Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.1.3Report Generated On : Mon, 27 Jul 2026 08:14:48 GMTDependencies Scanned : 19 (18 unique)Vulnerable Dependencies : 1 Vulnerabilities Found : 7Vulnerabilities Suppressed : 0 ... NVD API Last Checked : 2026-07-27T08:14:09ZNVD API Last Modified : 2026-07-27T07:16:30ZSummary Summary of Vulnerable Dependencies (click to show all)
bw-base-2.0.0.jarDescription:
This project provides base classes, types and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-base/2.0.0/bw-base-2.0.0.jar
MD5: 0480624145ad4fc5daeba898b7132099
SHA1: b24b7279e0475bb3c8c84e37af400ad87877c955
SHA256: 10d27642e3bf1f2f4f85320293b5041b7e34cba02cc2656f29e79f75cee97cc5
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - jsp support:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-base-2.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-config@6.1.0 pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-base High Vendor jar package name base Highest Vendor jar package name bedework Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-base Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-base Highest Vendor pom artifactid bw-base Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: base classes High Vendor pom url Bedework/bw-base Highest Product file name bw-base High Product jar package name base Highest Product jar package name bedework Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: base classes High Product Manifest implementation-url https://github.com/Bedework/bw-base Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: base classes Medium Product pom artifactid bw-base Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: base classes High Product pom url Bedework/bw-base High Version file version 2.0.0 High Version Manifest Implementation-Version 2.0.0 High Version pom version 2.0.0 Highest
bw-util-config-6.1.0.jarDescription:
This project provides a number of utility configuration classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-config/6.1.0/bw-util-config-6.1.0.jar
MD5: 7db546c39232fd82b5d944d498618fe6
SHA1: b8e8a91513c79a8df1eec8c216afbd7b68599389
SHA256: 360b90c0406fc847340472e7d3653f8c7c1aa2e6304fa748b15b9a89dd95c4c8
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-config-6.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-util-config High Vendor jar package name bedework Highest Vendor jar package name config Highest Vendor jar package name util Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util-conf/bw-util-config Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-config Highest Vendor pom artifactid bw-util-config Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: base configuration classes High Vendor pom url Bedework/bw-util-conf/bw-util-config Highest Product file name bw-util-config High Product jar package name bedework Highest Product jar package name config Highest Product jar package name util Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: base configuration classes High Product Manifest implementation-url https://github.com/Bedework/bw-util-conf/bw-util-config Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: base configuration classes Medium Product pom artifactid bw-util-config Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: base configuration classes High Product pom url Bedework/bw-util-conf/bw-util-config High Version file version 6.1.0 High Version Manifest Implementation-Version 6.1.0 High Version pom version 6.1.0 Highest
bw-util-jmx-6.1.0.jarDescription:
This project provides a number of utility configuration classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-jmx/6.1.0/bw-util-jmx-6.1.0.jar
MD5: 2c7532087d8a5fa7f422c3accd146533
SHA1: dbe25fb4201c3eea12f73efb8e07bb1616f2d567
SHA256: 771ace3629d3cdec7238de84c96624d056e4afcdacf78bebf7a3aee3710ce81c
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-jmx-6.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-util-jmx High Vendor jar package name bedework Highest Vendor jar package name jmx Highest Vendor jar package name util Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util-conf/bw-util-jmx Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-jmx Highest Vendor pom artifactid bw-util-jmx Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: JMX config classes High Vendor pom url Bedework/bw-util-conf/bw-util-jmx Highest Product file name bw-util-jmx High Product jar package name bedework Highest Product jar package name jmx Highest Product jar package name util Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: JMX config classes High Product Manifest implementation-url https://github.com/Bedework/bw-util-conf/bw-util-jmx Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: JMX config classes Medium Product pom artifactid bw-util-jmx Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: JMX config classes High Product pom url Bedework/bw-util-conf/bw-util-jmx High Version file version 6.1.0 High Version Manifest Implementation-Version 6.1.0 High Version pom version 6.1.0 Highest
bw-util-logging-6.0.0.jarDescription:
This project provides logging utility classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-logging/6.0.0/bw-util-logging-6.0.0.jar
MD5: 2c63b9031e2d0852a00e57753320b409
SHA1: a12c15e6670f1298c8c4779d08b24595e921aceb
SHA256: e26bbaf5a5dcad998990fdc647f448b2e2dcac6eb628be6945fe24d53759b745
