Skip to content

Fix hdfs-fixture kerb-admin & hadoop-minicluster dependencies are not…

Mend for GitHub.com / Mend Security Check failed Jul 11, 2024 in 18m 57s

Security Report

The Security Check found 3 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-52428

Path to dependency file: /test/fixtures/hdfs-fixture/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.nimbusds/nimbus-jose-jwt/9.31/229ba7b31d1f886968896c48aeeba5a1586b00bc/nimbus-jose-jwt-9.31.jar

Dependency Hierarchy:

-> hadoop-minicluster-3.4.0.jar (Root Library)

   -> hadoop-common-3.4.0.jar

     -> hadoop-auth-3.4.0.jar

       -> ❌ nimbus-jose-jwt-9.31.jar (Vulnerable Library)

High 7.5 nimbus-jose-jwt-9.31.jar Upgrade to version: com.nimbusds:nimbus-jose-jwt:9.37.2 #14180
CVE-2024-29133

Path to dependency file: /test/fixtures/hdfs-fixture/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-configuration2/2.8.0/6a76acbe14d2c01d4758a57171f3f6a150dbd462/commons-configuration2-2.8.0.jar

Dependency Hierarchy:

-> hadoop-minicluster-3.4.0.jar (Root Library)

   -> hadoop-common-3.4.0.jar

     -> ❌ commons-configuration2-2.8.0.jar (Vulnerable Library)

Medium 4.4 commons-configuration2-2.8.0.jar Upgrade to version: org.apache.commons:commons-configuration2:2.10.1 #14180
CVE-2024-29131

Path to dependency file: /test/fixtures/hdfs-fixture/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-configuration2/2.8.0/6a76acbe14d2c01d4758a57171f3f6a150dbd462/commons-configuration2-2.8.0.jar

Dependency Hierarchy:

-> hadoop-minicluster-3.4.0.jar (Root Library)

   -> hadoop-common-3.4.0.jar

     -> ❌ commons-configuration2-2.8.0.jar (Vulnerable Library)

Medium 4.4 commons-configuration2-2.8.0.jar Upgrade to version: org.apache.commons:commons-configuration2:2.10.1 #14180

Total libraries scanned: 626
Scan token: 6abeca7dfcfb4b5f98fda9295b1cf7c7