Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

Project: waffle-shiro

com.github.waffle:waffle-shiro:3.6.1-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

Dependency Vulnerability IDs Package Highest Severity CVE Count Confidence Evidence Count
bcprov-jdk18on-1.84.jar cpe:2.3:a:bouncycastle:bouncy_castle_for_java:1.84:*:*:*:*:*:*:* pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84   0 Highest 49
caffeine-3.2.4.jar pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.4   0 33
checker-qual-4.2.3.jar pkg:maven/org.checkerframework/checker-qual@4.2.3   0 44
com.github.waffle:waffle-jna:3.6.1-SNAPSHOT pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT   0 6
commons-beanutils-1.11.0.jar cpe:2.3:a:apache:commons_beanutils:1.11.0:*:*:*:*:*:*:* pkg:maven/commons-beanutils/commons-beanutils@1.11.0   0 Highest 170
commons-logging-1.3.5.jar pkg:maven/commons-logging/commons-logging@1.3.5   0 129
encoder-1.4.0.jar pkg:maven/org.owasp.encoder/encoder@1.4.0   0 33
error_prone_annotations-2.50.0.jar pkg:maven/com.google.errorprone/error_prone_annotations@2.50.0   0 29
j2objc-annotations-3.1.jar pkg:maven/com.google.j2objc/j2objc-annotations@3.1   0 33
jakarta.servlet-api-4.0.4.jar pkg:maven/jakarta.servlet/jakarta.servlet-api@4.0.4   0 43
jna-5.19.1.jar pkg:maven/net.java.dev.jna/jna@5.19.1   0 48
jna-5.19.1.jar: jnidispatch.dll   0 2
jna-5.19.1.jar: jnidispatch.dll   0 2
jna-5.19.1.jar: jnidispatch.dll   0 2
jna-platform-5.19.1.jar pkg:maven/net.java.dev.jna/jna-platform@5.19.1   0 42
jspecify-1.0.0.jar pkg:maven/org.jspecify/jspecify@1.0.0   0 32
jsr305-3.0.2.jar pkg:maven/com.google.code.findbugs/jsr305@3.0.2   0 17
shiro-core-2.2.1.jar cpe:2.3:a:apache:shiro:2.2.1:*:*:*:*:*:*:* pkg:maven/org.apache.shiro/shiro-core@2.2.1 MEDIUM 1 Highest 33
slf4j-api-2.0.19.jar pkg:maven/org.slf4j/slf4j-api@2.0.19   0 29
spotbugs-annotations-4.10.4.jar pkg:maven/com.github.spotbugs/spotbugs-annotations@4.10.4   0 53

Dependencies (vulnerable)

bcprov-jdk18on-1.84.jar

Description:

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains the  JCA/JCE provider and low-level API for the BC Java version 1.84 for Java 1.8 and later.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /home/runner/.m2/repository/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar
MD5: 19523b0cbcbce2fdeb98e3eaf68f602e
SHA1: 2d5651789941d2f8ae9b8771f23356de6b61e96b
SHA256:64d6c5a6121fcd927152dd182cbed39afe0fda641a970d9bcc0c9cb1858b2731
Referenced In Project/Scope: waffle-shiro:provided
bcprov-jdk18on-1.84.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.shiro/shiro-web@2.2.1

Identifiers

caffeine-3.2.4.jar

Description:

A high performance caching library

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.4/caffeine-3.2.4.jar
MD5: 04d655feb58be297a86fa2814a1f1ef8
SHA1: c63b303adf59c733d2a96125ad6670e938a2c15d
SHA256:9d9d2cfd681fd9272ded3d27c9930db12f89f732345975aa113ebc223bbf1224
Referenced In Project/Scope: waffle-shiro:compile
caffeine-3.2.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.4   (Confidence:High)

checker-qual-4.2.3.jar

Description:

checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.

