Update dependency org.elasticsearch:elasticsearch to v6 #35
Dev - Mend for GitHub.com / Mend Security Check
failed
Jan 9, 2025 in 28m 55s
Security Report
You have successfully remediated 7 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2017-9801Path to dependency file: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Path to vulnerable library: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Dependency Hierarchy: -> ❌ commons-email-1.4.jar (Vulnerable Library) |
High | 7.5 | commons-email-1.4.jar | Upgrade to version: 1.5 | #90 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2020-7020 | elasticsearch-2.1.0.jar |
CVE-2020-7021 | elasticsearch-2.1.0.jar |
CVE-2019-7614 | elasticsearch-2.1.0.jar |
CVE-2018-3824 | elasticsearch-2.1.0.jar |
CVE-2019-7611 | elasticsearch-2.1.0.jar |
CVE-2019-12421 | nifi-rel/nifi-1.3.0 |
CVE-2018-3823 | elasticsearch-2.1.0.jar |
Base branch total remaining vulnerabilities: 261
Base branch commit: d672f5c3ea38dd0e23359cf12d310c2c27abf963
Total libraries scanned: 410
Scan token: 28a55236eb974c988fc5c10e15e04340
Loading