Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: CORE

io.github.together.modules:core:3.1.0

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
angus-activation-2.0.1.jarpkg:maven/org.eclipse.angus/angus-activation@2.0.1 035
annotations-3.0.1u2.jarpkg:maven/com.google.code.findbugs/annotations@3.0.1u2 037
antlr4-runtime-4.13.0.jarpkg:maven/org.antlr/antlr4-runtime@4.13.0 030
apiguardian-api-1.1.2.jarpkg:maven/org.apiguardian/apiguardian-api@1.1.2 040
aspectjweaver-1.9.20.1.jarpkg:maven/org.aspectj/aspectjweaver@1.9.20.1 049
bundle-hibernate-6.4.1.pompkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1 018
bundle-spring-6.1.2.pompkg:maven/io.github.together.libraries/bundle-spring@6.1.2 018
byte-buddy-1.14.10.jarpkg:maven/net.bytebuddy/byte-buddy@1.14.10 029
caffeine-2.9.3.jarpkg:maven/com.github.ben-manes.caffeine/caffeine@2.9.3 033
checker-qual-3.41.0.jarpkg:maven/org.checkerframework/checker-qual@3.41.0 046
classmate-1.5.1.jarpkg:maven/com.fasterxml/classmate@1.5.1 054
commons-dbcp2-2.11.0.jarpkg:maven/org.apache.commons/commons-dbcp2@2.11.0 0110
commons-imaging-1.0-alpha3.jarcpe:2.3:a:apache:commons_imaging:1.0:pha3:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-imaging@1.0-alpha3 0Highest67
commons-lang3-3.11.jarpkg:maven/org.apache.commons/commons-lang3@3.11 0138
commons-logging-1.2.jarpkg:maven/commons-logging/commons-logging@1.2 0117
commons-pool2-2.12.0.jarpkg:maven/org.apache.commons/commons-pool2@2.12.0 094
core-3.5.2.jarpkg:maven/com.google.zxing/core@3.5.2 029
derby-10.17.1.0.jarcpe:2.3:a:apache:derby:10.17.1.0:*:*:*:*:*:*:*pkg:maven/org.apache.derby/derby@10.17.1.0 0Highest28
derbyclient-10.17.1.0.jarcpe:2.3:a:apache:derby:10.17.1.0:*:*:*:*:*:*:*pkg:maven/org.apache.derby/derbyclient@10.17.1.0 0Highest24
derbyshared-10.17.1.0.jarcpe:2.3:a:apache:derby:10.17.1.0:*:*:*:*:*:*:*pkg:maven/org.apache.derby/derbyshared@10.17.1.0 0Highest27
dom4j-2.1.3.jarcpe:2.3:a:dom4j_project:dom4j:2.1.3:*:*:*:*:*:*:*pkg:maven/org.dom4j/dom4j@2.1.3 0Highest20
error_prone_annotations-2.10.0.jarpkg:maven/com.google.errorprone/error_prone_annotations@2.10.0 021
ff4j-core-2.0.0.jarcpe:2.3:a:ff4j:ff4j:2.0.0:*:*:*:*:*:*:*pkg:maven/org.ff4j/ff4j-core@2.0.0 0Highest24
flying-saucer-core-9.3.1.jarpkg:maven/org.xhtmlrenderer/flying-saucer-core@9.3.1 027
flying-saucer-pdf-openpdf-9.3.1.jarpkg:maven/org.xhtmlrenderer/flying-saucer-pdf-openpdf@9.3.1 019
h2-2.2.224.jarcpe:2.3:a:h2database:h2:2.2.224:*:*:*:*:*:*:*pkg:maven/com.h2database/h2@2.2.224MEDIUM1Highest44
h2-2.2.224.jar: data.zip: table.js 00
h2-2.2.224.jar: data.zip: tree.js 00
hibernate-commons-annotations-6.0.6.Final.jarpkg:maven/org.hibernate.common/hibernate-commons-annotations@6.0.6.Final 038
hibernate-core-6.4.1.Final.jarcpe:2.3:a:hibernate:hibernate_orm:6.4.1:*:*:*:*:*:*:*pkg:maven/org.hibernate.orm/hibernate-core@6.4.1.Final 0Highest43
hibernate-entitymanager-6.0.0.Alpha7.jarcpe:2.3:a:hibernate:hibernate_orm:6.0.0:pha7:*:*:*:*:*:*pkg:maven/org.hibernate.orm/hibernate-entitymanager@6.0.0.Alpha7 0Highest25
hibernate-validator-8.0.1.Final.jarcpe:2.3:a:redhat:hibernate_validator:8.0.1:*:*:*:*:*:*:*pkg:maven/org.hibernate.validator/hibernate-validator@8.0.1.Final 0Highest34
hsqldb-2.7.2.jarcpe:2.3:a:hsqldb:hypersql_database:2.7.2:*:*:*:*:*:*:*pkg:maven/org.hsqldb/hsqldb@2.7.2 0Low47
imgscalr-lib-4.2.jarpkg:maven/org.imgscalr/imgscalr-lib@4.2 030
istack-commons-runtime-4.1.2.jarpkg:maven/com.sun.istack/istack-commons-runtime@4.1.2 029
jackson-core-2.16.1.jarcpe:2.3:a:fasterxml:jackson-modules-java8:2.16.1:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.1 0Low47
jackson-databind-2.16.1.jarcpe:2.3:a:fasterxml:jackson-databind:2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.16.1:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.1 0Highest41
jai-imageio-core-1.4.0.jarpkg:maven/com.github.jai-imageio/jai-imageio-core@1.4.0 042
jakarta.activation-2.0.1.jarpkg:maven/com.sun.activation/jakarta.activation@2.0.1 036
jakarta.activation-api-2.1.2.jarpkg:maven/jakarta.activation/jakarta.activation-api@2.1.2 045
jakarta.el-5.0.0-M1.jarcpe:2.3:a:eclipse:glassfish:5.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:eclipse:jakarta_expression_language:5.0.0:m1:*:*:*:*:*:*
pkg:maven/org.glassfish/jakarta.el@5.0.0-M1CRITICAL1Highest44
jakarta.el-api-5.0.0.jarcpe:2.3:a:eclipse:jakarta_expression_language:5.0.0:*:*:*:*:*:*:*pkg:maven/jakarta.el/jakarta.el-api@5.0.0 0Low45
jakarta.inject-api-2.0.1.jarpkg:maven/jakarta.inject/jakarta.inject-api@2.0.1 056
jakarta.mail-2.0.1.jarpkg:maven/com.sun.mail/jakarta.mail@2.0.1 042
jakarta.persistence-api-3.1.0.jarpkg:maven/jakarta.persistence/jakarta.persistence-api@3.1.0 040
jakarta.transaction-api-2.0.1.jarcpe:2.3:a:oracle:projects:2.0.1:*:*:*:*:*:*:*pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.1 0Low50
jakarta.validation-api-3.0.2.jarpkg:maven/jakarta.validation/jakarta.validation-api@3.0.2 056
jakarta.xml.bind-api-4.0.1.jarpkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.1 031
jandex-3.1.2.jarpkg:maven/io.smallrye/jandex@3.1.2 027