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-logging-6.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-util-logging High Vendor jar package name bedework Highest Vendor jar package name logging Highest Vendor jar package name util Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util-logging Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-logging Highest Vendor pom artifactid bw-util-logging Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: logging classes High Vendor pom url Bedework/bw-util-logging Highest Product file name bw-util-logging High Product jar package name bedework Highest Product jar package name logging Highest Product jar package name util Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: logging classes High Product Manifest implementation-url https://github.com/Bedework/bw-util-logging Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: logging classes Medium Product pom artifactid bw-util-logging Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: logging classes High Product pom url Bedework/bw-util-logging High Version file version 6.0.0 High Version Manifest Implementation-Version 6.0.0 High Version pom version 6.0.0 Highest
bw-util-misc-6.1.1-SNAPSHOT.jarDescription:
This project provides a number of utility classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-misc/6.1.1-SNAPSHOT/bw-util-misc-6.1.1-SNAPSHOT.jar
MD5: d7b9b8fa6ba87568ef5f174ad292850b
SHA1: 149c399da656052d514c3afc073ce77ee39d3281
SHA256: 61c456937882b1773120d6040af400d82c047e55646f7b6e7d8d3450f2988bfd
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-misc-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-jmx@6.1.0 pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-util-misc High Vendor jar package name bedework Highest Vendor jar package name misc Highest Vendor jar package name util Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-misc Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-misc Highest Vendor pom artifactid bw-util-misc Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: misc utils High Vendor pom url Bedework/bw-util/bw-util-misc Highest Product file name bw-util-misc High Product jar package name bedework Highest Product jar package name misc Highest Product jar package name util Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: misc utils High Product Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-misc Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: misc utils Medium Product pom artifactid bw-util-misc Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: misc utils High Product pom url Bedework/bw-util/bw-util-misc High Version Manifest Implementation-Version 6.1.1-SNAPSHOT High Version pom version 6.1.1-SNAPSHOT Highest
bw-util-properties-6.1.1-SNAPSHOT.jarDescription:
This project provides a number of utility classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-properties/6.1.1-SNAPSHOT/bw-util-properties-6.1.1-SNAPSHOT.jar
MD5: 0acb6f62930b18463a03b495ebfdbba7
SHA1: 75a0504b6bd1279d396c678c581d5d9de7adfbb8
SHA256: 6c2edd36dcd8b50aedef25f90ca669ec9a8988f1a1439b2cc127282ffbfd1a96
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-properties-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-config@6.1.0 pkg:maven/org.bedework/bw-util-config@6.1.0 pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name bw-util-properties High Vendor jar package name bedework Highest Vendor jar package name properties Highest Vendor jar package name util Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-properties Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-properties Highest Vendor pom artifactid bw-util-properties Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: property utils High Vendor pom url Bedework/bw-util/bw-util-properties Highest Product file name bw-util-properties High Product jar package name bedework Highest Product jar package name properties Highest Product jar package name util Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: property utils High Product Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-properties Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: property utils Medium Product pom artifactid bw-util-properties Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: property utils High Product pom url Bedework/bw-util/bw-util-properties High Version Manifest Implementation-Version 6.1.1-SNAPSHOT High Version pom version 6.1.1-SNAPSHOT Highest
bw-util-xml-6.1.1-SNAPSHOT.jarDescription:
This project provides a number of utility classes and methods License:
Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/.m2/repository/org/bedework/bw-util-xml/6.1.1-SNAPSHOT/bw-util-xml-6.1.1-SNAPSHOT.jar
MD5: a76e8bf313047b33086e2b425696fb50
SHA1: df59c3262834676cc0c2e764e0f7f9dfe515f35d
SHA256: 12b8a71944d135c3676624a7b43741f20a044fb1dbb8c4ed40c138c6d16951ce
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile bw-util-xml-6.1.1-SNAPSHOT.