendor Manifest build-number 70801 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status release Low
Vendor Manifest bundle-symbolicname micrometer-commons Medium
Vendor Manifest change dc2e5e2 Low
Vendor Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low
Vendor Manifest module-email tludwig@vmware.com Low
Vendor Manifest module-origin micrometer-metrics/micrometer.git Low
Vendor Manifest module-owner tludwig@vmware.com Low
Vendor Manifest module-source /micrometer-commons Low
Vendor pom artifactid micrometer-commons Highest
Vendor pom artifactid micrometer-commons Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id shakuzen Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-commons High
Vendor pom url micrometer-metrics/micrometer Highest
Product file name micrometer-commons High
Product jar package name common Highest
Product jar package name io Highest
Product jar package name micrometer Highest
Product Manifest automatic-module-name micrometer.commons Medium
Product Manifest branch HEAD Low
Product Manifest build-date 2026-06-08_05:57:33 Low
Product Manifest build-date-utc 2026-06-08T05:57:33.437169978Z Low
Product Manifest build-host 320eea4f7654 Low
Product Manifest build-job deploy Low
Product Manifest build-number 70801 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low
Product Manifest built-os Linux Low
Product Manifest built-status release Low
Product Manifest Bundle-Name micrometer-commons Medium
Product Manifest bundle-symbolicname micrometer-commons Medium
Product Manifest change dc2e5e2 Low
Product Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low
Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.15.12 High
Product Manifest module-email tludwig@vmware.com Low
Product Manifest module-origin micrometer-metrics/micrometer.git Low
Product Manifest module-owner tludwig@vmware.com Low
Product Manifest module-source /micrometer-commons Low
Product pom artifactid micrometer-commons Highest
Product pom developer email tludwig@vmware.com Low
Product pom developer id shakuzen Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-commons High
Product pom url micrometer-metrics/micrometer High
Version file version 1.15.12 High
Version Manifest Bundle-Version 1.15.12 High
Version Manifest Implementation-Version 1.15.12 High
Version pom version 1.15.12 Highest
pkg:maven/io.micrometer/micrometer-commons@1.15.12
(Confidence :High)
micrometer-commons-1.17.1.jar
Description:
Module containing common code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-commons/1.17.1/micrometer-commons-1.17.1.jar
MD5: aa9291ad211473834d3d48453ae05ea1
SHA1: b1c3fdea68c5a81495cf1c16cf2905c5ad9f30d2
SHA256: f2cee6ef046e72eec8128474c7f58c6217173b45ae373c30de0289f2a56ab0fd
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
micrometer-commons-1.17.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-commons High
Vendor jar package name common Highest
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor Manifest automatic-module-name micrometer.commons Medium
Vendor Manifest branch release/1.17.1 Low
Vendor Manifest build-date 2026-08-17_07:25:39 Low
Vendor Manifest build-date-utc 2026-08-17T07:25:39.516694470Z Low
Vendor Manifest build-host https://github.com Low
Vendor Manifest build-job build-release Low
Vendor Manifest build-number 50 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://github.com/micrometer-metrics/micrometer-commercial/actions/runs/32005692132 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status integration Low
Vendor Manifest bundle-symbolicname micrometer-commons Medium
Vendor Manifest change f1b1924 Low
Vendor Manifest full-change f1b1924bc8821adbc841df69eb433c933e17e1a5 Low
Vendor Manifest module-email tludwig@vmware.com,jivanov@vmware.com Low
Vendor Manifest module-origin https://github.com/micrometer-metrics/micrometer-commercial.git Low
Vendor Manifest module-owner tludwig@vmware.com,jivanov@vmware.com Low
Vendor pom artifactid micrometer-commons Highest
Vendor pom artifactid micrometer-commons Low
Vendor pom developer email jivanov@vmware.com Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id jonatan-ivanov Medium
Vendor pom developer id shakuzen Medium
Vendor pom developer name Jonatan Ivanov Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-commons High
Vendor pom url micrometer-metrics/micrometer-commercial Highest
Product file name micrometer-commons High
Product jar package name common Highest
Product jar package name io Highest
Product jar package name micrometer Highest
Product Manifest automatic-module-name micrometer.commons Medium
Product Manifest branch release/1.17.1 Low
Product Manifest build-date 2026-08-17_07:25:39 Low
Product Manifest build-date-utc 2026-08-17T07:25:39.516694470Z Low
Product Manifest build-host https://github.com Low
Product Manifest build-job build-release Low
Product Manifest build-number 50 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://github.com/micrometer-metrics/micrometer-commercial/actions/runs/32005692132 Low
Product Manifest built-os Linux Low
Product Manifest built-status integration Low
Product Manifest Bundle-Name micrometer-commons Medium
Product Manifest bundle-symbolicname micrometer-commons Medium
Product Manifest change f1b1924 Low
Product Manifest full-change f1b1924bc8821adbc841df69eb433c933e17e1a5 Low
Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.17.1 High
Product Manifest module-email tludwig@vmware.com,jivanov@vmware.com Low
Product Manifest module-origin https://github.com/micrometer-metrics/micrometer-commercial.git Low
Product Manifest module-owner tludwig@vmware.com,jivanov@vmware.com Low
Product pom artifactid micrometer-commons Highest
Product pom developer email jivanov@vmware.com Low
Product pom developer email tludwig@vmware.com Low
Product pom developer id jonatan-ivanov Low
Product pom developer id shakuzen Low
Product pom developer name Jonatan Ivanov Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-commons High
Product pom url micrometer-metrics/micrometer-commercial High
Version file version 1.17.1 High
Version Manifest Bundle-Version 1.17.1 High
Version Manifest Implementation-Version 1.17.1 High
Version pom version 1.17.1 Highest
pkg:maven/io.micrometer/micrometer-commons@1.17.1
(Confidence :High)
micrometer-observation-1.15.12.jar
Description:
Module containing Observation related code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-observation/1.15.12/micrometer-observation-1.15.12.jar
MD5: b6ea6ebf93debb874d7c10f3ae79a471
SHA1: 1d96fcaec8d2516236dfcb9914108e14bfd02238
SHA256: 54483e68ed44af1bb0c36d1df2235d36f233e459d52f5a3be3e69813827a6300
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
micrometer-observation-1.15.12.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-observation High
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor jar package name observation Highest
Vendor Manifest automatic-module-name micrometer.observation Medium
Vendor Manifest branch HEAD Low
Vendor Manifest build-date 2026-06-08_05:57:34 Low
Vendor Manifest build-date-utc 2026-06-08T05:57:34.134088941Z Low
Vendor Manifest build-host 320eea4f7654 Low
Vendor Manifest build-job deploy Low
Vendor Manifest build-number 70801 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status release Low
Vendor Manifest bundle-symbolicname micrometer-observation Medium
Vendor Manifest change dc2e5e2 Low
Vendor Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low
Vendor Manifest module-email tludwig@vmware.com Low
Vendor Manifest module-origin micrometer-metrics/micrometer.git Low