javase-3.5.2.jarpkg:maven/com.google.zxing/javase@3.5.2 021
javax.persistence-api-2.2.jarpkg:maven/javax.persistence/javax.persistence-api@2.2 031
jaxb-core-4.0.4.jarcpe:2.3:a:eclipse:glassfish:4.0.4:*:*:*:*:*:*:*pkg:maven/org.glassfish.jaxb/jaxb-core@4.0.4 0Highest40
jboss-logging-3.5.0.Final.jarpkg:maven/org.jboss.logging/jboss-logging@3.5.0.Final 043
jboss-transaction-api_1.2_spec-1.1.1.Final.jarpkg:maven/org.jboss.spec.javax.transaction/jboss-transaction-api_1.2_spec@1.1.1.Final 039
jcip-annotations-1.0-1.jarpkg:maven/com.github.stephenc.jcip/jcip-annotations@1.0-1 025
jcip-annotations-1.0.jarpkg:maven/net.jcip/jcip-annotations@1.0 024
jcl-over-slf4j-2.0.7.jarpkg:maven/org.slf4j/jcl-over-slf4j@2.0.7 029
jcommander-1.82.jarpkg:maven/com.beust/jcommander@1.82 026
jna-5.13.0.jarcpe:2.3:a:oracle:java_se:5.13.0:*:*:*:*:*:*:*pkg:maven/net.java.dev.jna/jna@5.13.0 0Low48
jna-5.13.0.jar: jnidispatch.dll 02
jna-5.13.0.jar: jnidispatch.dll 02
jna-5.13.0.jar: jnidispatch.dll 02
jna-platform-5.13.0.jarpkg:maven/net.java.dev.jna/jna-platform@5.13.0 044
jsoup-1.17.1.jarcpe:2.3:a:jsoup:jsoup:1.17.1:*:*:*:*:*:*:*pkg:maven/org.jsoup/jsoup@1.17.1 0Highest42
jsr305-3.0.1.jarpkg:maven/com.google.code.findbugs/jsr305@3.0.1 017
logback-core-1.4.14.jarcpe:2.3:a:qos:logback:1.4.14:*:*:*:*:*:*:*pkg:maven/ch.qos.logback/logback-core@1.4.14 0Highest36
mariadb-java-client-3.3.2.jarpkg:maven/org.mariadb.jdbc/mariadb-java-client@3.3.2 044
micrometer-commons-1.12.1.jarpkg:maven/io.micrometer/micrometer-commons@1.12.1 065
micrometer-observation-1.12.1.jarpkg:maven/io.micrometer/micrometer-observation@1.12.1 065
mysql-connector-j-8.0.33.jarcpe:2.3:a:mysql:mysql:8.0.33:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_connector\/j:8.0.33:*:*:*:*:*:*:*
pkg:maven/com.mysql/mysql-connector-j@8.0.33HIGH1Highest52
nimbus-jose-jwt-9.37.3.jar (shaded: com.google.code.gson:gson:2.10.1)cpe:2.3:a:google:gson:2.10.1:*:*:*:*:*:*:*pkg:maven/com.google.code.gson/gson@2.10.1 0Highest9
nimbus-jose-jwt-9.37.3.jarcpe:2.3:a:connect2id:nimbus_jose\+jwt:9.37.3:*:*:*:*:*:*:*pkg:maven/com.nimbusds/nimbus-jose-jwt@9.37.3 0Highest52
ojdbc10-19.3.0.0.jarcpe:2.3:a:oracle:jdbc:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/ojdbc10@19.3.0.0 0Highest30
ons-19.3.0.0.jarcpe:2.3:a:oracle:oracle_database:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/ons@19.3.0.0 0Low26
openpdf-1.3.35.jarpkg:maven/com.github.librepdf/openpdf@1.3.35 022
oraclepki-19.3.0.0.jarcpe:2.3:a:oracle:oracle_database:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/oraclepki@19.3.0.0 0Low25
osdt_core-19.3.0.0.jarcpe:2.3:a:oracle:oracle_database:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/osdt_core@19.3.0.0 0Low30
postgresql-42.7.1.jarcpe:2.3:a:postgresql:postgresql_jdbc_driver:42.7.1:*:*:*:*:*:*:*pkg:maven/org.postgresql/postgresql@42.7.1 0Low68
protobuf-java-3.21.9.jarcpe:2.3:a:google:protobuf-java:3.21.9:*:*:*:*:*:*:*
cpe:2.3:a:protobuf:protobuf:3.21.9:*:*:*:*:*:*:*
pkg:maven/com.google.protobuf/protobuf-java@3.21.9 0Highest25
resilience4j-circuitbreaker-2.2.0.jarpkg:maven/io.github.resilience4j/resilience4j-circuitbreaker@2.2.0 054
resilience4j-core-2.2.0.jarpkg:maven/io.github.resilience4j/resilience4j-core@2.2.0 054
simplefan-19.3.0.0.jarcpe:2.3:a:oracle:oracle_database:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/simplefan@19.3.0.0 0Low24
slf4j-api-2.0.9.jarpkg:maven/org.slf4j/slf4j-api@2.0.9 029
spring-core-6.1.2.jarcpe:2.3:a:pivotal_software:spring_framework:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:6.1.2:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-core@6.1.2 0Highest41
spring-web-6.1.2.jarcpe:2.3:a:pivotal_software:spring_framework:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:web_project:web:6.1.2:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-web@6.1.2 0Highest35
sqlite-jdbc-3.44.1.0.jarcpe:2.3:a:sqlite:sqlite:3.44.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sqlite_jdbc_project:sqlite_jdbc:3.44.1.0:*:*:*:*:*:*:*
pkg:maven/org.xerial/sqlite-jdbc@3.44.1.0 0Highest38
sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll 02
sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll 02
sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll 02
sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll 02
txw2-4.0.4.jarcpe:2.3:a:eclipse:glassfish:4.0.4:*:*:*:*:*:*:*pkg:maven/org.glassfish.jaxb/txw2@4.0.4 0Highest34
ucp-19.3.0.0.jarcpe:2.3:a:oracle:oracle_database:19.3.0.0:*:*:*:*:*:*:*pkg:maven/com.oracle.ojdbc/ucp@19.3.0.0 0Low26
velocity-engine-core-2.3.jar (shaded: commons-io:commons-io:2.8.0)cpe:2.3:a:apache:commons_io:2.8.0:*:*:*:*:*:*:*pkg:maven/commons-io/commons-io@2.8.0 0Highest92
velocity-engine-core-2.3.jarcpe:2.3:a:apache:velocity_engine:2.3:*:*:*:*:*:*:*pkg:maven/org.apache.velocity/velocity-engine-core@2.3 0Highest33
waffle-jna-3.3.0.jarpkg:maven/com.github.waffle/waffle-jna@3.3.0 042
xercesImpl-2.12.2.jarcpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*
pkg:maven/xerces/xercesImpl@2.12.2MEDIUM1Low84
xml-apis-1.4.01.jarpkg:maven/xml-apis/xml-apis@1.4.01 087