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-config@6.1.0 pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-config@6.1.0 Evidence Type Source Name Value Confidence Vendor file name bw-util-xml High Vendor jar package name bedework Highest Vendor jar package name util Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-xml Low Vendor Manifest Implementation-Vendor Bedework High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor Bedework Low Vendor pom artifactid bw-util-xml Highest Vendor pom artifactid bw-util-xml Low Vendor pom developer name Arlen Johnson Medium Vendor pom developer name Mike Douglass Medium Vendor pom developer org Bedework Commercial Services Medium Vendor pom developer org Spherical Cow Group Medium Vendor pom developer org URL http://sphericalcowgroup.com/ Medium Vendor pom developer org URL https://bedework.com/ Medium Vendor pom groupid org.bedework Highest Vendor pom name Bedework: util to handle xml High Vendor pom url Bedework/bw-util/bw-util-xml Highest Product file name bw-util-xml High Product jar package name bedework Highest Product jar package name util Highest Product jar package name xml Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Bedework: util to handle xml High Product Manifest implementation-url https://github.com/Bedework/bw-util/bw-util-xml Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Bedework: util to handle xml Medium Product pom artifactid bw-util-xml Highest Product pom developer name Arlen Johnson Low Product pom developer name Mike Douglass Low Product pom developer org Bedework Commercial Services Low Product pom developer org Spherical Cow Group Low Product pom developer org URL http://sphericalcowgroup.com/ Low Product pom developer org URL https://bedework.com/ Low Product pom groupid org.bedework Highest Product pom name Bedework: util to handle xml High Product pom url Bedework/bw-util/bw-util-xml High Version Manifest Implementation-Version 6.1.1-SNAPSHOT High Version pom version 6.1.1-SNAPSHOT Highest
commons-beanutils-1.11.0.jarDescription:
Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/commons-beanutils/commons-beanutils/1.11.0/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256: 9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Project/Scope: Bedework: network util - jsp support:compile
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-servlet-jsp@6.2.2-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-beanutils High Vendor jar package name apache Highest Vendor jar package name beanutils Highest Vendor jar package name commons Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-beanutils Highest Vendor pom artifactid commons-beanutils Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email epugh@apache.org Low Vendor pom developer email geirm@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email jconlon@apache.org Low Vendor pom developer email jstrachan@apache.org Low Vendor pom developer email morgand@apache.org Low Vendor pom developer email mvdb@apache.org Low Vendor pom developer email niallp@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer email scolebourne@apache.org Low Vendor pom developer email skitching@apache.org Low Vendor pom developer email stain@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer email yoavs@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dion Medium Vendor pom developer id epugh Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id jconlon Medium Vendor pom developer id jstrachan Medium Vendor pom developer id morgand Medium Vendor pom developer id mvdb Medium Vendor pom developer id niallp Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer id skitching Medium Vendor pom developer id stain Medium Vendor pom developer id tobrien Medium Vendor pom developer id yoavs Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Eric Pugh Medium Vendor pom developer name Dion Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Jr. Medium Vendor pom developer name James Carman Medium Vendor pom developer name James Strachan Medium Vendor pom developer name John E. Conlon Medium Vendor pom developer name Martin van den Bemt Medium Vendor pom developer name Morgan James Delagrange Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Simon Kitching Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Stian Soiland-Reyes Medium Vendor pom developer name Tim O'Brien Medium Vendor pom developer name Yoav Shapira Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-beanutils Highest Vendor pom name Apache Commons BeanUtils High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-beanutils Highest Product file name commons-beanutils High Product jar package name apache Highest Product jar package name beanutils Highest Product jar package name commons Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils Low Product Manifest Bundle-Name Apache Commons BeanUtils Medium Product Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Product Manifest Implementation-Title Apache Commons BeanUtils High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons BeanUtils Medium Product pom artifactid commons-beanutils Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email craigmcc@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email epugh@apache.org Low Product pom developer email geirm@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email jconlon@apache.org Low Product pom developer email jstrachan@apache.org Low Product pom developer email morgand@apache.org Low Product pom developer email mvdb@apache.org Low Product pom developer email niallp@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer email scolebourne@apache.org Low Product pom developer email skitching@apache.org Low Product pom developer email stain@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer email yoavs@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id craigmcc Low Product pom developer id dion Low Product pom developer id epugh Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id jconlon Low Product pom developer id jstrachan Low Product pom developer id morgand Low Product pom developer id mvdb Low Product pom developer id niallp Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer id skitching Low Product pom developer id stain Low Product pom developer id tobrien Low Product pom developer id yoavs Low Product pom developer name Benedikt Ritter