Vendor Manifest module-owner tludwig@vmware.com Low
Vendor Manifest module-source /micrometer-observation Low
Vendor pom artifactid micrometer-observation Highest
Vendor pom artifactid micrometer-observation Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id shakuzen Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-observation High
Vendor pom url micrometer-metrics/micrometer Highest
Product file name micrometer-observation High
Product jar package name io Highest
Product jar package name micrometer Highest
Product jar package name observation Highest
Product Manifest automatic-module-name micrometer.observation Medium
Product Manifest branch HEAD Low
Product Manifest build-date 2026-06-08_05:57:34 Low
Product Manifest build-date-utc 2026-06-08T05:57:34.134088941Z Low
Product Manifest build-host 320eea4f7654 Low
Product Manifest build-job deploy Low
Product Manifest build-number 70801 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low
Product Manifest built-os Linux Low
Product Manifest built-status release Low
Product Manifest Bundle-Name micrometer-observation Medium
Product Manifest bundle-symbolicname micrometer-observation Medium
Product Manifest change dc2e5e2 Low
Product Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low
Product Manifest Implementation-Title io.micrometer#micrometer-observation;1.15.12 High
Product Manifest module-email tludwig@vmware.com Low
Product Manifest module-origin micrometer-metrics/micrometer.git Low
Product Manifest module-owner tludwig@vmware.com Low
Product Manifest module-source /micrometer-observation Low
Product pom artifactid micrometer-observation Highest
Product pom developer email tludwig@vmware.com Low
Product pom developer id shakuzen Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-observation High
Product pom url micrometer-metrics/micrometer High
Version file version 1.15.12 High
Version Manifest Bundle-Version 1.15.12 High
Version Manifest Implementation-Version 1.15.12 High
Version pom version 1.15.12 Highest
pkg:maven/io.micrometer/micrometer-observation@1.15.12
(Confidence :High)
micrometer-observation-1.17.1.jar
Description:
Module containing Observation related code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-observation/1.17.1/micrometer-observation-1.17.1.jar
MD5: f63baf5840fb4446b9313a3bd8773da1
SHA1: 24c0b05bc06a9ab6f4e09a48949b6eccc179ca15
SHA256: eb34f0cd84a879393ae5c21160fc06385ccdc74f36a4d1e31b199f59acfdaf71
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
micrometer-observation-1.17.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-observation High
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor jar package name observation Highest
Vendor Manifest automatic-module-name micrometer.observation Medium
Vendor Manifest branch release/1.17.1 Low
Vendor Manifest build-date 2026-08-17_07:25:39 Low
Vendor Manifest build-date-utc 2026-08-17T07:25:39.958346319Z Low
Vendor Manifest build-host https://github.com Low
Vendor Manifest build-job build-release Low
Vendor Manifest build-number 50 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://github.com/micrometer-metrics/micrometer-commercial/actions/runs/32005692132 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status integration Low
Vendor Manifest bundle-symbolicname micrometer-observation Medium
Vendor Manifest change f1b1924 Low
Vendor Manifest full-change f1b1924bc8821adbc841df69eb433c933e17e1a5 Low
Vendor Manifest module-email tludwig@vmware.com,jivanov@vmware.com Low
Vendor Manifest module-origin https://github.com/micrometer-metrics/micrometer-commercial.git Low
Vendor Manifest module-owner tludwig@vmware.com,jivanov@vmware.com Low
Vendor pom artifactid micrometer-observation Highest
Vendor pom artifactid micrometer-observation Low
Vendor pom developer email jivanov@vmware.com Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id jonatan-ivanov Medium
Vendor pom developer id shakuzen Medium
Vendor pom developer name Jonatan Ivanov Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-observation High
Vendor pom url micrometer-metrics/micrometer-commercial Highest
Product file name micrometer-observation High
Product jar package name io Highest
Product jar package name micrometer Highest
Product jar package name observation Highest
Product Manifest automatic-module-name micrometer.observation Medium
Product Manifest branch release/1.17.1 Low
Product Manifest build-date 2026-08-17_07:25:39 Low
Product Manifest build-date-utc 2026-08-17T07:25:39.958346319Z Low
Product Manifest build-host https://github.com Low
Product Manifest build-job build-release Low
Product Manifest build-number 50 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://github.com/micrometer-metrics/micrometer-commercial/actions/runs/32005692132 Low
Product Manifest built-os Linux Low
Product Manifest built-status integration Low
Product Manifest Bundle-Name micrometer-observation Medium
Product Manifest bundle-symbolicname micrometer-observation Medium
Product Manifest change f1b1924 Low
Product Manifest full-change f1b1924bc8821adbc841df69eb433c933e17e1a5 Low
Product Manifest Implementation-Title io.micrometer#micrometer-observation;1.17.1 High
Product Manifest module-email tludwig@vmware.com,jivanov@vmware.com Low
Product Manifest module-origin https://github.com/micrometer-metrics/micrometer-commercial.git Low
Product Manifest module-owner tludwig@vmware.com,jivanov@vmware.com Low
Product pom artifactid micrometer-observation Highest
Product pom developer email jivanov@vmware.com Low
Product pom developer email tludwig@vmware.com Low
Product pom developer id jonatan-ivanov Low
Product pom developer id shakuzen Low
Product pom developer name Jonatan Ivanov Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-observation High
Product pom url micrometer-metrics/micrometer-commercial High
Version file version 1.17.1 High
Version Manifest Bundle-Version 1.17.1 High
Version Manifest Implementation-Version 1.17.1 High
Version pom version 1.17.1 Highest
pkg:maven/io.micrometer/micrometer-observation@1.17.1
(Confidence :High)
slf4j-api-2.0.18.jar
Description:
The slf4j API
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.18/slf4j-api-2.0.18.jar
MD5: fe2837bd49bfb76657419002fed20ca9
SHA1: 78a9e7a37cd6360e0b818e86341b24123d28d4df
SHA256: 44508fd1576500688c790b190acdd16fec4f8c79a3e0b900afd70503cf055f55
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:compile
waffle-demo-parent-jakarta:compile
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
slf4j-api-2.0.18.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/ch.qos.logback/logback-classic@1.6.3
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Highest
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.18 High
Version Manifest Bundle-Version 2.0.18 High
Version Manifest Implementation-Version 2.0.18 High
Version pom version 2.0.18 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.18
(Confidence :High)
slf4j-api-2.0.19.jar
Description:
The slf4j API
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.19/slf4j-api-2.0.19.jar
MD5: 1ca3a2acac3d5947b37d9b5536c55829
SHA1: efad9817997b3a6ce9e058f92e612917a744c290
SHA256: e91ff6d720609e7a194ffe758c3ed5c84e798617ae07b0a0f6a4fe229741b4bb
Referenced In Projects/Scopes:
waffle-demo-form-jakarta:compile
waffle-demo-jaas-jakarta:compile
waffle-demo-mixed-jakarta:compile
waffle-demo-mixed-post-jakarta:compile
waffle-demo-negotiate-jakarta:compile
slf4j-api-2.0.19.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Highest
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.19 High