Dependencies (vulnerable)

angus-activation-2.0.1.jar

Description:

 Implementation

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/org/eclipse/angus/angus-activation/2.0.1/angus-activation-2.0.1.jar
MD5: 9a66564224140488f83f645ac32d4169
SHA1: eaafaf4eb71b400e4136fc3a286f50e34a68ecb7
SHA256:b226761815868edf8964c1d71e6d2d54ab238c2788507061b4e0633933b4c131
Referenced In Project/Scope: CORE:runtime
angus-activation-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

annotations-3.0.1u2.jar

Description:

Annotation the FindBugs tool supports

License:

GNU Lesser Public License: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ed/Programs/mvn-repository/com/google/code/findbugs/annotations/3.0.1u2/annotations-3.0.1u2.jar
MD5: 4242c4e6b7719eeb3f91d3fe4c7af12c
SHA1: 89a670596c98e416fb2583c08ae34cc5c3ce2097
SHA256:acc0d2c06be70e9094d70cd05dffa077735c8f9d1a870eafda130b0592528200
Referenced In Project/Scope: CORE:provided
annotations-3.0.1u2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

antlr4-runtime-4.13.0.jar

Description:

The ANTLR 4 Runtime

License:

https://www.antlr.org/license.html
File Path: /home/ed/Programs/mvn-repository/org/antlr/antlr4-runtime/4.13.0/antlr4-runtime-4.13.0.jar
MD5: bff95723c494b332b14575d713a65df4
SHA1: 5a02e48521624faaf5ff4d99afc88b01686af655
SHA256:bd7f7b5d07bc0b047f10915b32ca4bb1de9e57d8049098882e4453c88c076a5d
Referenced In Project/Scope: CORE:runtime
antlr4-runtime-4.13.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

apiguardian-api-1.1.2.jar

Description:

@API Guardian

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apiguardian/apiguardian-api/1.1.2/apiguardian-api-1.1.2.jar
MD5: 8c7de3f82037fa4a2e8be2a2f13092af
SHA1: a231e0d844d2721b0fa1b238006d15c6ded6842a
SHA256:b509448ac506d607319f182537f0b35d71007582ec741832a1f111e5b5b70b38
Referenced In Project/Scope: CORE:compile
apiguardian-api-1.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

aspectjweaver-1.9.20.1.jar

Description:

The AspectJ weaver applies aspects to Java classes. It can be used as a Java agent in order to apply load-time
		weaving (LTW) during class-loading and also contains the AspectJ runtime classes.

License:

Eclipse Public License - v 2.0: https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/aspectj/aspectjweaver/1.9.20.1/aspectjweaver-1.9.20.1.jar
MD5: 25ff63c95878ac361028f45748b2b540
SHA1: 33b0e41476658229933eec7134678cf336e66dd4
SHA256:ca4d10891b851c62bff65c6cf9a7ef870f51584253399060d300041083afbb99
Referenced In Project/Scope: CORE:compile
aspectjweaver-1.9.20.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

bundle-hibernate-6.4.1.pom

Description:

Bill of Materials \n
        HBM 3.2 + | JPA 1.0 | JSR 220 \n
        HBM 3.5 + | JPA 2.0 | JSR 317 \n
        HBM 4.3 + | JPA 2.1 | JSR 338 \n
        HBM 5.3 + | JPA 2.2 | JSR 338 \n
        HBM 5.5 + | JPA 2.2 | Jakarta EE 8 \n
        HBM 6.0 + | JPA 3.0 | Jakarta EE 9 \n
        HBM 6.1 + | JPA 3.1 | Jakarta EE 10
    

License:

${license.name}: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ed/Programs/mvn-repository/io/github/together/libraries/bundle-hibernate/6.4.1/bundle-hibernate-6.4.1.pom
MD5: 05f620bc0b463cc4457e7e51e5642ea9
SHA1: 65119c79d47addb2ee83895a6e23ed657a1d0abf
SHA256:b7f990b0128a3fa06aa9c79f0abdd8d4a3f329144393feca67e8f17ce3b38d24
bundle-hibernate-6.4.1.pom is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

bundle-spring-6.1.2.pom

Description:

Bill of Materials

License:

${license.name}: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ed/Programs/mvn-repository/io/github/together/libraries/bundle-spring/6.1.2/bundle-spring-6.1.2.pom
MD5: bbc9866e92565133d4c5bfdfbc33ae42
SHA1: ea765b04c31b0ad7a1ccb4f3376db6aaeacba0c4
SHA256:dea463a429ef88332592c9065b14dbcb18152aee32127b3838abf0b91d81048f
bundle-spring-6.1.2.pom is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

byte-buddy-1.14.10.jar

Description:

        Byte Buddy is a Java library for creating Java classes at run time.
        This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
    

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/net/bytebuddy/byte-buddy/1.14.10/byte-buddy-1.14.10.jar
MD5: 4e5bd83559bf8533b51f92dcd911d16c
SHA1: 8117daf4a612122eb4f517f66adff778cb8b4737
SHA256:30e6e0446437a67db37e2b7f7d33f50787ddfd970359319dfd05469daa2dcbce
Referenced In Project/Scope: CORE:compile
byte-buddy-1.14.10.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.mockito/mockito-core@5.8.0

Identifiers

caffeine-2.9.3.jar

Description:

A high performance caching library

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/github/ben-manes/caffeine/caffeine/2.9.3/caffeine-2.9.3.jar
MD5: e0b9c5ccd60a1b5403df1dfe6de37d8e
SHA1: b162491f768824d21487551873f9b3b374a7fe19
SHA256:1e0a7bbef1dd791653143f3f05d0e489934bf5481e58a87c9e619cd46b68729b
Referenced In Project/Scope: CORE:compile
caffeine-2.9.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

checker-qual-3.41.0.jar

Description:

checker-qual contains annotations (type qualifiers) that a programmer
writes to specify Java code for type-checking by the Checker Framework.

License:

The MIT License: http://opensource.org/licenses/MIT
File Path: /home/ed/Programs/mvn-repository/org/checkerframework/checker-qual/3.41.0/checker-qual-3.41.0.jar
MD5: 3187e97ad396c881e9e9f98456e8d878
SHA1: 08be6df7f1e9bccb19f8f351b3651f0bac2f5e0c
SHA256:2f9f245bf68e4259d610894f2406dc1f6363dc639302bd566e8272e4f4541172
Referenced In Project/Scope: CORE:compile
checker-qual-3.41.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

classmate-1.5.1.jar

Description:

Library for introspecting types with full generic information
        including resolving of field and method types.
    

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar
MD5: e91fcd30ba329fd1b0b6dc5321fd067c
SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c
SHA256:aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b
Referenced In Project/Scope: CORE:compile
classmate-1.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

commons-dbcp2-2.11.0.jar

Description:

Apache Commons DBCP software implements Database Connection Pooling

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apache/commons/commons-dbcp2/2.11.0/commons-dbcp2-2.11.0.jar
MD5: f4b4862aa3f2fd796f4f0e822f41cf5c
SHA1: 5553126edbdc3d2dd24118f687d09d6d066fca1b
SHA256:58d144d6327b4a054ca0e71a4438456bd66c0ca8d0c1aa799f59dcfb0ec599cc
Referenced In Project/Scope: CORE:compile
commons-dbcp2-2.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

commons-imaging-1.0-alpha3.jar

Description:

Apache Commons Imaging (previously Sanselan) is a pure-Java image library.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apache/commons/commons-imaging/1.0-alpha3/commons-imaging-1.0-alpha3.jar
MD5: c08d610dd64f970d286444654733a38f
SHA1: 6c753938422d5810ab815a24337d062bf4e22614
SHA256:3c5efe8c6654eae6384f0c2e382fafec1f164be527117803d869f8df27b84853
Referenced In Project/Scope: CORE:compile
commons-imaging-1.0-alpha3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

commons-lang3-3.11.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apache/commons/commons-lang3/3.11/commons-lang3-3.11.jar
MD5: c592f49f703f9b3ab25556559b1ff379
SHA1: 68e9a6adf7cf8eb7e9d31bbc554c7c75eeaac568
SHA256:4ee380259c068d1dbe9e84ab52186f2acd65de067ec09beff731fca1697fdb16
Referenced In Project/Scope: CORE:compile
commons-lang3-3.11.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.velocity/velocity-engine-core@2.3

Identifiers

commons-logging-1.2.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256:daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: CORE:compile
commons-logging-1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

commons-pool2-2.12.0.jar

Description:

The Apache Commons Object Pooling Library.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apache/commons/commons-pool2/2.12.0/commons-pool2-2.12.0.jar
MD5: 0516bf5ac1549e8ba78f6b7c49d09ed2
SHA1: 458563f69fbdaebf7daadfe10dc3a22e42a7de50
SHA256:6d3bd18df8410f3e31b031aca582cc109342358a62a2759ebd0c4cdf30d06f8b
Referenced In Project/Scope: CORE:compile
commons-pool2-2.12.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

core-3.5.2.jar

Description:

Core barcode encoding/decoding library

License:

"The Apache Software License, Version 2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: /home/ed/Programs/mvn-repository/com/google/zxing/core/3.5.2/core-3.5.2.jar
MD5: a4b9626b8022056fca2034ed94988103
SHA1: baab0f4a47b2052c9393af6af7c47a9dd8d89297
SHA256:fba90122b5d56bac8c947c60b5925211b0d8d40c539b3109be3774f08f74fedb
Referenced In Project/Scope: CORE:compile
core-3.5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

derby-10.17.1.0.jar

Description:

Contains the core Apache Derby database engine, which also includes the embedded JDBC driver.

