Update dependency org.springframework:spring-core to v5.2.22.RELEASE #118
Security Report
You have successfully remediated 10 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2017-9801Path to dependency file: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Path to vulnerable library: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Dependency Hierarchy: -> ❌ commons-email-1.4.jar (Vulnerable Library) |
High | 7.5 | commons-email-1.4.jar | Upgrade to version: 1.5 | #90 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-framework-core-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-site-to-site-1.4.0-SNAPSHOT.jar -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #73 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-administration-1.4.0-SNAPSHOT.jar (Root Library) -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #80 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.22.RELEASE.jar (Root Library) -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | None | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-site-to-site-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #111 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-jetty-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-web-security-1.4.0-SNAPSHOT.jar -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #113 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-web-security-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #116 | |
CVE-2023-20863Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-web-optimistic-locking-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #110 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-framework-core-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-site-to-site-1.4.0-SNAPSHOT.jar -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #73 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-administration-1.4.0-SNAPSHOT.jar (Root Library) -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #80 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.22.RELEASE.jar (Root Library) -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | None | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-site-to-site-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #111 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-jetty-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-web-security-1.4.0-SNAPSHOT.jar -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #113 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-web-security-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #116 | |
CVE-2023-20861Path to dependency file: /nifi-nar-bundles/nifi-framework-bundle/nifi-framework/nifi-web/nifi-jetty/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.22.RELEASE/spring-expression-5.2.22.RELEASE.jar Dependency Hierarchy: -> nifi-web-optimistic-locking-1.4.0-SNAPSHOT.jar (Root Library) -> nifi-administration-1.4.0-SNAPSHOT.jar -> spring-context-5.2.22.RELEASE.jar -> ❌ spring-expression-5.2.22.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-5.2.22.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #110 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-22968 | spring-context-5.2.18.RELEASE.jar |
CVE-2022-22950 | spring-expression-5.2.18.RELEASE.jar |
CVE-2021-22060 | spring-core-5.2.18.RELEASE.jar |
CVE-2023-20861 | spring-expression-5.2.18.RELEASE.jar |
CVE-2019-12421 | nifi-rel/nifi-1.3.0 |
CVE-2023-20863 | spring-expression-5.2.18.RELEASE.jar |
CVE-2022-22970 | spring-core-5.2.18.RELEASE.jar |
CVE-2022-22970 | spring-beans-5.2.18.RELEASE.jar |
CVE-2021-22060 | spring-web-5.2.18.RELEASE.jar |
CVE-2022-22965 | spring-beans-5.2.18.RELEASE.jar |
Base branch total remaining vulnerabilities: 261
Base branch commit: d672f5c3ea38dd0e23359cf12d310c2c27abf963
Total libraries scanned: 410
Scan token: 27fdc4a2bb384931aa76a9887a7b8cbe