Version Manifest Bundle-Version 2.0.19 High
Version Manifest Implementation-Version 2.0.19 High
Version pom version 2.0.19 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.19
(Confidence :High)
snakeyaml-2.4.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/yaml/snakeyaml/2.4/snakeyaml-2.4.jar
MD5: 29410ee3a987e3bff7b847933c591972
SHA1: e0666b825b796f85521f02360e77f4c92c5a7a07
SHA256: ef779af5d29a9dde8cc70ce0341f5c6f7735e23edff9685ceaa9d35359b7bb7f
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
snakeyaml-2.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Highest
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.4 High
Version pom version 2.4 Highest
snakeyaml-2.6.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/yaml/snakeyaml/2.6/snakeyaml-2.6.jar
MD5: d8bd94536cee962cfff39730bffdb8da
SHA1: 2bc14918a2f8d5414749ab12d0c590cd3198b8c1
SHA256: c8f7a98e7394adda02f6317249710e4d1b4c7a25aa8c7eace0c2eea52eb8bf85
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
snakeyaml-2.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Highest
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.6 High
Version pom version 2.6 Highest
spotbugs-annotations-4.10.4.jar
Description:
Annotations the SpotBugs tool supports
License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.10.4/spotbugs-annotations-4.10.4.jar
MD5: 472925cb4e5451c8f7a1aeeefe286622
SHA1: 7eb4c58212378becfb6ea6d236ec24a2352a316e
SHA256: 28fa4befaddce5d7b79b07c68e7c12fa27c5d9282c4229528717971606661ea3
Referenced In Projects/Scopes:
waffle-demo-filter-jakarta:provided
waffle-demo-form-jakarta:provided
waffle-demo-jaas-jakarta:provided
waffle-demo-mixed-jakarta:provided
waffle-demo-mixed-post-jakarta:provided
waffle-demo-negotiate-jakarta:provided
waffle-demo-parent-jakarta:provided
waffle-demo-spring-boot-filter3:provided
waffle-demo-spring-boot-filter4:provided
waffle-demo-spring-filter-jakarta:provided
waffle-demo-spring-form-jakarta:provided
spotbugs-annotations-4.10.4.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-form-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-jaas-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-mixed-post-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-negotiate-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-parent-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-boot-filter4@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-filter-jakarta@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle.demo.jakarta/waffle-demo-spring-form-jakarta@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spotbugs-annotations High
Vendor Manifest automatic-module-name com.github.spotbugs.annotations Medium
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname spotbugs-annotations Medium
Vendor pom artifactid spotbugs-annotations Highest
Vendor pom artifactid spotbugs-annotations Low
Vendor pom developer email andreas.sewe@codetrails.com Low
Vendor pom developer email dbrosius@mebigfatguy.com Low
Vendor pom developer email loskutov@gmx.de Low
Vendor pom developer email skypencil@gmail.com Low
Vendor pom developer id henrik242 Medium
Vendor pom developer id iloveeclipse Medium
Vendor pom developer id jsotuyod Medium
Vendor pom developer id KengoTODA Medium
Vendor pom developer id mebigfatguy Medium
Vendor pom developer id sewe Medium
Vendor pom developer id ThrawnCA Medium
Vendor pom developer name Andreas Sewe Medium
Vendor pom developer name Andrey Loskutov Medium
Vendor pom developer name Dave Brosius Medium
Vendor pom developer name Juan Martín Sotuyo Dodero Medium
Vendor pom developer name Kengo TODA Medium
Vendor pom groupid com.github.spotbugs Highest
Vendor pom name SpotBugs Annotations High
Vendor pom url https://spotbugs.github.io/ Highest
Product file name spotbugs-annotations High
Product Manifest automatic-module-name com.github.spotbugs.annotations Medium
Product Manifest Bundle-Name spotbugs-annotations Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname spotbugs-annotations Medium
Product pom artifactid spotbugs-annotations Highest
Product pom developer email andreas.sewe@codetrails.com Low
Product pom developer email dbrosius@mebigfatguy.com Low
Product pom developer email loskutov@gmx.de Low
Product pom developer email skypencil@gmail.com Low
Product pom developer id henrik242 Low
Product pom developer id iloveeclipse Low
Product pom developer id jsotuyod Low
Product pom developer id KengoTODA Low
Product pom developer id mebigfatguy Low
Product pom developer id sewe Low
Product pom developer id ThrawnCA Low
Product pom developer name Andreas Sewe Low
Product pom developer name Andrey Loskutov Low
Product pom developer name Dave Brosius Low
Product pom developer name Juan Martín Sotuyo Dodero Low
Product pom developer name Kengo TODA Low
Product pom groupid com.github.spotbugs Highest
Product pom name SpotBugs Annotations High
Product pom url https://spotbugs.github.io/ Medium
Version file version 4.10.4 High
Version Manifest Bundle-Version 4.10.4 High
Version pom version 4.10.4 Highest
pkg:maven/com.github.spotbugs/spotbugs-annotations@4.10.4
(Confidence :High)
spring-boot-3.5.16.jar
Description:
Spring Boot
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot/3.5.16/spring-boot-3.5.16.jar
MD5: 7a7ad5afd579e7a5b871dd29bf3ff406
SHA1: 8e75e8d0d3cfbca088774df8d30b45bbd21e5d99
SHA256: 2d5b16632402b840b0425ed52610071890bf8cb24c6c49af343bbde574123265
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
spring-boot-3.5.16.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name spring-boot High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name boot Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.boot Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid spring-boot Highest
Vendor pom artifactid spring-boot Low
Vendor pom developer email ask@spring.io Low
Vendor pom developer name Spring Medium
Vendor pom developer org VMware, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.boot Highest
Vendor pom name spring-boot High
Vendor pom organization name VMware, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-boot Highest
Product file name spring-boot High
Product jar package name boot Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.boot Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Spring Boot High
Product pom artifactid spring-boot Highest
Product pom developer email ask@spring.io Low
Product pom developer name Spring Low
Product pom developer org VMware, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.boot Highest
Product pom name spring-boot High
Product pom organization name VMware, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-boot Medium
Version file version 3.5.16 High
Version Manifest Implementation-Version 3.5.16 High
Version pom version 3.5.16 Highest
Related Dependencies
spring-boot-autoconfigure-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/3.5.16/spring-boot-autoconfigure-3.5.16.jar
MD5: 456df6ce6ce9901dc7239a2ccd7b5eee
SHA1: 87db09240595b49b530b230252311836abd21df1
SHA256: 0198331231e9bf872a135741d59c6d1f9e9007ff207a1ca910179c550bb12bfc
pkg:maven/org.springframework.boot/spring-boot-autoconfigure@3.5.16
spring-boot-starter-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter/3.5.16/spring-boot-starter-3.5.16.jar
MD5: a9bedef81badcc7696680d69aadef61e
SHA1: d38b3f624f867a7d1e7f72a7adb193f6d4111114
SHA256: 649da4576c83a4f814222dcff067cd774eeeb1119e790390eaeab8e9955d0d44
pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
spring-boot-starter-json-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-json/3.5.16/spring-boot-starter-json-3.5.16.jar
