Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Bedework: general utility classes

org.bedework:bw-util:6.0.2-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
bw-base-2.0.0.jarpkg:maven/org.bedework/bw-base@2.0.0 042
bw-util-logging-6.0.0.jarpkg:maven/org.bedework/bw-util-logging@6.0.0 044
commons-io-2.20.0.jarcpe:2.3:a:apache:commons_io:2.20.0:*:*:*:*:*:*:*pkg:maven/commons-io/commons-io@2.20.0 0Highest125
commons-lang3-3.18.0.jarcpe:2.3:a:apache:commons_lang:3.18.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-lang3@3.18.0 0Highest145
commons-text-1.14.0.jarcpe:2.3:a:apache:commons_text:1.14.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-text@1.14.0 0Highest73
dom4j-2.1.4.jarcpe:2.3:a:dom4j_project:dom4j:2.1.4:*:*:*:*:*:*:*pkg:maven/org.dom4j/dom4j@2.1.4 0Highest21
jackson-core-2.18.2.jarcpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.2 0Low47
jackson-databind-2.18.2.jarcpe:2.3:a:fasterxml:jackson-databind:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2 0Highest41
jakarta.jms-api-3.1.0.jarpkg:maven/jakarta.jms/jakarta.jms-api@3.1.0 035
org.bedework:bw-util-args:6.0.2-SNAPSHOTpkg:maven/org.bedework/bw-util-args@6.0.2-SNAPSHOT 06
org.bedework:bw-util-misc:6.0.2-SNAPSHOTpkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT 06

Dependencies (vulnerable)

bw-base-2.0.0.jar

Description:

This project provides base classes, types and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-base/2.0.0/bw-base-2.0.0.jar
MD5: 0480624145ad4fc5daeba898b7132099
SHA1: b24b7279e0475bb3c8c84e37af400ad87877c955
SHA256:10d27642e3bf1f2f4f85320293b5041b7e34cba02cc2656f29e79f75cee97cc5
Referenced In Projects/Scopes:
  • Bedework: util to handle xml:compile
  • Bedework: misc utils:compile
  • Bedework: util to handle ldap directories:compile
  • Bedework: util to handle jms:compile
  • Bedework: xml tools:compile

bw-base-2.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-xml@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-directory@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jms@6.0.2-SNAPSHOT

Identifiers

bw-util-logging-6.0.0.jar

Description:

This project provides logging utility classes and methods

License:

Apache License Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/org/bedework/bw-util-logging/6.0.0/bw-util-logging-6.0.0.jar
MD5: 2c63b9031e2d0852a00e57753320b409
SHA1: a12c15e6670f1298c8c4779d08b24595e921aceb
SHA256:e26bbaf5a5dcad998990fdc647f448b2e2dcac6eb628be6945fe24d53759b745
Referenced In Projects/Scopes:
  • Bedework: util to handle xml:compile
  • Bedework: misc utils:compile
  • Bedework: util to handle ldap directories:compile
  • Bedework: util to handle jms:compile
  • Bedework: xml tools:compile
  • Bedework: util to handle caching:compile

bw-util-logging-6.0.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-caching@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-directory@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jms@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xmltools@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.0.2-SNAPSHOT

Identifiers

commons-io-2.20.0.jar

Description:

The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-io/commons-io/2.20.0/commons-io-2.20.0.jar
MD5: 94e7e6b9b5fe82388687b584d3571081
SHA1: 36f3474daec2849c149e877614e7f979b2082cd2
SHA256:df90bba0fe3cb586b7f164e78fe8f8f4da3f2dd5c27fa645f888100ccc25dd72
Referenced In Project/Scope: Bedework: xml tools:compile
commons-io-2.20.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-xmltools@6.0.2-SNAPSHOT

Identifiers

commons-lang3-3.18.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17 and 21 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.18.0/commons-lang3-3.18.0.jar
MD5: 48b9886957920a4cdb602780ca345087
SHA1: fb14946f0e39748a6571de0635acbe44e7885491
SHA256:4eeeae8d20c078abb64b015ec158add383ac581571cddc45c68f0c9ae0230720
Referenced In Projects/Scopes:
  • Bedework: util to handle xml:compile
  • Bedework: misc utils:compile
  • Bedework: util to handle ldap directories:compile
  • Bedework: util to handle jms:compile
  • Bedework: xml tools:compile

commons-lang3-3.18.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.apache.commons/commons-text@1.14.0
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT

Identifiers

commons-text-1.14.0.jar

Description:

Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256:121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Referenced In Projects/Scopes:
  • Bedework: util to handle xml:compile
  • Bedework: misc utils:compile
  • Bedework: util to handle ldap directories:compile
  • Bedework: util to handle jms:compile
  • Bedework: xml tools:compile

commons-text-1.14.0.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-misc@6.0.2-SNAPSHOT

Identifiers

dom4j-2.1.4.jar

Description:

flexible XML framework for Java

License:

Plexus: https://github.com/dom4j/dom4j/blob/master/LICENSE
File Path: /home/runner/.m2/repository/org/dom4j/dom4j/2.1.4/dom4j-2.1.4.jar
MD5: 8246840e53db2781ca941e4d3f9ad715
SHA1: 35c16721b88cf17b8279fcb134c0abb161cc0e9b
SHA256:235a9167a8a199be04b5326d92927ca0adeb90d11f69fe2e821b34ce8433b591
Referenced In Project/Scope: Bedework: xml tools:compile
dom4j-2.1.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-xmltools@6.0.2-SNAPSHOT

Identifiers

jackson-core-2.18.2.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.2/jackson-core-2.18.2.jar
MD5: bf935e6eca3a57defa13918661905cb0
SHA1: fb64ccac5c27dca8819418eb4e443a9f496d9ee7
SHA256:d8054ae7c0d1c2d2f55d28e46026ebe5892881f3fab5f439233184381c3b4a1f
Referenced In Project/Scope: Bedework: util to handle json:compile
jackson-core-2.18.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.2

Identifiers

jackson-databind-2.18.2.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.18.2/jackson-databind-2.18.2.jar
MD5: 1b56887bcd3eaea1ff710eb673e610b0
SHA1: deef8697b92141fb6caf7aa86966cff4eec9b04f
SHA256:4b364e6850dc89172fcf1d4dd26b8ff5488eda44ff4657e22dd265203dd5ab3c
Referenced In Project/Scope: Bedework: util to handle json:compile
jackson-databind-2.18.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-json@6.0.2-SNAPSHOT

Identifiers

jakarta.jms-api-3.1.0.jar

Description:

        Jakarta Messaging describes a means for Java applications to create, send, 
        and receive messages via loosely coupled, reliable asynchronous communication services.
    

License:

Eclipse Public License 2.0: https://projects.eclipse.org/license/epl-2.0
GNU General Public License, version 2 with the GNU Classpath Exception: https://projects.eclipse.org/license/secondary-gpl-2.0-cp
File Path: /home/runner/.m2/repository/jakarta/jms/jakarta.jms-api/3.1.0/jakarta.jms-api-3.1.0.jar
MD5: 68b9809056047472375bf10441b2a26f
SHA1: e194cf91a3f908e4846542849ac11a8e0b3c68ad
SHA256:6605e08075ab389c359451c7854808cf4b1575e1ea6317e534e9d4df088096df
Referenced In Project/Scope: Bedework: util to handle jms:compile
jakarta.jms-api-3.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-jms@6.0.2-SNAPSHOT

Identifiers

org.bedework:bw-util-args:6.0.2-SNAPSHOT

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util/bw-util/bw-util-args/pom.xml

Referenced In Project/Scope: Bedework: xml tools
org.bedework:bw-util-args:6.0.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bedework/bw-util-xmltools@6.0.2-SNAPSHOT

Identifiers

org.bedework:bw-util-misc:6.0.2-SNAPSHOT

Description:

This project provides a number of utility classes and methods

License:

Apache License Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/work/bw-util/bw-util/bw-util-misc/pom.xml

Referenced In Projects/Scopes:
  • Bedework: util to handle ldap directories
  • Bedework: util to handle jms
  • Bedework: xml tools
  • Bedework: util to handle xml

org.bedework:bw-util-misc:6.0.2-SNAPSHOT is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/org.bedework/bw-util-xmltools@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-directory@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-xml@6.0.2-SNAPSHOT
  • pkg:maven/org.bedework/bw-util-jms@6.0.2-SNAPSHOT

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.