Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

Project: waffle-demo-parent

com.github.waffle.demo:waffle-demo-parent:3.6.0-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

Dependency Vulnerability IDs Package Highest Severity CVE Count Confidence Evidence Count
caffeine-3.2.3.jar pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3   0 33
checker-qual-3.53.0.jar pkg:maven/org.checkerframework/checker-qual@3.53.0   0 44
com.github.waffle:waffle-jna:3.6.0-SNAPSHOT pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT   0 6
com.github.waffle:waffle-spring-boot-autoconfigure2:3.6.0-SNAPSHOT pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure2@3.6.0-SNAPSHOT   0 6
com.github.waffle:waffle-spring-boot-starter2:3.6.0-SNAPSHOT pkg:maven/com.github.waffle/waffle-spring-boot-starter2@3.6.0-SNAPSHOT   0 6
com.github.waffle:waffle-spring-security5:3.6.0-SNAPSHOT pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT   0 6
com.github.waffle:waffle-tomcat9:3.6.0-SNAPSHOT pkg:maven/com.github.waffle/waffle-tomcat9@3.6.0-SNAPSHOT   0 6
commons-logging-1.3.5.jar pkg:maven/commons-logging/commons-logging@1.3.5   0 129
error_prone_annotations-2.46.0.jar pkg:maven/com.google.errorprone/error_prone_annotations@2.46.0   0 29
j2objc-annotations-3.1.jar pkg:maven/com.google.j2objc/j2objc-annotations@3.1   0 33
jackson-annotations-2.21.jar cpe:2.3:a:fasterxml:jackson-modules-java8:2.21:*:*:*:*:*:*:* pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21   0 Low 36
jackson-core-2.21.0.jar cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.0:*:*:*:*:*:*:* pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.0   0 Low 47
jackson-databind-2.21.0.jar cpe:2.3:a:fasterxml:jackson-databind:2.21.0:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.0:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.0   0 Highest 41
jakarta.annotation-api-1.3.5.jar cpe:2.3:a:oracle:projects:1.3.5:*:*:*:*:*:*:* pkg:maven/jakarta.annotation/jakarta.annotation-api@1.3.5   0 Low 35
jakarta.servlet-api-4.0.4.jar cpe:2.3:a:oracle:projects:4.0.4:*:*:*:*:*:*:* pkg:maven/jakarta.servlet/jakarta.servlet-api@4.0.4   0 Low 43
jna-5.18.1.jar cpe:2.3:a:oracle:java_se:5.18.1:*:*:*:*:*:*:* pkg:maven/net.java.dev.jna/jna@5.18.1   0 Low 48
jna-5.18.1.jar: jnidispatch.dll   0 2
jna-5.18.1.jar: jnidispatch.dll   0 2
jna-5.18.1.jar: jnidispatch.dll   0 2
jna-platform-5.18.1.jar pkg:maven/net.java.dev.jna/jna-platform@5.18.1   0 42
jspecify-1.0.0.jar pkg:maven/org.jspecify/jspecify@1.0.0   0 32
jsr305-3.0.2.jar pkg:maven/com.google.code.findbugs/jsr305@3.0.2   0 17
jul-to-slf4j-1.7.36.jar pkg:maven/org.slf4j/jul-to-slf4j@1.7.36   0 28
log4j-api-2.25.3.jar cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:* pkg:maven/org.apache.logging.log4j/log4j-api@2.25.3   0 Highest 43
log4j-to-slf4j-2.25.3.jar pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.25.3   0 39
logback-core-1.5.25.jar cpe:2.3:a:qos:logback:1.5.25:*:*:*:*:*:*:* pkg:maven/ch.qos.logback/logback-core@1.5.25   0 Highest 39
slf4j-api-2.0.17.jar pkg:maven/org.slf4j/slf4j-api@2.0.17   0 29
snakeyaml-2.5.jar cpe:2.3:a:snakeyaml_project:snakeyaml:2.5:*:*:*:*:*:*:* pkg:maven/org.yaml/snakeyaml@2.5   0 Highest 42
spotbugs-annotations-4.9.8.jar pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8   0 53
spring-boot-2.7.18.jar cpe:2.3:a:vmware:spring_boot:2.7.18:*:*:*:*:*:*:* pkg:maven/org.springframework.boot/spring-boot@2.7.18   0 Highest 38
spring-core-5.3.39.jar cpe:2.3:a:pivotal_software:spring_framework:5.3.39:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.3.39:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.3.39:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-core@5.3.39 MEDIUM 1 Highest 37
spring-security-core-5.8.16.jar cpe:2.3:a:pivotal_software:spring_security:5.8.16:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.8.16:*:*:*:*:*:*:*
pkg:maven/org.springframework.security/spring-security-core@5.8.16   0 Highest 38
spring-web-5.3.39.jar cpe:2.3:a:pivotal_software:spring_framework:5.3.39:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.3.39:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.3.39:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-web@5.3.39 CRITICAL 2 Highest 35
tomcat-embed-core-9.0.113.jar cpe:2.3:a:apache:tomcat:9.0.113:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:9.0.113:*:*:*:*:*:*:*
pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.113   0 Highest 65
tomcat-embed-el-9.0.113.jar pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.113   0 33