MD5: 1335561c4d84c3c854d234a0dc772763
SHA1: 5840614f0a4371809023d7409b5ee132f686e55a
SHA256: be8340bdd87d5e76bfec5b3b256bb923c841464793e5a8e2f7e8ced37e6eb434
pkg:maven/org.springframework.boot/spring-boot-starter-json@3.5.16
spring-boot-starter-logging-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-logging/3.5.16/spring-boot-starter-logging-3.5.16.jar
MD5: f7403bc79d5914196bfd62efd4a4115e
SHA1: 18df7a243be45f11ee346cdd4d7b84d377917a2e
SHA256: f761d56f6693a47e6cccca8e9202c716ab954ccdf7440e1fccc0cb50c661eeb8
pkg:maven/org.springframework.boot/spring-boot-starter-logging@3.5.16
spring-boot-starter-security-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-security/3.5.16/spring-boot-starter-security-3.5.16.jar
MD5: 50481913461e9fdb61cd0f73283cba9a
SHA1: b32c27a95316b69df761455c6f29d30ecaba07f2
SHA256: 826a677535c3a3a37c242c2de8061f2ecafb34d449ba1c5988079733dcb6d65d
pkg:maven/org.springframework.boot/spring-boot-starter-security@3.5.16
spring-boot-starter-tomcat-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat/3.5.16/spring-boot-starter-tomcat-3.5.16.jar
MD5: a387774e6aaf92adc4bb90aa48b62085
SHA1: e76d97eb7710f95feaa82c9cf2fa74cc78acc64d
SHA256: c3bc33205b0a46faab33dcdf743958e845ee94e1f7961bbe0e0f8ce881db747b
pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@3.5.16
spring-boot-starter-web-3.5.16.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-web/3.5.16/spring-boot-starter-web-3.5.16.jar
MD5: 64ed509c59fb81442d28a42381f6b7b1
SHA1: 5c30cb2a0a69e25a8fc402d22e171dbca7b49278
SHA256: 3272f145a6edd94896c60fba7d2a05b525c78f8efd0172e7bffb6c3b9857762e
pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
spring-boot-web-server-4.1.1.jar
Description:
Spring Boot Web Server
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-web-server/4.1.1/spring-boot-web-server-4.1.1.jar
MD5: a060efd710429298574e5f7615e4f6df
SHA1: d1eb8e523013ac3939ae59adc5335a3de704d11b
SHA256: 6912fb1fdf7f657a61ac050760fa835fb1e7496399291697e2901f82887a4fee
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
spring-boot-web-server-4.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name spring-boot-web-server High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name boot Highest
Vendor jar package name server Highest
Vendor jar package name springframework Highest
Vendor jar package name web Highest
Vendor Manifest automatic-module-name spring.boot.web.server Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid spring-boot-web-server Highest
Vendor pom artifactid spring-boot-web-server Low
Vendor pom developer email ask@spring.io Low
Vendor pom developer name Spring Medium
Vendor pom developer org VMware, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.boot Highest
Vendor pom name spring-boot-web-server High
Vendor pom organization name VMware, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-boot Highest
Product file name spring-boot-web-server High
Product jar package name boot Highest
Product jar package name server Highest
Product jar package name springframework Highest
Product jar package name web Highest
Product Manifest automatic-module-name spring.boot.web.server Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Spring Boot Web Server High
Product pom artifactid spring-boot-web-server Highest
Product pom developer email ask@spring.io Low
Product pom developer name Spring Low
Product pom developer org VMware, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.boot Highest
Product pom name spring-boot-web-server High
Product pom organization name VMware, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-boot Medium
Version file version 4.1.1 High
Version Manifest Implementation-Version 4.1.1 High
Version pom version 4.1.1 Highest
Related Dependencies
spring-boot-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot/4.1.1/spring-boot-4.1.1.jar
MD5: 81b5253239da3bbee07178a6c28bd9d4
SHA1: f958dfcba9bc998459cd7862894aa69220645c44
SHA256: 0d92b532b1d4020640e72d78c31af175c23db8e0ddd45b81855b7fdf4c9c70f0
pkg:maven/org.springframework.boot/spring-boot@4.1.1
spring-boot-autoconfigure-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/4.1.1/spring-boot-autoconfigure-4.1.1.jar
MD5: bdae3903f86e1ce179fc0da467594b14
SHA1: 53c1c604301b4183faa480a5b9f2fd86a2f043c3
SHA256: 59228756ddd76cea050f95d86deff334789bc53b6688beaa673b1af2b9794592
pkg:maven/org.springframework.boot/spring-boot-autoconfigure@4.1.1
spring-boot-http-converter-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-http-converter/4.1.1/spring-boot-http-converter-4.1.1.jar
MD5: dca1f4468f453cd12fd3497d5ad7ed22
SHA1: 886e76307151a64c8710c61e02a2323ab883b87c
SHA256: 52a167430a918c223b2ccd2eb62aff91a8e43e6daebe5a07caa37b9a04c61cb9
pkg:maven/org.springframework.boot/spring-boot-http-converter@4.1.1
spring-boot-jackson-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-jackson/4.1.1/spring-boot-jackson-4.1.1.jar
MD5: 25cf1458df4244b5d1e583ceffab5f2e
SHA1: 1defff7e3f9dda050f26e98da3285b4321920dc1
SHA256: 69a9b4d8850a0532a5e44ff7306a03621485b26596e7f9481de7d28e68a2dd42
pkg:maven/org.springframework.boot/spring-boot-jackson@4.1.1
spring-boot-security-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-security/4.1.1/spring-boot-security-4.1.1.jar
MD5: f32cab4e9825bc63d15fd6c5e4cd6f1d
SHA1: 8f08145264d1a224c4b9c865d60e47f62f4dd85f
SHA256: c940697be9bc67820d5011b86d58105836b7cae7c8fb5d4e61d635b51b392cbe
pkg:maven/org.springframework.boot/spring-boot-security@4.1.1
spring-boot-servlet-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-servlet/4.1.1/spring-boot-servlet-4.1.1.jar
MD5: d496b25e22cd17f4f89e6a54a1f9b6f7
SHA1: 76881b573c8639708ce3d520b428209335f007fc
SHA256: 4dcb156e311a4c1ad5f1ed7eabd94a78ea74510b05c429a4fcfdcf8beb9d5882
pkg:maven/org.springframework.boot/spring-boot-servlet@4.1.1
spring-boot-starter-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter/4.1.1/spring-boot-starter-4.1.1.jar
MD5: 5d5008acc9638eca189bbcd581e164b3
SHA1: 50fe6a89fa4fd26e7caaec909ab1c4cc9afde5d4
SHA256: de5b2dd28400eda20914fd4a6054d0c201e68d2e4de35a25a4d89f054ccc2e63
pkg:maven/org.springframework.boot/spring-boot-starter@4.1.1
spring-boot-starter-jackson-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-jackson/4.1.1/spring-boot-starter-jackson-4.1.1.jar
MD5: 5dad3d4002b15cc88586263d4224a82e
SHA1: f8cd6a81994a207a808564515e5104548d1967bb
SHA256: d30e594a3e0f3a090438fc22000a87ab577a3b80c674180a10544ca331207f24
pkg:maven/org.springframework.boot/spring-boot-starter-jackson@4.1.1
spring-boot-starter-logging-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-logging/4.1.1/spring-boot-starter-logging-4.1.1.jar
MD5: d7cf74c5bba2267508f0bfafd374c367
SHA1: c6831fe833182419def54db4c41fc34ce71f4fc5
SHA256: 8eca7d72c8434f5c3b935385c656cd5337f473434bdbcb4913b3b3a34897d178
pkg:maven/org.springframework.boot/spring-boot-starter-logging@4.1.1
spring-boot-starter-security-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-security/4.1.1/spring-boot-starter-security-4.1.1.jar
MD5: 1d540ab506986647dc85fca9b6230f24
SHA1: 6c8b67269e28642ac532a85fec1ea159847ab602
SHA256: 38628875b75cbed6ba4642f3b0a4baf4735bd4f82b49450e4ae5a5e4d1b7b4a9
pkg:maven/org.springframework.boot/spring-boot-starter-security@4.1.1
spring-boot-starter-tomcat-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat/4.1.1/spring-boot-starter-tomcat-4.1.1.jar
MD5: da4fd524d53460ee9872627f37d82955
SHA1: 8a7b2b2fd2ec40ed7e56359fb68c9a8b5fde315c
SHA256: f224d8504be3b413825ee85ef549a7b1598ee8512e062c6bd5ddce1043cd388a
pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@4.1.1