File Path: /home/ed/Programs/mvn-repository/org/apache/derby/derby/10.17.1.0/derby-10.17.1.0.jar
MD5: 0665c8f3365fca01eb639e41f7685991
SHA1: e90e61e8ee731614a9bafd3d81155e09fff5e80c
SHA256:764e4c133f860a8876e835ef2306efecad27a742d27f05bc4bce669432c6b397
Referenced In Project/Scope: CORE:compile
derby-10.17.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

derbyclient-10.17.1.0.jar

Description:

The Derby client JDBC driver, used to connect to a Derby server over a network connection.

File Path: /home/ed/Programs/mvn-repository/org/apache/derby/derbyclient/10.17.1.0/derbyclient-10.17.1.0.jar
MD5: 49799b7b53c54c52a2f009cb22d2bcae
SHA1: de3c15ed06ad5e438720fff251d41de12ec0ee1f
SHA256:8f3e7a1f2eec23faf8c1c0fb21767b37c4d60d32223362a1f82a740b39b3726a
Referenced In Project/Scope: CORE:compile
derbyclient-10.17.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

derbyshared-10.17.1.0.jar

Description:

The code which is shared across all Derby configurations.

File Path: /home/ed/Programs/mvn-repository/org/apache/derby/derbyshared/10.17.1.0/derbyshared-10.17.1.0.jar
MD5: ce2d7164d5cda8ac3a1ede81023814d4
SHA1: e6eac60d1b80b3781dff97ccef88fa131043f2a5
SHA256:fb68bab30785375c1f8cb5e9583b349750f8904d6f7ee15ce8e1c30b6be30ef4
Referenced In Project/Scope: CORE:compile
derbyshared-10.17.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

dom4j-2.1.3.jar

Description:

flexible XML framework for Java

License:

BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE
File Path: /home/ed/Programs/mvn-repository/org/dom4j/dom4j/2.1.3/dom4j-2.1.3.jar
MD5: 41efcf234c5a05a8c590f9b51d53ca66
SHA1: a75914155a9f5808963170ec20653668a2ffd2fd
SHA256:549f3007c6290f6a901e57d1d331b4ed0e6bf7384f78bf10316ffceeca834de6
Referenced In Project/Scope: CORE:compile
dom4j-2.1.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

error_prone_annotations-2.10.0.jar

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/google/errorprone/error_prone_annotations/2.10.0/error_prone_annotations-2.10.0.jar
MD5: df93bd9f00b1d2b1e2ca6317fd8f6df3
SHA1: 9bc20b94d3ac42489cf6ce1e42509c86f6f861a1
SHA256:a249d4d25dfb86d41e6c82fc335df580189f0c9feeabdc53233fc1e5060724a1
Referenced In Project/Scope: CORE:compile
error_prone_annotations-2.10.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

ff4j-core-2.0.0.jar

File Path: /home/ed/Programs/mvn-repository/org/ff4j/ff4j-core/2.0.0/ff4j-core-2.0.0.jar
MD5: cec7c8236b55658c957c87397e3524bb
SHA1: a4f1a151756b5f7b3bb57c0e581628c0df139e29
SHA256:ffe4fba911b122e5b1ce8b6550c936dd3ea2cd2c9fc466954a0be646a7c957c0
Referenced In Project/Scope: CORE:compile
ff4j-core-2.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

flying-saucer-core-9.3.1.jar

Description:

Flying Saucer is a CSS 2.1 renderer written in Java.  This artifact contains the core rendering and layout code as well as Java2D output.

License:

GNU Lesser General Public License (LGPL), version 2.1 or later: https://www.gnu.org/licenses/lgpl-3.0.html
File Path: /home/ed/Programs/mvn-repository/org/xhtmlrenderer/flying-saucer-core/9.3.1/flying-saucer-core-9.3.1.jar
MD5: 956e46d6911e300568d5e68dc9a4c8af
SHA1: 2ab8779ebd30eb71c0c4a60ff83cc70a7c384c66
SHA256:a2d8b0bc97add7f582ae968b3d559068037d567a077c61f1beb710bcafa5e7b2
Referenced In Project/Scope: CORE:compile
flying-saucer-core-9.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.xhtmlrenderer/flying-saucer-pdf-openpdf@9.3.1

Identifiers

flying-saucer-pdf-openpdf-9.3.1.jar

Description:

Flying Saucer is a CSS 2.1 renderer written in Java.  This artifact supports PDF output. (OpenPDF)

License:

GNU Lesser General Public License (LGPL), version 2.1 or later: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ed/Programs/mvn-repository/org/xhtmlrenderer/flying-saucer-pdf-openpdf/9.3.1/flying-saucer-pdf-openpdf-9.3.1.jar
MD5: 0eaa23a25650a31ef04d2529f1910927
SHA1: 4d6ca8fcf48795e16f3dbdb73b6ee32815576ebf
SHA256:ef0813115bb61c93f0b60cf4b49a4e38a280ba5f3e117016069eeaec4635fd8c
Referenced In Project/Scope: CORE:compile
flying-saucer-pdf-openpdf-9.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

h2-2.2.224.jar

Description:

H2 Database Engine

License:

MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/
EPL 1.0: https://opensource.org/licenses/eclipse-1.0.php
File Path: /home/ed/Programs/mvn-repository/com/h2database/h2/2.2.224/h2-2.2.224.jar
MD5: 769d5a85d19ccc2b06620f8c81d6d8f8
SHA1: 7bdade27d8cd197d9b5ce9dc251f41d2edc5f7ad
SHA256:b9d8f19358ada82a4f6eb5b174c6cfe320a375b5a9cb5a4fe456d623e6e55497
Referenced In Project/Scope: CORE:compile
h2-2.2.224.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

