Update dependency com.squareup.okhttp:okhttp to v2.7.4 #1
Dev - Mend for GitHub.com / Mend Security Check
failed
Jan 9, 2025 in 4m 5s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2017-9801Path to dependency file: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Path to vulnerable library: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Dependency Hierarchy: -> ❌ commons-email-1.4.jar (Vulnerable Library) |
High | 7.5 | commons-email-1.4.jar | Upgrade to version: 1.5 | #90 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2016-2402 | okhttp-2.7.1.jar |
CVE-2019-12421 | nifi-rel/nifi-1.3.0 |
Base branch total remaining vulnerabilities: 261
Base branch commit: d672f5c3ea38dd0e23359cf12d310c2c27abf963
Total libraries scanned: 410
Scan token: 5c36605ae019498c842e8c714085db4f
Loading