spring-boot-starter-tomcat-runtime-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat-runtime/4.1.1/spring-boot-starter-tomcat-runtime-4.1.1.jar
MD5: 8bf74fd310649fcc3fadd2ae63ef33e7
SHA1: 0397ae80a471fa432ef858230c7d52498ee20ecd
SHA256: 580f0d9a9d02a1a6e387640e422af42f9dbdf302836d562ec595fdb2b31a1c29
pkg:maven/org.springframework.boot/spring-boot-starter-tomcat-runtime@4.1.1
spring-boot-starter-web-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-web/4.1.1/spring-boot-starter-web-4.1.1.jar
MD5: 458186b1220acdb0d5ddcc644782fbfd
SHA1: e26041af0e4abd0219452f7cffbf70782f6b2667
SHA256: 840d2ccfa8945bbbde526121f7bbbc075b98c816fec188c0c5f89b7b05be5e21
pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
spring-boot-tomcat-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-tomcat/4.1.1/spring-boot-tomcat-4.1.1.jar
MD5: f6af30cb7f976f9ffb40870d546dfe97
SHA1: 61450290ced8f16d8d00308f1aa81423d7660dc2
SHA256: 17f65629e4eb3c979c0572b69b57d630bb12e64869e9d7520adddaa6734256b6
pkg:maven/org.springframework.boot/spring-boot-tomcat@4.1.1
spring-boot-webmvc-4.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-webmvc/4.1.1/spring-boot-webmvc-4.1.1.jar
MD5: c2ab42be73e47c4389f6605ede5f24b2
SHA1: 3057d155bc66412ad906ecdd488e0fd617589151
SHA256: 9f08c1fb938c45a8693fec5f3065be3aca203948a7ab4d56b06444986f75a6b2
pkg:maven/org.springframework.boot/spring-boot-webmvc@4.1.1
spring-core-6.2.19.jar
Description:
Spring Core
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/spring-core/6.2.19/spring-core-6.2.19.jar
MD5: 4afe3968028c2b743dbff2d79013e144
SHA1: 691459d4644894dae8e5c2d9550a4cfb8302f62f
SHA256: 52146689e71a911c92bac26677d73c692512a739893a57710cc233591756bff6
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
spring-core-6.2.19.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
pkg:maven/org.springframework.boot/spring-boot-starter@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name spring-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name io Highest
Vendor jar package name org Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.core Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid spring-core Highest
Vendor pom artifactid spring-core Low
Vendor pom developer email juergen.hoeller@broadcom.com Low
Vendor pom developer id jhoeller Medium
Vendor pom developer name Juergen Hoeller Medium
Vendor pom groupid org.springframework Highest
Vendor pom name Spring Core High
Vendor pom organization name Spring IO High
Vendor pom organization url https://spring.io/projects/spring-framework Medium
Vendor pom url spring-projects/spring-framework Highest
Product file name spring-core High
Product hint analyzer product springsource_spring_framework Highest
Product jar package name core Highest
Product jar package name io Highest
Product jar package name org Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.core Medium
Product Manifest Implementation-Title spring-core High
Product Manifest multi-release true Low
Product pom artifactid spring-core Highest
Product pom developer email juergen.hoeller@broadcom.com Low
Product pom developer id jhoeller Low
Product pom developer name Juergen Hoeller Low
Product pom groupid org.springframework Highest
Product pom name Spring Core High
Product pom organization name Spring IO Low
Product pom organization url https://spring.io/projects/spring-framework Low
Product pom url spring-projects/spring-framework High
Version file version 6.2.19 High
Version Manifest Implementation-Version 6.2.19 High
Version pom version 6.2.19 Highest
Related Dependencies
spring-aop-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-aop/6.2.19/spring-aop-6.2.19.jar
MD5: 36ab0f0a76202a0f8cd077fd323372a5
SHA1: 86a538bb7b2be38a0afc4ef049784def10a86c62
SHA256: a11b93539d80b02caf76171db2da96df39abebbfef49a2fadd6dda0779f2e20b
pkg:maven/org.springframework/spring-aop@6.2.19
spring-beans-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-beans/6.2.19/spring-beans-6.2.19.jar
MD5: ae0cf6f1e373577d322e17c350d0fb15
SHA1: 6d6b4774db3b036df46be6332d93b09d70e5c147
SHA256: 846dc8f30a639a36eb551ee99a30469be4d11bd285ca9daf164d98321571b404
pkg:maven/org.springframework/spring-beans@6.2.19
spring-context-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-context/6.2.19/spring-context-6.2.19.jar
MD5: 77c848b32f387021e0b690be9cd24de8
SHA1: e218e4c4ecad1e821905628b2c4ce8561d937baa
SHA256: ead4b645f94a7f665f00093eaafde634e97b34524294de653b51e43e0b3fc4a4
pkg:maven/org.springframework/spring-context@6.2.19
spring-expression-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-expression/6.2.19/spring-expression-6.2.19.jar
MD5: 233e2f7ced4637cad68a9449844e9a6b
SHA1: c7202d23797fa778c5ed55e502ac1a9f0d34012a
SHA256: d710a44417d890353895b341a722d7d08199e2b7da52f0a11c0e92571e1d6e19
pkg:maven/org.springframework/spring-expression@6.2.19
spring-web-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-web/6.2.19/spring-web-6.2.19.jar
MD5: 1d5ca2b445acea292d5787536c069a36
SHA1: f1dc7b238611aeaf9e256a230aa089057cf0e5b3
SHA256: ca88e364ecebee61163e2260e8a20584138eca74e28a050d6a2ef6302bad2f2d
pkg:maven/org.springframework/spring-web@6.2.19
spring-webmvc-6.2.19.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-webmvc/6.2.19/spring-webmvc-6.2.19.jar
MD5: df1758cf3891705ec3bb290bf75f740e
SHA1: 836c68c8797106000e44153686b1cfa1a806a998
SHA256: 134f42320cedd31f54f683d2ca9936a4e015c011fb1882a31fa7213e2d8c7e94
pkg:maven/org.springframework/spring-webmvc@6.2.19
CVE-2026-47884 suppress
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47890 suppress
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47891 suppress
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47892 suppress
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
CWE-863 Incorrect Authorization
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59313 suppress
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59283 suppress
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-913 Improper Control of Dynamically-Managed Code Resources
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47885 suppress
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47886 suppress
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47888 suppress
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
CWE-401 Missing Release of Memory after Effective Lifetime
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47889 suppress
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
CWE-1275 Sensitive Cookie with Improper SameSite Attribute
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47893 suppress
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59282 suppress
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47883 suppress
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47887 suppress
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59281 suppress
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59280 suppress
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: MEDIUM (4.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59314 suppress
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
NVD-CWE-Other, CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSSv3:
Base Score: LOW (3.7)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
spring-core-7.0.9.jar
Description:
Spring Core
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/spring-core/7.0.9/spring-core-7.0.9.jar
MD5: f87ba857b1fb00b125568d966aa66058
SHA1: e03c619fc5b26931973277f5ba65ae47967a20e3
SHA256: 5195f4722699b39878d99a832549fe65df2890b159d063b88fff31b1ca65ae36