CVE-2018-14335 (OSSINDEX)  

h2database - Improper Link Resolution Before File Access

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CWE-59 Improper Link Resolution Before File Access ('Link Following')

CVSSv3:
  • Base Score: MEDIUM (6.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.h2database:h2:2.2.224:*:*:*:*:*:*:*

h2-2.2.224.jar: data.zip: table.js

File Path: /home/ed/Programs/mvn-repository/com/h2database/h2/2.2.224/h2-2.2.224.jar/org/h2/util/data.zip/org/h2/server/web/res/table.js
MD5: f374e067dff4b106b77abab77b360d8b
SHA1: 67d0af73251e86e079f1db4b837920309a1a3993
SHA256:75e452b34b317d0a8c630b9ac469db3d82988e221d41adc17cf1bab3c0e88c78
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

h2-2.2.224.jar: data.zip: tree.js

File Path: /home/ed/Programs/mvn-repository/com/h2database/h2/2.2.224/h2-2.2.224.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.js
MD5: 760f137680a67ae829c2000c4156e050
SHA1: d947ebba0777d68aa9397fc7d8b04ce2a725c12b
SHA256:2bb3d968d50a5d96912f77552d772184d0213e2601895517ba53afa64dc433ed
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

hibernate-commons-annotations-6.0.6.Final.jar

Description:

Common reflection code used in support of annotation processing

License:

GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1
File Path: /home/ed/Programs/mvn-repository/org/hibernate/common/hibernate-commons-annotations/6.0.6.Final/hibernate-commons-annotations-6.0.6.Final.jar
MD5: c155df7d9f04d15f3f6bbe79f4907074
SHA1: 77a5f94b56d49508e0ee334751db5b78e5ccd50c
SHA256:cd974e0a8481fafdbaf9b4a0f08bb5a6c969b0365482763eedf77e6fd7f493b7
Referenced In Project/Scope: CORE:compile
hibernate-commons-annotations-6.0.6.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-testing@6.4.1.Final

Identifiers

hibernate-core-6.4.1.Final.jar

Description:

Hibernate's core ORM functionality

License:

GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1
File Path: /home/ed/Programs/mvn-repository/org/hibernate/orm/hibernate-core/6.4.1.Final/hibernate-core-6.4.1.Final.jar
MD5: e72592b644fe11e1a7aa4ac3e792e991
SHA1: 3dcefddf6609e6491d37208bcc0cab1273598cbd
SHA256:05b7a932adb71937979b0a9cb9a5b98428ce5d2aa184a6c9c1ffb5a19d342f44
Referenced In Project/Scope: CORE:compile
hibernate-core-6.4.1.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

hibernate-entitymanager-6.0.0.Alpha7.jar

Description:

Hibernate ORM 6.0.0.Alpha7 release.  See http://hibernate.org/orm/releases/6.0

License:

GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1
File Path: /home/ed/Programs/mvn-repository/org/hibernate/orm/hibernate-entitymanager/6.0.0.Alpha7/hibernate-entitymanager-6.0.0.Alpha7.jar
MD5: 7d89646843567b2f7173d53ccfc3084b
SHA1: 5aa00e052da6a0410d9da06ef5aa013b9719b5ab
SHA256:6c9b812e8e51bd8c6ee48a447b941184ca92c3b7417154adb77e75b5c39c174a
Referenced In Project/Scope: CORE:compile
hibernate-entitymanager-6.0.0.Alpha7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

hibernate-validator-8.0.1.Final.jar

Description:

Hibernate's Jakarta Bean Validation reference implementation.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/hibernate/validator/hibernate-validator/8.0.1.Final/hibernate-validator-8.0.1.Final.jar
MD5: 66985b6bf8da17611031e2421c235241
SHA1: e49e116b3d3928060599b176b3538bb848718e95
SHA256:8c1244a498231091fe723d9666a93444ee9f93607245c6b29829dc5fe57a335c
Referenced In Project/Scope: CORE:compile
hibernate-validator-8.0.1.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

hsqldb-2.7.2.jar

Description:

HSQLDB - Lightweight 100% Java SQL Database Engine

License:

HSQLDB License, a BSD open source license: http://hsqldb.org/web/hsqlLicense.html
File Path: /home/ed/Programs/mvn-repository/org/hsqldb/hsqldb/2.7.2/hsqldb-2.7.2.jar
MD5: dab42304e10a7983af59ce89a8ccee12
SHA1: d92d4d2aa515714da2165c9d640d584c2896c9df
SHA256:aa455133e664f6a7e6f30cd0cd4f8ad83dfbd94eb717c438548e446784614a92
Referenced In Project/Scope: CORE:compile
hsqldb-2.7.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

imgscalr-lib-4.2.jar

Description:

imgscalr is an simple and efficient best-practices image-scaling and manipulation library implemented in pure Java.

License:

ASF 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/imgscalr/imgscalr-lib/4.2/imgscalr-lib-4.2.jar
MD5: 1c4860cbc02f8c1766396d68636ab9ab
SHA1: e2838f7119361511ef7d54fe0d502bf07f3325eb
SHA256:6f128a71c5e87a16f810513a73ad3c77d0ee0bb622ee0ce1ead115bccbc76d0a
Referenced In Project/Scope: CORE:compile
imgscalr-lib-4.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

istack-commons-runtime-4.1.2.jar

Description:

istack common utility code

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/com/sun/istack/istack-commons-runtime/4.1.2/istack-commons-runtime-4.1.2.jar
MD5: 535154ef647af2a52478c4debec93659
SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739
SHA256:7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee
Referenced In Project/Scope: CORE:compile
istack-commons-runtime-4.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

jackson-core-2.16.1.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/fasterxml/jackson/core/jackson-core/2.16.1/jackson-core-2.16.1.jar
MD5: 0f51c6a7d713aed6e044cf1692bb59f4
SHA1: 9456bb3cdd0f79f91a5f730a1b1bb041a380c91f
SHA256:f5f8ef90609e64fec82eb908e497dc7d81b2eb983fe509b870292a193cde4dfb
Referenced In Project/Scope: CORE:compile
jackson-core-2.16.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

jackson-databind-2.16.1.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/fasterxml/jackson/core/jackson-databind/2.16.1/jackson-databind-2.16.1.jar
MD5: ac71b868569d329136f2c63f34dd2c89
SHA1: 02a16efeb840c45af1e2f31753dfe76795278b73
SHA256:baf8a8ebee8f45ef68cdd5e2dd3923b3e296c0937b96ec0b4806aa3a31bccd1d
Referenced In Project/Scope: CORE:compile
jackson-databind-2.16.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

jai-imageio-core-1.4.0.jar

Description:

    Java Advanced Imaging Image I/O Tools API core, but without the classes 
    involved with javax.media.jai dependencies, JPEG2000 or 
    codecLibJIIO, meaning that this library can be distributed under the 
    modified BSD license and should be GPL compatible.
  

License:

BSD 3-clause License w/nuclear disclaimer: LICENSE.txt
File Path: /home/ed/Programs/mvn-repository/com/github/jai-imageio/jai-imageio-core/1.4.0/jai-imageio-core-1.4.0.jar
MD5: 6978d733bfb55c0a82639f724fe5f3bb
SHA1: fb6d79b929556362a241b2f65a04e538062f0077
SHA256:8ad3c68e9efffb10ac87ff8bc589adf64b04a729c5194c079efd0643607fd72a
Referenced In Project/Scope: CORE:runtime
jai-imageio-core-1.4.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.google.zxing/javase@3.5.2

Identifiers

jakarta.activation-2.0.1.jar

Description:

Jakarta Activation

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/com/sun/activation/jakarta.activation/2.0.1/jakarta.activation-2.0.1.jar
MD5: 39228ac67f033514a0ccb3360ac461f3
SHA1: 828b80e886a52bb09fe41ff410b10b342f533ce1
SHA256:b9e24b7dd6e07495562ea96531be3130c96dba4d78e1dfd88adbbdebf4332871
Referenced In Project/Scope: CORE:compile
jakarta.activation-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.sun.mail/jakarta.mail@2.0.1

Identifiers

jakarta.activation-api-2.1.2.jar

Description:

  Specification

License:

EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/jakarta/activation/jakarta.activation-api/2.1.2/jakarta.activation-api-2.1.2.jar
MD5: 1af11450fafc7ee26c633d940286bc16
SHA1: 640c0d5aff45dbff1e1a1bc09673ff3a02b1ba12
SHA256:f53f578dd0eb4170c195a4e215c59a38abfb4123dcb95dd902fef92876499fbb
Referenced In Project/Scope: CORE:compile
jakarta.activation-api-2.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

jakarta.el-5.0.0-M1.jar

Description:

Jakarta Expression Language Implementation

License:

https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html
File Path: /home/ed/Programs/mvn-repository/org/glassfish/jakarta.el/5.0.0-M1/jakarta.el-5.0.0-M1.jar
MD5: 468e55a104550edeafbec77bb8137405
SHA1: 64280bae9c1140fe4f007e87a9e2d1ea198ba200
SHA256:54ce254eab6971749210eb7074fe17699ed38a9d181aa5e81bbf8283fd0b4833
Referenced In Project/Scope: CORE:compile
jakarta.el-5.0.0-M1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

CVE-2023-5763  

In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
CWE-20 Improper Input Validation, CWE-913 Improper Control of Dynamically-Managed Code Resources

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

jakarta.el-api-5.0.0.jar

Description:

        Jakarta Expression Language defines an expression language for Java applications
    

License:

https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html
File Path: /home/ed/Programs/mvn-repository/jakarta/el/jakarta.el-api/5.0.0/jakarta.el-api-5.0.0.jar
MD5: 191b53c8c1c12c969f0678f9c6e073b0
SHA1: 2a22b304920f43d6427cdefb5ce5f6726e2a63a3
SHA256:57b822380207900f5145c2a687384c50fd41495d388a235791d96ae3b9bfd36d
Referenced In Project/Scope: CORE:compile
jakarta.el-api-5.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jakarta.inject-api-2.0.1.jar

Description:

Jakarta Dependency Injection

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/jakarta/inject/jakarta.inject-api/2.0.1/jakarta.inject-api-2.0.1.jar
MD5: 72003bf6efcc8455d414bbd7da86c11c
SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e
SHA256:f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c
Referenced In Project/Scope: CORE:runtime
jakarta.inject-api-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jakarta.mail-2.0.1.jar

Description:

Jakarta Mail API

License:

http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/com/sun/mail/jakarta.mail/2.0.1/jakarta.mail-2.0.1.jar
MD5: 8885560796641719f1cc0c9ea17b8bee
SHA1: 96d3645f02a92bcc5e7ae1ff037151e44179f230
SHA256:8988bdbde922ee173db7179e23393dd2258f3b64f708f41082e03f0e0494cc23
Referenced In Project/Scope: CORE:compile
jakarta.mail-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

jakarta.persistence-api-3.1.0.jar

Description:

Jakarta Persistence 3.1 API jar

License:

Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/jakarta/persistence/jakarta.persistence-api/3.1.0/jakarta.persistence-api-3.1.0.jar
MD5: 35a1b7dfb38cf44ff795be607b0e6b5b
SHA1: 66901fa1c373c6aff65c13791cc11da72060a8d6
SHA256:475389446d35c6f46c565728b756dc508c284644ea2690644e0d8e7e339d42fd
Referenced In Project/Scope: CORE:compile
jakarta.persistence-api-3.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jakarta.transaction-api-2.0.1.jar

Description:

Jakarta Transactions

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/ed/Programs/mvn-repository/jakarta/transaction/jakarta.transaction-api/2.0.1/jakarta.transaction-api-2.0.1.jar
MD5: 5315974a3935e342b40849478e1c9966
SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a
SHA256:50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875
Referenced In Project/Scope: CORE:compile
jakarta.transaction-api-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jakarta.validation-api-3.0.2.jar

