Skip to content

Bump com.azure:azure-core from 1.51.0 to 1.54.1 in /plugins/repositor…

Mend for GitHub.com / Mend Security Check failed Dec 17, 2024 in 52m 24s

Security Report

The Security Check found 2 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2024-6763

Path to dependency file: /test/fixtures/hdfs-fixture/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar

Dependency Hierarchy:

-> ❌ jetty-server-9.4.55.v20240627.jar (Vulnerable Library)

Low 3.7 jetty-server-9.4.55.v20240627.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12;org.eclipse.jetty:jetty-server:12.0.12 #16372
CVE-2024-6763

Path to dependency file: /build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar

Dependency Hierarchy:

-> hdfs-fixture-3.0.0-SNAPSHOT (Root Library)

   -> javax-websocket-server-impl-9.4.55.v20240627.jar

     -> javax-websocket-client-impl-9.4.55.v20240627.jar

       -> websocket-client-9.4.55.v20240627.jar

         -> jetty-client-9.4.55.v20240627.jar

           -> ❌ jetty-http-9.4.55.v20240627.jar (Vulnerable Library)

Low 3.7 jetty-http-9.4.55.v20240627.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12;org.eclipse.jetty:jetty-server:12.0.12 #14183

Total libraries scanned: 779
Scan token: b28724dd346a4461863cb6378a151f4a