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
spring-core-7.0.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spring-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name io Highest
Vendor jar package name org Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.core Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid spring-core Highest
Vendor pom artifactid spring-core Low
Vendor pom developer email juergen.hoeller@broadcom.com Low
Vendor pom developer id jhoeller Medium
Vendor pom developer name Juergen Hoeller Medium
Vendor pom groupid org.springframework Highest
Vendor pom name Spring Core High
Vendor pom organization name Spring IO High
Vendor pom organization url https://spring.io/projects/spring-framework Medium
Vendor pom url spring-projects/spring-framework Highest
Product file name spring-core High
Product hint analyzer product springsource_spring_framework Highest
Product jar package name core Highest
Product jar package name io Highest
Product jar package name org Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.core Medium
Product Manifest Implementation-Title spring-core High
Product Manifest multi-release true Low
Product pom artifactid spring-core Highest
Product pom developer email juergen.hoeller@broadcom.com Low
Product pom developer id jhoeller Low
Product pom developer name Juergen Hoeller Low
Product pom groupid org.springframework Highest
Product pom name Spring Core High
Product pom organization name Spring IO Low
Product pom organization url https://spring.io/projects/spring-framework Low
Product pom url spring-projects/spring-framework High
Version file version 7.0.9 High
Version Manifest Implementation-Version 7.0.9 High
Version pom version 7.0.9 Highest
Related Dependencies
spring-aop-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-aop/7.0.9/spring-aop-7.0.9.jar
MD5: 1766c086d944229fdca3c052bd133735
SHA1: 35f68fd8cdf30444e18835cec152f2619c4c46c7
SHA256: b8c5d6bfcb1f4993f2cc124f7ab7fac40edf5256b9e43c2f7250a733cb5510e9
pkg:maven/org.springframework/spring-aop@7.0.9
spring-beans-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-beans/7.0.9/spring-beans-7.0.9.jar
MD5: 4472076f5c22297927d129768a54119d
SHA1: 2bee42fa948a5f32761fd0838de3baa1f51c0225
SHA256: ff218b827a25c9e8929b0cd56dfb56916cea9d5b669ed97dc7cb262508ff548b
pkg:maven/org.springframework/spring-beans@7.0.9
spring-context-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-context/7.0.9/spring-context-7.0.9.jar
MD5: 4528f937c5eadd30458a0f19a977e3b8
SHA1: 7eb8e01ecf1633ddd4d64ca184194f967b6bc0aa
SHA256: 7552a2fcfa30cea53eb14d7a65a7a8e1b1dd82e832a7164fb7e6fb105f438858
pkg:maven/org.springframework/spring-context@7.0.9
spring-expression-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-expression/7.0.9/spring-expression-7.0.9.jar
MD5: 46931226190dcd4ab0dd8862cd7f4986
SHA1: 9452ece85b97fa3e208046cc3a7e985c314b0034
SHA256: 046434c40f43819729b9b1db0e6c659dfa68184c1c2c2efa5f7b3a5b27c4e2e2
pkg:maven/org.springframework/spring-expression@7.0.9
spring-web-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-web/7.0.9/spring-web-7.0.9.jar
MD5: 3ad4a5d872c4094ab34b16980aedafa9
SHA1: c42f4ce0cded1526527296726c4ed30335dfaa10
SHA256: 941ced476427bde2533872f293da535fd0258de3f3a650a7f1bfe01ed2927302
pkg:maven/org.springframework/spring-web@7.0.9
spring-webmvc-7.0.9.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-webmvc/7.0.9/spring-webmvc-7.0.9.jar
MD5: 7d4e0f02f611df75eabff8d2822b1f81
SHA1: 53b41e6290df1a75fe0e0d16608c80a93bb63bdd
SHA256: 8f114c1461692c5e534e82b27de23b7fb23370db8dee7ce0c92d5106906c9555
pkg:maven/org.springframework/spring-webmvc@7.0.9
spring-security-core-6.5.11.jar
Description:
Spring Security
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-core/6.5.11/spring-security-core-6.5.11.jar
MD5: 697081575fdb870e6c77e4f489acb192
SHA1: d57309ff65d122a2fa45a3a8f47b01e9183cb6e6
SHA256: 26ac26527cc015c5c71f3832add705a2410129a8f8de847054f2bc3b1d2e4465
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
spring-security-core-6.5.11.jar is in the transitive dependency tree of the listed items. Included by:
pkg:maven/com.github.waffle/waffle-spring-boot-starter3@3.6.1-SNAPSHOT
pkg:maven/com.github.waffle/waffle-spring-security6@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spring-security-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name security Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.security.core Medium
Vendor pom artifactid spring-security-core Highest
Vendor pom artifactid spring-security-core Low
Vendor pom developer email info@pivotal.io Low
Vendor pom developer name Pivotal Medium
Vendor pom developer org Pivotal Software, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.security Highest
Vendor pom name spring-security-core High
Vendor pom organization name Pivotal Software, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-security Highest
Product file name spring-security-core High
Product jar package name core Highest
Product jar package name security Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.security.core Medium
Product Manifest Implementation-Title spring-security-core High
Product pom artifactid spring-security-core Highest
Product pom developer email info@pivotal.io Low
Product pom developer name Pivotal Low
Product pom developer org Pivotal Software, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.security Highest
Product pom name spring-security-core High
Product pom organization name Pivotal Software, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-security Medium
Version file version 6.5.11 High
Version Manifest Implementation-Version 6.5.11 High
Version pom version 6.5.11 Highest
Related Dependencies
spring-security-config-6.5.11.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-config/6.5.11/spring-security-config-6.5.11.jar
MD5: 56a1f736ee4e6e8557ea360d0ae995c3
SHA1: c698bc32f1f10f85b3ade54575077eaebc9b86c3
SHA256: 218685930013a2d1c126a896490ac3c44cf6fe90cf3d0286f2266bb877f916f7
pkg:maven/org.springframework.security/spring-security-config@6.5.11
spring-security-crypto-6.5.11.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-crypto/6.5.11/spring-security-crypto-6.5.11.jar
MD5: d9fb7f74b14c2c049d46d0454f138247
SHA1: 2cbc07fa7650ef2f49bcc5ac35e7666c79614f55
SHA256: dcdd2f3b2d5d2bb1531986b5cc1737b464a76d8b5831f93fc8da9cdd67e6797f
pkg:maven/org.springframework.security/spring-security-crypto@6.5.11
spring-security-web-6.5.11.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/6.5.11/spring-security-web-6.5.11.jar
MD5: 9e6b94f61b08fe8d113a7835bb994576
SHA1: eeee13020ef81f290633e68fe062bccba062774e
SHA256: 50df9fc76162d33cf8b5410cf7a7a969abd42a5ecddb284aab4f453cb5512306
pkg:maven/org.springframework.security/spring-security-web@6.5.11
CVE-2026-59270 suppress
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
CWE-863 Incorrect Authorization
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47841 suppress
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (7.4)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-47842 suppress
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
CWE-326 Inadequate Encryption Strength
CVSSv3:
Base Score: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59276 suppress
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.18
Spring Security 5.8.0 - 5.8.27
Spring Security 5.7.0 - 5.7.25
CWE-208 Observable Timing Discrepancy
CVSSv3:
Base Score: MEDIUM (5.9)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
spring-security-core-7.1.1.jar