Dependencies (vulnerable)

caffeine-3.2.3.jar

Description:

A high performance caching library

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.3/caffeine-3.2.3.jar
MD5: 0258f45d43968523cc11beeb01b240f2
SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19
SHA256:ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

caffeine-3.2.3.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-tomcat9@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3   (Confidence:High)

checker-qual-3.53.0.jar

Description:

checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.

License:

The MIT License: http://opensource.org/licenses/MIT
File Path: /home/runner/.m2/repository/org/checkerframework/checker-qual/3.53.0/checker-qual-3.53.0.jar
MD5: d1ee2a3366a19a8fff01208da2adb48e
SHA1: af1105964a03d7ed8aaf8ea2cb6ec0da7ec6c7a6
SHA256:7ca002815d92fad79e966b375c2ee7b2b4bf953024bc9a5d5e0c59df13ff5af8
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

checker-qual-3.53.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.hazendaz.jmockit/jmockit@2.1.0
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.hazendaz.jmockit/jmockit@2.1.0
  • pkg:maven/com.github.hazendaz.jmockit/jmockit@2.1.0
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/org.checkerframework/checker-qual@3.53.0   (Confidence:High)

com.github.waffle:waffle-jna:3.6.0-SNAPSHOT

Description:

WAFFLE JNA implementation

License:

MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-jna/pom.xml

Referenced In Projects/Scopes:
  • waffle-demo-spring-form
  • waffle-demo-negotiate
  • waffle-demo-jaas
  • waffle-demo-form
  • waffle-demo-spring-boot-filter2
  • waffle-demo-filter
  • waffle-demo-mixed-post
  • waffle-demo-spring-filter
  • waffle-demo-mixed

com.github.waffle:waffle-jna:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-jaas@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT   (Confidence:Highest)

com.github.waffle:waffle-spring-boot-autoconfigure2:3.6.0-SNAPSHOT

Description:

Spring Boot 2 Autoconfigure for WAFFLE

License:

MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot2/waffle-spring-boot-autoconfigure2/pom.xml

Referenced In Project/Scope: waffle-demo-spring-boot-filter2
com.github.waffle:waffle-spring-boot-autoconfigure2:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure2@3.6.0-SNAPSHOT   (Confidence:Highest)

com.github.waffle:waffle-spring-boot-starter2:3.6.0-SNAPSHOT

Description:

Spring Boot 2 Starter for WAFFLE

License:

MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-boot2/waffle-spring-boot-starter2/pom.xml

Referenced In Project/Scope: waffle-demo-spring-boot-filter2
com.github.waffle:waffle-spring-boot-starter2:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-spring-boot-starter2@3.6.0-SNAPSHOT   (Confidence:Highest)

com.github.waffle:waffle-spring-security5:3.6.0-SNAPSHOT

Description:

Spring Security 5 integration for WAFFLE

License:

MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-security5/pom.xml

Referenced In Projects/Scopes:
  • waffle-demo-spring-form
  • waffle-demo-spring-boot-filter2
  • waffle-demo-spring-filter

com.github.waffle:waffle-spring-security5:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT   (Confidence:Highest)

com.github.waffle:waffle-tomcat9:3.6.0-SNAPSHOT

Description:

Tomcat 9 integration for WAFFLE

License:

MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-tomcat9/pom.xml

Referenced In Projects/Scopes:
  • waffle-demo-negotiate
  • waffle-demo-filter
  • waffle-demo-mixed-post
  • waffle-demo-mixed

com.github.waffle:waffle-tomcat9:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-tomcat9@3.6.0-SNAPSHOT   (Confidence:Highest)

commons-logging-1.3.5.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well-known logging systems.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.3.5/commons-logging-1.3.5.jar
MD5: 9ca067b073153c86c2da350c0f2cdf70
SHA1: a3fcc5d3c29b2b03433aa2d2f2d2c1b1638924a1
SHA256:6d7a744e4027649fbb50895df9497d109f98c766a637062fe8d2eabbb3140ba4
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-spring-filter:compile

commons-logging-1.3.5.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-boot-starter2@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/commons-logging/commons-logging@1.3.5   (Confidence:High)

error_prone_annotations-2.46.0.jar

Description:

Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/errorprone/error_prone_annotations/2.46.0/error_prone_annotations-2.46.0.jar
MD5: d0dabea249c067d21d7eb997fbdf5c99
SHA1: 4ecb5d2392c38c46e6cb65e1bf60be708d97005d
SHA256:b67be81ff4b956401146e14eaf1526bc435a9480f2546e91eb45b796631a8a99
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:provided
  • waffle-demo-spring-boot-filter2:provided
  • waffle-demo-jaas:provided
  • waffle-demo-spring-filter:provided
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:provided
  • waffle-demo-mixed-post:provided
  • waffle-demo-form:provided
  • waffle-demo-parent:provided
  • waffle-demo-mixed:provided

error_prone_annotations-2.46.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-parent@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-jaas@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.google.errorprone/error_prone_annotations@2.46.0   (Confidence:High)

j2objc-annotations-3.1.jar

Description:

    A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/j2objc/j2objc-annotations/3.1/j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256:84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:provided
  • waffle-demo-spring-boot-filter2:provided
  • waffle-demo-jaas:provided
  • waffle-demo-spring-filter:provided
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:provided
  • waffle-demo-mixed-post:provided
  • waffle-demo-form:provided
  • waffle-demo-parent:provided
  • waffle-demo-mixed:provided

j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-jaas@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-parent@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.google.j2objc/j2objc-annotations@3.1   (Confidence:High)

jackson-annotations-2.21.jar

Description:

Core annotations used for value types, used by Jackson data binding package.
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.21/jackson-annotations-2.21.jar
MD5: e0d0c3e7300954f73e43c67d933aaea4
SHA1: b1bc1868bf02dc0bd6c7836257a036a331005309
SHA256:53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
jackson-annotations-2.21.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18

Identifiers

  • pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21   (Confidence:High)
  • cpe:2.3:a:fasterxml:jackson-modules-java8:2.21:*:*:*:*:*:*:*   (Confidence:Low)   

jackson-core-2.21.0.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.21.0/jackson-core-2.21.0.jar
MD5: eeaf6f2d71789f1c04ba944aeaa8e18e
SHA1: 1f7c3f82e6e2ef5def0a12d7dd754e26f0c0ae28
SHA256:e22604bcd9b24e462d5df102007cb06e1ed811e86f1ce6081ca62f385f2db87b
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
jackson-core-2.21.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18

Identifiers

  • pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.0   (Confidence:High)
  • cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.0:*:*:*:*:*:*:*   (Confidence:Low)   

jackson-databind-2.21.0.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.21.0/jackson-databind-2.21.0.jar
MD5: 6da51758193ce8b00c39e742010b6c45
SHA1: a6b96ee168ca8734a293b6dc70acd5d495119521
SHA256:0057817ee40bc71544072dc2a3ba575ef91dce53a2d87489bde91c05f3a22621
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
jackson-databind-2.21.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18

Identifiers

jakarta.annotation-api-1.3.5.jar

Description:

Jakarta Annotations API

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/annotation/jakarta.annotation-api/1.3.5/jakarta.annotation-api-1.3.5.jar
MD5: 8b165cf58df5f8c2a222f637c0a07c97
SHA1: 59eb84ee0d616332ff44aba065f3888cf002cd2d
SHA256:85fb03fc054cdf4efca8efd9b6712bbb418e1ab98241c4539c8585bbc23e1b8a
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
jakarta.annotation-api-1.3.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

  • pkg:maven/jakarta.annotation/jakarta.annotation-api@1.3.5   (Confidence:High)
  • cpe:2.3:a:oracle:projects:1.3.5:*:*:*:*:*:*:*   (Confidence:Low)   

jakarta.servlet-api-4.0.4.jar

Description:

Jakarta Servlet 4.0

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jakarta.servlet-api/4.0.4/jakarta.servlet-api-4.0.4.jar
MD5: f5d1d7a29978e4ae0be5a456ee1c65c3
SHA1: b8a1142e04838fe54194049c6e7a18dae8f9b960
SHA256:586e27706c21258f5882f43be06904f49b02db9ac54e345d393fe4a32494d127
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:provided
  • waffle-demo-spring-boot-filter2:provided
  • waffle-demo-jaas:provided
  • waffle-demo-spring-filter:provided
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:provided
  • waffle-demo-mixed-post:provided
  • waffle-demo-form:provided
  • waffle-demo-parent:provided
  • waffle-demo-mixed:provided

jakarta.servlet-api-4.0.4.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-parent@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-jaas@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/jakarta.servlet/jakarta.servlet-api@4.0.4   (Confidence:High)
  • cpe:2.3:a:oracle:projects:4.0.4:*:*:*:*:*:*:*   (Confidence:Low)   

jna-5.18.1.jar

Description:

Java Native Access

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar
MD5: cb531ec131e1c68c045b5d45fe5b9878
SHA1: b27ba04287cc4abe769642fe8318d39fc89bf937
SHA256:260c4b1e22b1db9e110ee441c4f13ce115f841fa48c41d78750986214b395557
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

jna-5.18.1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-tomcat9@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/net.java.dev.jna/jna@5.18.1   (Confidence:High)
  • cpe:2.3:a:oracle:java_se:5.18.1:*:*:*:*:*:*:*   (Confidence:Low)   

jna-5.18.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256:b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Projects/Scopes:

  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

Identifiers

  • None

jna-5.18.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256:5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Projects/Scopes:

  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

Identifiers

  • None

jna-5.18.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256:752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Projects/Scopes:

  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

Identifiers

  • None

jna-platform-5.18.1.jar

Description:

Java Native Access Platform

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna-platform/5.18.1/jna-platform-5.18.1.jar
MD5: a7af00779ec98bfe22dfb07b1532830d
SHA1: dd817f391efc492041c9ae91127527c13750a789
SHA256:ad14c1b1ec4f43d396231219dfa635ebf828f738eac9f890ea1bc07795892d9a
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

jna-platform-5.18.1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-tomcat9@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/net.java.dev.jna/jna-platform@5.18.1   (Confidence:High)

jspecify-1.0.0.jar

Description:

An artifact of well-named and well-specified annotations to power static analysis checks

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256:1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:compile
  • waffle-demo-mixed-post:provided
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-mixed:provided
  • waffle-demo-spring-filter:compile

jspecify-1.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
  • pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3
  • pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2
  • pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.2

Identifiers

  • pkg:maven/org.jspecify/jspecify@1.0.0   (Confidence:High)

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:provided
  • waffle-demo-spring-boot-filter2:provided
  • waffle-demo-jaas:provided
  • waffle-demo-spring-filter:provided
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:provided
  • waffle-demo-mixed-post:provided
  • waffle-demo-form:provided
  • waffle-demo-parent:provided
  • waffle-demo-mixed:provided

jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8

Identifiers

  • pkg:maven/com.google.code.findbugs/jsr305@3.0.2   (Confidence:High)

jul-to-slf4j-1.7.36.jar

Description:

JUL to SLF4J bridge

File Path: /home/runner/.m2/repository/org/slf4j/jul-to-slf4j/1.7.36/jul-to-slf4j-1.7.36.jar
MD5: 2a3fe73e6cafe8f102facaf2dd65353f
SHA1: ed46d81cef9c412a88caef405b58f93a678ff2ca
SHA256:9e641fb142c5f0b0623d6222c09ea87523a41bf6bed48ac79940724010b989de
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
jul-to-slf4j-1.7.36.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

  • pkg:maven/org.slf4j/jul-to-slf4j@1.7.36   (Confidence:High)

log4j-api-2.25.3.jar

Description:

The logging API of the Log4j project.
    Library and application code can log through this API.
    It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
    Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core.