Low Product pom developer name Craig McClanahan Low Product pom developer name David Eric Pugh Low Product pom developer name Dion Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Jr. Low Product pom developer name James Carman Low Product pom developer name James Strachan Low Product pom developer name John E. Conlon Low Product pom developer name Martin van den Bemt Low Product pom developer name Morgan James Delagrange Low Product pom developer name Niall Pemberton Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Simon Kitching Low Product pom developer name Stephen Colebourne Low Product pom developer name Stian Soiland-Reyes Low Product pom developer name Tim O'Brien Low Product pom developer name Yoav Shapira Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-beanutils Highest Product pom name Apache Commons BeanUtils High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-beanutils Medium Version file version 1.11.0 High Version Manifest Bundle-Version 1.11.0 High Version Manifest Implementation-Version 1.11.0 High Version pom parent-version 1.11.0 Low Version pom version 1.11.0 Highest
commons-codec-1.17.1.jarDescription:
The Apache Commons Codec component contains encoders and decoders for
various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/commons-codec/commons-codec/1.17.1/commons-codec-1.17.1.jar
MD5: 7b3438ab4c6d91e0066d410947e43f3e
SHA1: 973638b7149d333563584137ebf13a691bb60579
SHA256: f9f6cb103f2ddc3c99a9d80ada2ae7bf0685111fd6bffccb72033d1da4e6ff23
Referenced In Projects/Scopes: Bedework: network util - http:compile Bedework: network util - webbdav handling:compile commons-codec-1.17.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name digest Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email mattsicker@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id mattsicker Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Matt Sicker Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name digest Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email mattsicker@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id mattsicker Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Matt Sicker Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.17.1 High Version Manifest Bundle-Version 1.17.1 High Version Manifest Implementation-Version 1.17.1 High Version pom parent-version 1.17.1 Low Version pom version 1.17.1 Highest
commons-lang3-3.18.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.18.0/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256: 4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-jmx@6.1.0 pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Highest Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.18.0 High Version Manifest Bundle-Version 3.18.0 High Version Manifest Implementation-Version 3.18.0 High Version pom parent-version 3.18.0 Low Version pom version 3.18.0 Highest
commons-logging-1.2.jarDescription:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256: daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Projects/Scopes: Bedework: network util - http:compile Bedework: network util - jsp support:compile Bedework: network util - webbdav handling:compile commons-logging-1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/commons-beanutils/commons-beanutils@1.11.0 pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 Evidence Type Source Name Value Confidence Vendor file name commons-logging High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-logging Highest Vendor pom artifactid commons-logging Low Vendor pom developer email baliuka@apache.org Low Vendor pom developer email costin@apache.org Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dennisl@apache.org Low Vendor pom developer email donaldp@apache.org Low Vendor pom developer email morgand@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rsitze@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer email skitching@apache.org Low Vendor pom developer email tn@apache.org Low Vendor pom developer id baliuka Medium Vendor pom developer id bstansberry Medium Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dennisl Medium Vendor pom developer id donaldp Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id skitching Medium Vendor pom developer id tn Medium Vendor pom developer name Brian Stansberry Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dennis Lundberg Medium Vendor pom developer name Juozas Baliuka Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Peter Donald Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Simon Kitching Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer org Apache Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom groupid commons-logging Highest Vendor pom name Apache Commons Logging High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Product file name commons-logging High Product jar package name apache Highest Product jar package name commons Highest Product jar package name logging Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Product Manifest Bundle-Name Apache Commons Logging Medium Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Product Manifest Implementation-Title Apache Commons Logging High Product Manifest specification-title Apache Commons Logging Medium Product pom artifactid commons-logging Highest Product pom developer email baliuka@apache.org Low Product pom developer email costin@apache.org Low Product pom developer email craigmcc@apache.org Low Product pom developer email dennisl@apache.org Low Product pom developer email donaldp@apache.org Low Product