Description:
Spring Security
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-core/7.1.1/spring-security-core-7.1.1.jar
MD5: e9c072aeb1ab83fb92dd5a0bc556a857
SHA1: c0373b564151af7a3001ccfbea589bf37dd6dc3b
SHA256: 98a5011baa78df36fb184e6ce0e8e086ca9a64fcdd8f161c0a96475a3a0907bd
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
spring-security-core-7.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-starter4@3.6.1-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spring-security-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name security Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.security.core Medium
Vendor pom artifactid spring-security-core Highest
Vendor pom artifactid spring-security-core Low
Vendor pom developer email info@pivotal.io Low
Vendor pom developer name Pivotal Medium
Vendor pom developer org Pivotal Software, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.security Highest
Vendor pom name spring-security-core High
Vendor pom organization name Pivotal Software, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-security Highest
Product file name spring-security-core High
Product jar package name core Highest
Product jar package name security Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.security.core Medium
Product Manifest Implementation-Title spring-security-core High
Product pom artifactid spring-security-core Highest
Product pom developer email info@pivotal.io Low
Product pom developer name Pivotal Low
Product pom developer org Pivotal Software, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.security Highest
Product pom name spring-security-core High
Product pom organization name Pivotal Software, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-security Medium
Version file version 7.1.1 High
Version Manifest Implementation-Version 7.1.1 High
Version pom version 7.1.1 Highest
Related Dependencies
spring-security-config-7.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-config/7.1.1/spring-security-config-7.1.1.jar
MD5: 08ebfc196ab56b26cd5d36ebb5497f70
SHA1: 06aadefb4acc552578b28f0b95908158861bea08
SHA256: 1f947c853f14cab76563464ee22e72f6672f3913db52647d2f5d1df5f2b1e5a5
pkg:maven/org.springframework.security/spring-security-config@7.1.1
spring-security-crypto-7.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-crypto/7.1.1/spring-security-crypto-7.1.1.jar
MD5: cd2777efdf4d91dd0b264f608af574ef
SHA1: 5356e8056e4dcb18b12550c422fb12e0c8e742ae
SHA256: 6e8bb2337faccabd30626f917ed1d2bfa9dde982229b6b373b644d1a01635403
pkg:maven/org.springframework.security/spring-security-crypto@7.1.1
spring-security-web-7.1.1.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/7.1.1/spring-security-web-7.1.1.jar
MD5: cc76d1f39558ef5eeaee80997caac280
SHA1: 449685cf2be4029b1200f1d0860a15caa5c2d05b
SHA256: dece134a2332c976a2c94ecf13f816c64e8ea7f2139795485afe655fba0408f3
pkg:maven/org.springframework.security/spring-security-web@7.1.1
spring-security-web-6.5.11.jar: spring-security-webauthn.js
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/6.5.11/spring-security-web-6.5.11.jar/org/springframework/security/spring-security-webauthn.js
MD5: d8d90d854a23d021c2e758b3eebce213
SHA1: 7814ccd3adc2388f52b2658bf5fc30b457949ab6
SHA256: 044a2b8d7e995bff815565678631a2d3a5cc0aa96ef8ac35cfacb579307f77a9
Referenced In Projects/Scopes:
waffle-demo-spring-boot-filter3:compile
waffle-demo-spring-boot-filter4:compile
waffle-demo-spring-filter-jakarta:compile
waffle-demo-spring-form-jakarta:compile
Evidence
Type Source Name Value Confidence
Related Dependencies
spring-security-web-7.1.1.jar: spring-security-webauthn.js
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/7.1.1/spring-security-web-7.1.1.jar/org/springframework/security/spring-security-webauthn.js
MD5: d8d90d854a23d021c2e758b3eebce213
SHA1: 7814ccd3adc2388f52b2658bf5fc30b457949ab6
SHA256: 044a2b8d7e995bff815565678631a2d3a5cc0aa96ef8ac35cfacb579307f77a9
tomcat-embed-core-10.1.55.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/10.1.55/tomcat-embed-core-10.1.55.jar
MD5: b56211060ef226699d7c6746444c94e9
SHA1: 740c1000c60766b3a4d99903434fd1a1d67ec229
SHA256: 82473f841824095e03f2c938c18707e44e388e34fb1735b2b338bb4f22fd54f0
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
tomcat-embed-core-10.1.55.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-core High
Vendor jar package name apache Highest
Vendor jar package name core Highest
Vendor jar package name tomcat Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.0";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.0";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/http/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-core Highest
Vendor pom artifactid tomcat-embed-core Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-core High
Product jar package name annotation Highest
Product jar package name apache Highest
Product jar package name auth Highest
Product jar package name core Highest
Product jar package name descriptor Highest
Product jar package name http Highest
Product jar package name jakarta Highest
Product jar package name message Highest
Product jar package name security Highest
Product jar package name servlet Highest
Product jar package name tomcat Highest
Product Manifest Bundle-Name tomcat-embed-core Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.0";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.0";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/security/auth/message/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/callback/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/callback/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/config/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/config/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/module/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/module/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/servlet/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/annotation/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/annotation/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/descriptor/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/descriptor/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/http/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/http/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/resources/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/resources/ Specification-Title Jakarta Servlet Medium
Product pom artifactid tomcat-embed-core Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 10.1.55 High
Version Manifest Bundle-Version 10.1.55 High
Version Manifest Implementation-Version 10.1.55 High
Version pom version 10.1.55 Highest
Related Dependencies
tomcat-embed-websocket-10.1.55.jar
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/10.1.55/tomcat-embed-websocket-10.1.55.jar
MD5: 82bf59988201166d80a060a5e00a1fa9
SHA1: b07cf802e82f358903a07f70757a4bcbe4fece20
SHA256: 81800431395fe2ef317fc14075ed49faaa64679a3458ee8791159111a1aa1b37
pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@10.1.55
CVE-2026-65637 suppress
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65905 suppress
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-294 Authentication Bypass by Capture-replay
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-53434 suppress
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
CWE-390 Detection of Error Condition Without Action
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-55276 suppress
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.