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-api/2.25.3/log4j-api-2.25.3.jar
MD5: 7061652b4274beeaa657ec908e83f491
SHA1: fb385330d89c2d61058ef649403f214633569205
SHA256:e886682920fa0fb9d6eb6395dcb4de088443f8646c89c5e5846e168e327f406f
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
log4j-api-2.25.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

log4j-to-slf4j-2.25.3.jar

Description:

Forwards the Log4j API calls to SLF4J.
    (Refer to the `log4j-slf4j[2]-impl` artifacts for forwarding SLF4J to the Log4j API.)

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-to-slf4j/2.25.3/log4j-to-slf4j-2.25.3.jar
MD5: f515a81b64474e5faf389ab8611e123a
SHA1: 30adfb40cca243ec88cf7ec1fddb411ab55faa4f
SHA256:90a09280390c54a28ac1514ded7c5293f3fe62f4448bf371b4e2415272e67a3d
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
log4j-to-slf4j-2.25.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

  • pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.25.3   (Confidence:High)

logback-core-1.5.25.jar

Description:

logback-core module

License:

http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-core/1.5.25/logback-core-1.5.25.jar
MD5: 6a1c2feb8e1ecb20417a4d0e74c9ad51
SHA1: 137f4ae0af7acaa0f9600a2ca18ddc9f3a0b899b
SHA256:aeb86d749936a960a1ec897aa821fe611ab6b105f1170ad334ae5eadc4bd689c
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:compile
  • waffle-demo-mixed:compile
  • waffle-demo-filter:compile
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-mixed-post:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-parent:compile
  • waffle-demo-spring-filter:compile

logback-core-1.5.25.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25

Identifiers

slf4j-api-2.0.17.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256:7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Projects/Scopes:
  • waffle-demo-form:compile
  • waffle-demo-negotiate:compile
  • waffle-demo-mixed:compile
  • waffle-demo-filter:compile
  • waffle-demo-jaas:compile
  • waffle-demo-spring-form:compile
  • waffle-demo-mixed-post:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-parent:compile
  • waffle-demo-spring-filter:compile

slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/ch.qos.logback/logback-classic@1.5.25
  • pkg:maven/com.github.waffle/waffle-jna@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/org.slf4j/slf4j-api@2.0.17   (Confidence:High)

snakeyaml-2.5.jar

Description:

YAML 1.1 parser and emitter for Java

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/yaml/snakeyaml/2.5/snakeyaml-2.5.jar
MD5: 8d3b7581db5c7620db55183f33a4f2ad
SHA1: 2d53ddec134280cb384c1e35d094e5f71c1f2316
SHA256:e6682acf1ace77508ef13649cbf4f8d09d2cf5457bdb61d25ffb6ac0233d78dd
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
snakeyaml-2.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

spotbugs-annotations-4.9.8.jar

Description:

Annotations the SpotBugs tool supports

License:

GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.9.8/spotbugs-annotations-4.9.8.jar
MD5: d4c2e7bd090be697ad409a4e75684a94
SHA1: ca4a2783a6123e67124fd7feb4caccd2e2ac9a73
SHA256:6f69d6fe9c55a54dcb30e87d8fa2d5f52246af50d7a3445246d9539ef221be1c
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:provided
  • waffle-demo-spring-boot-filter2:provided
  • waffle-demo-jaas:provided
  • waffle-demo-spring-filter:provided
  • waffle-demo-negotiate:provided
  • waffle-demo-filter:provided
  • waffle-demo-mixed-post:provided
  • waffle-demo-form:provided
  • waffle-demo-parent:provided
  • waffle-demo-mixed:provided

spotbugs-annotations-4.9.8.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle.demo/waffle-demo-jaas@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-parent@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-mixed-post@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-form@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-filter@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-spring-boot-filter2@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle.demo/waffle-demo-negotiate@3.6.0-SNAPSHOT