License:

The MIT License: https://opensource.org/licenses/MIT
File Path: /home/runner/.m2/repository/org/checkerframework/checker-qual/4.2.3/checker-qual-4.2.3.jar
MD5: d9e63a451931be32bd29cfc3ac5674c1
SHA1: d2a10af5c8574adfe24f5e35ff56cca92af2e916
SHA256:f868f731f6e37db3e1c2140d06016477989959a2d13fc5bed9c46760cffd5ba0
Referenced In Project/Scope: waffle-shiro:compile
checker-qual-4.2.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/org.checkerframework/checker-qual@4.2.3   (Confidence:High)

com.github.waffle:waffle-jna:3.6.1-SNAPSHOT

Description:

WAFFLE JNA implementation

License:

MIT https://opensource.org/licenses/MIT
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-jna/pom.xml

Referenced In Project/Scope: waffle-shiro
com.github.waffle:waffle-jna:3.6.1-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT   (Confidence:Highest)

commons-beanutils-1.11.0.jar

Description:

Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-beanutils/commons-beanutils/1.11.0/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256:9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Project/Scope: waffle-shiro:provided
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

commons-logging-1.3.5.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well-known logging systems.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.3.5/commons-logging-1.3.5.jar
MD5: 9ca067b073153c86c2da350c0f2cdf70
SHA1: a3fcc5d3c29b2b03433aa2d2f2d2c1b1638924a1
SHA256:6d7a744e4027649fbb50895df9497d109f98c766a637062fe8d2eabbb3140ba4
Referenced In Project/Scope: waffle-shiro:provided
commons-logging-1.3.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/commons-beanutils/commons-beanutils@1.11.0

Identifiers

  • pkg:maven/commons-logging/commons-logging@1.3.5   (Confidence:High)

encoder-1.4.0.jar

Description:

        The OWASP Encoders package is a collection of high-performance low-overhead
        contextual encoders, that when utilized correctly, is an effective tool in
        preventing Web Application security vulnerabilities such as Cross-Site
        Scripting.
    

License:

http://www.opensource.org/licenses/BSD-3-Clause
File Path: /home/runner/.m2/repository/org/owasp/encoder/encoder/1.4.0/encoder-1.4.0.jar
MD5: d26a36885af1fd62e8a3c18ec51ed39c
SHA1: 41560c4db1cae2290402eee6ea0db544e8d48b7f
SHA256:90f9860925905dd97f313cffae065835eb02acc3e2e9b0051621693efd09025c
Referenced In Project/Scope: waffle-shiro:provided
encoder-1.4.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.shiro/shiro-web@2.2.1

Identifiers

  • pkg:maven/org.owasp.encoder/encoder@1.4.0   (Confidence:High)

error_prone_annotations-2.50.0.jar

Description:

Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/errorprone/error_prone_annotations/2.50.0/error_prone_annotations-2.50.0.jar
MD5: 1ded1848cfd4f5167e00824faf9c4d3b
SHA1: 74ba43e49ab1184d41634af2ef0047e82c4064b0
SHA256:4667724877f1d37a689202da191e23efa7657c62eef93ccdac406eccfe5cdd0a
Referenced In Project/Scope: waffle-shiro:provided
error_prone_annotations-2.50.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/com.google.errorprone/error_prone_annotations@2.50.0   (Confidence:High)

j2objc-annotations-3.1.jar

Description:

    A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/j2objc/j2objc-annotations/3.1/j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256:84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Project/Scope: waffle-shiro:provided
j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/com.google.j2objc/j2objc-annotations@3.1   (Confidence:High)

jakarta.servlet-api-4.0.4.jar

Description:

Jakarta Servlet 4.0

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/servlet/jakarta.servlet-api/4.0.4/jakarta.servlet-api-4.0.4.jar
MD5: f5d1d7a29978e4ae0be5a456ee1c65c3
SHA1: b8a1142e04838fe54194049c6e7a18dae8f9b960
SHA256:586e27706c21258f5882f43be06904f49b02db9ac54e345d393fe4a32494d127
Referenced In Project/Scope: waffle-shiro:provided
jakarta.servlet-api-4.0.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/jakarta.servlet/jakarta.servlet-api@4.0.4   (Confidence:High)

jna-5.19.1.jar

Description:

Java Native Access

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar
MD5: cf327da3e9cf5a5d77c8a43540320929
SHA1: ca303052cd617c1af2e2c8d344c98a706fb63143
SHA256:4fb141dd8ef6b0585ffceea4bc49602fbc6312fa977e2c488794ea3e6aafecae
Referenced In Project/Scope: waffle-shiro:compile
jna-5.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/net.java.dev.jna/jna@5.19.1   (Confidence:High)

jna-5.19.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256:b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Project/Scope: waffle-shiro:compile

Identifiers

  • None

jna-5.19.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256:5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Project/Scope: waffle-shiro:compile

Identifiers

  • None

jna-5.19.1.jar: jnidispatch.dll

File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.19.1/jna-5.19.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256:752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Project/Scope: waffle-shiro:compile

Identifiers

  • None

jna-platform-5.19.1.jar

Description:

Java Native Access Platform

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna-platform/5.19.1/jna-platform-5.19.1.jar
MD5: 1d97b6103a9b3b7ddb671908683f4566
SHA1: d1e54d9231da5ca3fa730d52960deaa555475468
SHA256:3b3864f5b449e9c3c24b16861524b622b086563f44e0cd8384c8efc5a6052f82
Referenced In Project/Scope: waffle-shiro:compile
jna-platform-5.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/net.java.dev.jna/jna-platform@5.19.1   (Confidence:High)

jspecify-1.0.0.jar

Description:

An artifact of well-named and well-specified annotations to power static analysis checks

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256:1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Project/Scope: waffle-shiro:compile
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.1.3

Identifiers

  • pkg:maven/org.jspecify/jspecify@1.0.0   (Confidence:High)

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: waffle-shiro:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.10.4

Identifiers

  • pkg:maven/com.google.code.findbugs/jsr305@3.0.2   (Confidence:High)

shiro-core-2.2.1.jar

Description:

Apache Shiro is a powerful and flexible open-source security framework that cleanly handles        authentication, authorization, enterprise session management, single sign-on and cryptography services.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/shiro/shiro-core/2.2.1/shiro-core-2.2.1.jar
MD5: 3b83eaa1cf9fff4febadafc3a8dd1ea9
SHA1: 23d29cf0f69bd91049780b4d3b77e028a505abd3
SHA256:688489d58e00d40476e67be2cae8f349a6d51a21c0d16e4d856bcc6f6c9c2001
Referenced In Project/Scope: waffle-shiro:provided
shiro-core-2.2.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.shiro/shiro-web@2.2.1

Identifiers

CVE-2026-58301  

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module.

Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. +
Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.
CWE-918 Server-Side Request Forgery (SSRF)

CVSSv4:
  • Base Score: MEDIUM (5.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:D/RE:L/U:Amber
CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RC:R/MAV:A

References:

Vulnerable Software & Versions:

slf4j-api-2.0.19.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.19/slf4j-api-2.0.19.jar
MD5: 1ca3a2acac3d5947b37d9b5536c55829
SHA1: efad9817997b3a6ce9e058f92e612917a744c290
SHA256:e91ff6d720609e7a194ffe758c3ed5c84e798617ae07b0a0f6a4fe229741b4bb
Referenced In Project/Scope: waffle-shiro:compile
slf4j-api-2.0.19.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-jna@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/org.slf4j/slf4j-api@2.0.19   (Confidence:High)

spotbugs-annotations-4.10.4.jar

Description:

Annotations the SpotBugs tool supports

License:

GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.10.4/spotbugs-annotations-4.10.4.jar
MD5: 472925cb4e5451c8f7a1aeeefe286622
SHA1: 7eb4c58212378becfb6ea6d236ec24a2352a316e
SHA256:28fa4befaddce5d7b79b07c68e7c12fa27c5d9282c4229528717971606661ea3
Referenced In Project/Scope: waffle-shiro:provided
spotbugs-annotations-4.10.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.waffle/waffle-shiro@3.6.1-SNAPSHOT

Identifiers

  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.10.4   (Confidence:High)


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype Guide OSS Index API.