CWE-670 Always-Incorrect Control Flow Implementation
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59083 suppress
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
CWE-177 Improper Handling of URL Encoding (Hex Encoding)
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-59084 suppress
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
CWE-1059 Insufficient Technical Documentation
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65182 suppress
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
CWE-863 Incorrect Authorization, CWE-284 Improper Access Control
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68525 suppress
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
CWE-863 Incorrect Authorization
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65183 suppress
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-66422 suppress
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-285 Improper Authorization
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68569 suppress
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-287 Improper Authentication
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65927 suppress
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.
CWE-193 Off-by-one Error
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68763 suppress
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-53404 suppress
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CWE-670 Always-Incorrect Control Flow Implementation
CVSSv3:
Base Score: HIGH (7.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-73180 suppress
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-613 Insufficient Session Expiration
CVSSv3:
Base Score: MEDIUM (6.8)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-55955 suppress
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
CWE-287 Improper Authentication
CVSSv3:
Base Score: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-55956 suppress
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CWE-285 Improper Authorization
CVSSv3:
Base Score: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-50229 suppress
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVSSv3:
Base Score: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-66299 suppress
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
tomcat-embed-core-11.0.24.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/11.0.24/tomcat-embed-core-11.0.24.jar
MD5: 87410cbfa90c782419859efb70e1fd91
SHA1: 0172bb449cba1a8ffcffa249727907602a4cc899
SHA256: e7b966dcaac8c5ffa4f10e44031ebf5b71f2123560c08ac8b7120028615aea08
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
tomcat-embed-core-11.0.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-core High
Vendor jar package name apache Highest
Vendor jar package name core Highest
Vendor jar package name tomcat Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.1";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.1";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/http/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-core Highest
Vendor pom artifactid tomcat-embed-core Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-core High
Product jar package name annotation Highest
Product jar package name apache Highest
Product jar package name auth Highest
Product jar package name core Highest
Product jar package name descriptor Highest
Product jar package name http Highest
Product jar package name jakarta Highest
Product jar package name message Highest
Product jar package name security Highest
Product jar package name servlet Highest
Product jar package name tomcat Highest
Product Manifest Bundle-Name tomcat-embed-core Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.1";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.1";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/security/auth/message/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/callback/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/callback/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/config/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/config/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/module/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/module/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/servlet/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/annotation/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/annotation/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/descriptor/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/descriptor/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/http/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/http/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/resources/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/resources/ Specification-Title Jakarta Servlet Medium
Product pom artifactid tomcat-embed-core Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 11.0.24 High
Version Manifest Bundle-Version 11.0.24 High
Version Manifest Implementation-Version 11.0.24 High
Version pom version 11.0.24 Highest
Related Dependencies
tomcat-embed-websocket-11.0.24.jar
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/11.0.24/tomcat-embed-websocket-11.0.24.jar
MD5: 4276fc81c04ef0458c5111a0726ad22b
SHA1: 8cd43556888f042c90115d54b124a4648f2b413f
SHA256: 825160101f0da4a10e19b5730c2ae2f99f8c2c7a7211ac05562726c5e97ab91e
pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@11.0.24
CVE-2026-65637 suppress
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-20 Improper Input Validation
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65905 suppress
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-294 Authentication Bypass by Capture-replay
CVSSv3:
Base Score: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65182 suppress
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
CWE-863 Incorrect Authorization, CWE-284 Improper Access Control
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68525 suppress
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
CWE-863 Incorrect Authorization
CVSSv3:
Base Score: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65183 suppress
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-66422 suppress
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-285 Improper Authorization
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68569 suppress
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-287 Improper Authentication
CVSSv3:
Base Score: HIGH (8.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-65927 suppress
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121 which fix the issue.
CWE-193 Off-by-one Error
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-68763 suppress
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-73180 suppress
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CWE-613 Insufficient Session Expiration
CVSSv3:
Base Score: MEDIUM (6.8)
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
CVE-2026-66299 suppress
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RC:R/MAV:A
References:
Vulnerable Software & Versions: (show all )
tomcat-embed-el-10.1.55.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/10.1.55/tomcat-embed-el-10.1.55.jar
MD5: 3aa05b1e98fe6122d642e890db5f599c
SHA1: 202f2de13bd61be720cf302f28d63eda558d29f3
SHA256: a527fe51c6f9428c5116f78fe28588e55357b4492309b51fb0453372da16fa5f
Referenced In Project/Scope: waffle-demo-spring-boot-filter3:compile
tomcat-embed-el-10.1.55.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.5.16
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-el High
Vendor jar package name apache Highest
Vendor jar package name el Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="5.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/el/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-el Highest
Vendor pom artifactid tomcat-embed-el Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-el High
Product jar package name apache Highest
Product jar package name el Highest
Product jar package name expression Highest
Product jar package name expressionfactory Highest
Product jar package name expressionfactoryimpl Highest
Product jar package name jakarta Highest
Product Manifest Bundle-Name tomcat-embed-jasper-el Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="5.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/el/ Implementation-Title jakarta.annotation Medium
Product manifest: jakarta/el/ Specification-Title Jakarta Expression Language Medium
Product pom artifactid tomcat-embed-el Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 10.1.55 High
Version Manifest Bundle-Version 10.1.55 High
Version Manifest Implementation-Version 10.1.55 High
Version pom version 10.1.55 Highest
pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@10.1.55
(Confidence :High)
tomcat-embed-el-11.0.24.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/11.0.24/tomcat-embed-el-11.0.24.jar
MD5: cb6b040782afb670264116a994b0bcae
SHA1: 3eafa072a45e67081452e56576ab4fe68b525fb5
SHA256: ad0546f12dace008aacce18ba13222137760b310ca719e173d3e13021b9af6c6
Referenced In Project/Scope: waffle-demo-spring-boot-filter4:compile
tomcat-embed-el-11.0.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.1.1
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-el High
Vendor jar package name apache Highest
Vendor jar package name el Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="6.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/el/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-el Highest
Vendor pom artifactid tomcat-embed-el Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-el High
Product jar package name apache Highest
Product jar package name el Highest
Product jar package name expression Highest
Product jar package name expressionfactory Highest
Product jar package name expressionfactoryimpl Highest
Product jar package name jakarta Highest
Product Manifest Bundle-Name tomcat-embed-jasper-el Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="6.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/el/ Implementation-Title jakarta.annotation Medium
Product manifest: jakarta/el/ Specification-Title Jakarta Expression Language Medium
Product pom artifactid tomcat-embed-el Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 11.0.24 High
Version Manifest Bundle-Version 11.0.24 High
Version Manifest Implementation-Version 11.0.24 High
Version pom version 11.0.24 Highest
pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@11.0.24
(Confidence :High)