Identifiers

  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8   (Confidence:High)

spring-boot-2.7.18.jar

Description:

Spring Boot

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar
MD5: 0941c83c25204150f8bd73ae66c63fd1
SHA1: f6dbdd8da7c2bded63dff9b1f48d01a4923f20a0
SHA256:530f4e0fdfeb3a0e2b3a369d15cdea38fbdc1696f8b030c35a6ad65c27524950
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
spring-boot-2.7.18.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18

Identifiers

spring-core-5.3.39.jar

Description:

Spring Core

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/spring-core/5.3.39/spring-core-5.3.39.jar
MD5: 632d2a8c30962a69273775968c052651
SHA1: d2bff2eedf27b51d6ef9a2fc892aaff5b7a768dd
SHA256:3a1ddcf05420a9181bd9cacb6062a3edc493e14d555961ad50e1a6360eb1e75f
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-spring-filter:compile

spring-core-5.3.39.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.springframework.boot/spring-boot-starter@2.7.18
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT

Identifiers

CVE-2024-38820  

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
NVD-CWE-noinfo, CWE-178 Improper Handling of Case Sensitivity

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

spring-security-core-5.8.16.jar

Description:

Spring Security

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-core/5.8.16/spring-security-core-5.8.16.jar
MD5: c70ae997256d27ca6fb1c7a8b24e4248
SHA1: b3d21a1f967db39dabaca487ba3fe58972e6a9a5
SHA256:3be7d217048f5ea76fd6d0eddaa3169ad3bee0bba9c456e27670ec37ca33c3fd
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-spring-filter:compile

spring-security-core-5.8.16.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/com.github.waffle/waffle-spring-boot-starter2@3.6.0-SNAPSHOT

Identifiers

spring-web-5.3.39.jar

Description:

Spring Web

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/spring-web/5.3.39/spring-web-5.3.39.jar
MD5: 2b940bc714d6e29570b5dfa92755eefc
SHA1: 4ab03cd7376a6b3365d2798aac8d01dcd22c0174
SHA256:444f243b936119b5488029f2d9399a3980855c60b493b9e2811464c6433a2b71
Referenced In Projects/Scopes:
  • waffle-demo-spring-form:compile
  • waffle-demo-spring-boot-filter2:compile
  • waffle-demo-spring-filter:compile

spring-web-5.3.39.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT
  • pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18
  • pkg:maven/com.github.waffle/waffle-spring-security5@3.6.0-SNAPSHOT

Identifiers

CVE-2016-1000027  

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
CWE-502 Deserialization of Untrusted Data

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
  • Base Score: HIGH (7.5)
  • Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P

References:

Vulnerable Software & Versions:

CVE-2024-38820  

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
NVD-CWE-noinfo, CWE-178 Improper Handling of Case Sensitivity

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

tomcat-embed-core-9.0.113.jar

Description:

Core Tomcat implementation

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/9.0.113/tomcat-embed-core-9.0.113.jar
MD5: 7d9e5b10c51f00a2f6bb222a7db1c118
SHA1: b364692bca96817268b38f183fafd14dbd00950e
SHA256:fdd67f6953c538cebffaa27df6384f2c614bf9f5aca8947d52db38701bd13957
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
tomcat-embed-core-9.0.113.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18

Identifiers

tomcat-embed-el-9.0.113.jar

Description:

Core Tomcat implementation

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/9.0.113/tomcat-embed-el-9.0.113.jar
MD5: 80b47fc18a1348ce8b6101db8493866f
SHA1: 8f4c51d31666de2539d2e4498a6494ecc50abc61
SHA256:a6761d2504837af3805c306938603cea6982fb11a80175ca039f86fb142243b1
Referenced In Project/Scope: waffle-demo-spring-boot-filter2:compile
tomcat-embed-el-9.0.113.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.18

Identifiers

  • pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.113   (Confidence:High)


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.