pom developer email morgand@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rsitze@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer email skitching@apache.org Low Product pom developer email tn@apache.org Low Product pom developer id baliuka Low Product pom developer id bstansberry Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id dennisl Low Product pom developer id donaldp Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id skitching Low Product pom developer id tn Low Product pom developer name Brian Stansberry Low Product pom developer name Costin Manolache Low Product pom developer name Craig McClanahan Low Product pom developer name Dennis Lundberg Low Product pom developer name Juozas Baliuka Low Product pom developer name Morgan Delagrange Low Product pom developer name Peter Donald Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Simon Kitching Low Product pom developer name Thomas Neidhart Low Product pom developer org Apache Low Product pom developer org The Apache Software Foundation Low Product pom groupid commons-logging Highest Product pom name Apache Commons Logging High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-logging/ Medium Version file version 1.2 High Version Manifest Implementation-Version 1.2 High Version pom parent-version 1.2 Low Version pom version 1.2 Highest
commons-text-1.14.0.jarDescription:
Apache Commons Text is a set of utility functions and reusable components for processing
and manipulating text in a Java environment.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256: 121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile commons-text-1.14.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-jmx@6.1.0 pkg:maven/org.bedework/bw-util-xml@6.1.1-SNAPSHOT pkg:maven/org.bedework/bw-util-misc@6.1.1-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name commons-text High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name text Highest Vendor Manifest automatic-module-name org.apache.commons.text Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Vendor Manifest bundle-symbolicname org.apache.commons.text Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-text Highest Vendor pom artifactid commons-text Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email kinow@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id ggregory Medium Vendor pom developer id kinow Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Bruno P. Kinoshita Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Text High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-text Highest Product file name commons-text High Product jar package name apache Highest Product jar package name commons Highest Product jar package name text Highest Product Manifest automatic-module-name org.apache.commons.text Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Product Manifest Bundle-Name Apache Commons Text Medium Product Manifest bundle-symbolicname org.apache.commons.text Medium Product Manifest Implementation-Title Apache Commons Text High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Text Medium Product pom artifactid commons-text Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email kinow@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id ggregory Low Product pom developer id kinow Low Product pom developer name Benedikt Ritter Low Product pom developer name Bruno P. Kinoshita Low Product pom developer name Duncan Jones Low Product pom developer name Gary Gregory Low Product pom developer name Rob Tompkins Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Text High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-text Medium Version file version 1.14.0 High Version Manifest Bundle-Version 1.14.0 High Version Manifest Implementation-Version 1.14.0 High Version pom parent-version 1.14.0 Low Version pom version 1.14.0 Highest
httpclient-4.5.14.jarDescription:
Apache HttpComponents Client
File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jarMD5: 2cb357c4b763f47e58af6cad47df6ba3SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98SHA256: c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6Referenced In Projects/Scopes:
Bedework: network util - http:compile Bedework: network util - webbdav handling:compile httpclient-4.5.14.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name httpclient High Vendor jar package name apache Highest Vendor jar package name client Highest Vendor jar package name httpclient Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpclient Highest Vendor pom artifactid httpclient Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client-ga Highest Product file name httpclient High Product jar package name apache Highest Product jar package name client Highest Product jar package name http Highest Product jar package name httpclient Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Product Manifest Implementation-Title Apache HttpClient High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Product Manifest specification-title Apache HttpClient Medium Product pom artifactid httpclient Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client-ga Medium Version file version 4.5.14 High Version Manifest Implementation-Version 4.5.14 High Version pom version 4.5.14 Highest
httpcore-4.4.16.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /home/runner/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jarMD5: 28d2cd9bf8789fd2ec774fb88436ebd1SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850SHA256: 6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464fReferenced In Projects/Scopes:
Bedework: network util - http:compile Bedework: network util - webbdav handling:compile httpcore-4.4.16.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name httpcore High Vendor jar package name apache Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom artifactid httpcore Highest Vendor pom artifactid httpcore Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpCore High Vendor pom parent-artifactid httpcomponents-core Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product file name httpcore High Product jar package name apache Highest Product jar package name http Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product pom artifactid httpcore Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpCore High Product pom parent-artifactid httpcomponents-core Medium Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Version file version 4.4.16 High Version Manifest Implementation-Version 4.4.16 High Version pom version 4.4.16 Highest
jackson-core-2.18.2.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.2/jackson-core-2.18.2.jar
MD5: bf935e6eca3a57defa13918661905cb0
SHA1: fb64ccac5c27dca8819418eb4e443a9f496d9ee7
SHA256: d8054ae7c0d1c2d2f55d28e46026ebe5892881f3fab5f439233184381c3b4a1f
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile jackson-core-2.18.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2 pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2 pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name com Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name com Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name json Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.18.2 High Version Manifest Bundle-Version 2.18.2 High Version Manifest Implementation-Version 2.18.2 High Version pom version 2.18.2 Highest
Related Dependencies jackson-annotations-2.18.2.jarFile Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.18.2/jackson-annotations-2.18.2.jar MD5: 79d38d3c51068a2bbc40268d02f80763 SHA1: 985d77751ebc7fce5db115a986bc9aa82f973f4a SHA256: 581bd61000ef7648943f781ca05689e56d03f6052748365a8e2b3a9b5d3fa32f pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.18.2 jackson-databind-2.18.2.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.18.2/jackson-databind-2.18.2.jar
MD5: 1b56887bcd3eaea1ff710eb673e610b0
SHA1: deef8697b92141fb6caf7aa86966cff4eec9b04f
SHA256: 4b364e6850dc89172fcf1d4dd26b8ff5488eda44ff4657e22dd265203dd5ab3c
Referenced In Projects/Scopes: Bedework: network util - servlet filters:compile Bedework: network util - http:compile Bedework: network util - servlet support:compile Bedework: network util - webbdav handling:compile jackson-databind-2.18.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-servlet@6.2.2-SNAPSHOT pkg:maven/org.bedework/bw-util-http@6.2.2-SNAPSHOT Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Highest Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.18.2 High Version Manifest Bundle-Version 2.18.2 High Version Manifest Implementation-Version 2.18.2 High Version pom version 2.18.2 Highest
CVE-2026-54512 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4. CWE-502 Deserialization of Untrusted Data, CWE-184 Incomplete List of Disallowed Inputs
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2026-54513 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4. CWE-184 Incomplete List of Disallowed Inputs
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2026-54518 (OSSINDEX) suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.
Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://guide.sonatype.com/vulnerability/CVE-2026-54518 for details CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.900000095367432) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:* CVE-2026-59888 (OSSINDEX) suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4. CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv2:
Base Score: MEDIUM (6.300000190734863) Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:* CVE-2026-59889 (OSSINDEX) suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.300000190734863) Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.2:*:*:*:*:*:*:* CVE-2026-54514 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2026-54515 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4. CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.bedework:bw-util-http:6.2.2-SNAPSHOTDescription:
Network (http, DAV,servlet etc) related utilities License:
Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-http/pom.xml
Referenced In Project/Scope: Bedework: network util - webbdav handling
org.bedework:bw-util-http:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-dav@6.2.2-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid bw-util-http Low Vendor project groupid org.bedework Highest Product file name pom High Product project artifactid bw-util-http Highest Product project groupid org.bedework Low
org.bedework:bw-util-servlet:6.2.2-SNAPSHOTDescription:
Network (http, DAV,servlet etc) related utilities License:
Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/runner/work/bw-util-network/bw-util-network/bw-util-servlet/pom.xml
Referenced In Project/Scope: Bedework: network util - servlet filters
org.bedework:bw-util-servlet:6.2.2-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.bedework/bw-util-servlet-filters@6.2.2-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid bw-util-servlet Low Vendor project groupid org.bedework Highest Product file name pom High Product project artifactid bw-util-servlet Highest Product project groupid org.bedework Low