Description:

        Jakarta Bean Validation API
    

License:

Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/jakarta/validation/jakarta.validation-api/3.0.2/jakarta.validation-api-3.0.2.jar
MD5: 3a1ee6efca3e41e3320599790f54c5eb
SHA1: 92b6631659ba35ca09e44874d3eb936edfeee532
SHA256:291c25e6910cc6a7ebd96d4c6baebf6d7c37676c5482c2d96146e901b62c1fc9
Referenced In Project/Scope: CORE:compile
jakarta.validation-api-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jakarta.xml.bind-api-4.0.1.jar

Description:

Jakarta XML Binding API 4.0 Design Specification

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.1/jakarta.xml.bind-api-4.0.1.jar
MD5: e62084f1afb23eccde6645bf3a9eb06f
SHA1: ca2330866cbc624c7e5ce982e121db1125d23e15
SHA256:287f3b6d0600082e0b60265d7de32be403ee7d7269369c9718d9424305b89d95
Referenced In Project/Scope: CORE:compile
jakarta.xml.bind-api-4.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

jandex-3.1.2.jar

Description:

SmallRye Build Parent POM

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/io/smallrye/jandex/3.1.2/jandex-3.1.2.jar
MD5: 757ae579a3a52c03c3c60fbe393c086f
SHA1: a6c1c89925c7df06242b03dddb353116ceb9584c
SHA256:dee12fa1787d5523ed1a02d6c63b19e7aef6ac560f7c6d70595db01aa37e041e
Referenced In Project/Scope: CORE:runtime
jandex-3.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-testing@6.4.1.Final

Identifiers

javase-3.5.2.jar

Description:

Java SE-specific extensions to core ZXing library

File Path: /home/ed/Programs/mvn-repository/com/google/zxing/javase/3.5.2/javase-3.5.2.jar
MD5: 533316e37d639469925b61b6ec50dbc7
SHA1: b9b1eecd1032e57d086ae80019861f77e8b54752
SHA256:a1289c546d1f4f978363247b0aa5a211fa635abb40a58999f7c34cdd8081e37d
Referenced In Project/Scope: CORE:compile
javase-3.5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

javax.persistence-api-2.2.jar

Description:

Java(TM) Persistence API

License:

Eclipse Public License v1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/javax/persistence/javax.persistence-api/2.2/javax.persistence-api-2.2.jar
MD5: e6520b3435f5b6d58eee415b5542abf8
SHA1: 25665ac8c0b62f50e6488173233239120fc52c96
SHA256:5578b71b37999a5eaed3fea0d14aa61c60c6ec6328256f2b63472f336318baf4
Referenced In Project/Scope: CORE:compile
javax.persistence-api-2.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jaxb-core-4.0.4.jar

Description:

JAXB Core module. Contains sources required by XJC, JXC and Runtime modules.

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/ed/Programs/mvn-repository/org/glassfish/jaxb/jaxb-core/4.0.4/jaxb-core-4.0.4.jar
MD5: 244f2bbf8fca5549421d9199fab22f53
SHA1: 2d5aadd02af86f1e9d8c6f7e8501673f915d4e25
SHA256:0112a26623460fb4df5a0a29b663f2adfe7e9584eb138ae047b5a21c9457f0d7
Referenced In Project/Scope: CORE:compile
jaxb-core-4.0.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

jboss-logging-3.5.0.Final.jar

Description:

The JBoss Logging Framework

License:

Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/jboss/logging/jboss-logging/3.5.0.Final/jboss-logging-3.5.0.Final.jar
MD5: bdb57db05e9905e02dbbf1cbedf26469
SHA1: c19307cc11f28f5e2679347e633a3294d865334d
SHA256:7bb135b081952f6d32d83374619ae5201b05ca3bf862a28dd111016ce19b2c07
Referenced In Project/Scope: CORE:compile
jboss-logging-3.5.0.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-testing@6.4.1.Final

Identifiers

jboss-transaction-api_1.2_spec-1.1.1.Final.jar

Description:

The Java Transaction 1.2 API classes

License:

Common Development and Distribution License: http://repository.jboss.org/licenses/cddl.txt
GNU General Public License, Version 2 with the Classpath Exception: http://repository.jboss.org/licenses/gpl-2.0-ce.txt
File Path: /home/ed/Programs/mvn-repository/org/jboss/spec/javax/transaction/jboss-transaction-api_1.2_spec/1.1.1.Final/jboss-transaction-api_1.2_spec-1.1.1.Final.jar
MD5: 1e633c47138aba999d39692a31a1a124
SHA1: a8485cab9484dda36e9a8c319e76b5cc18797b58
SHA256:a310a50b9bdc44aaf36362dc9bb212235a147ffa8ef72dc9544a39c329eabbc3
Referenced In Project/Scope: CORE:compile
jboss-transaction-api_1.2_spec-1.1.1.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jcip-annotations-1.0-1.jar

Description:

    A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/github/stephenc/jcip/jcip-annotations/1.0-1/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256:4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Project/Scope: CORE:compile
jcip-annotations-1.0-1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.nimbusds/nimbus-jose-jwt@9.37.3

Identifiers

jcip-annotations-1.0.jar

File Path: /home/ed/Programs/mvn-repository/net/jcip/jcip-annotations/1.0/jcip-annotations-1.0.jar
MD5: 9d5272954896c5a5d234f66b7372b17a
SHA1: afba4942caaeaf46aab0b976afd57cc7c181467e
SHA256:be5805392060c71474bf6c9a67a099471274d30b83eef84bfc4e0889a4f1dcc0
Referenced In Project/Scope: CORE:provided
jcip-annotations-1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.google.code.findbugs/annotations@3.0.1u2

Identifiers

jcl-over-slf4j-2.0.7.jar

Description:

JCL 1.2 implemented over SLF4J

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/slf4j/jcl-over-slf4j/2.0.7/jcl-over-slf4j-2.0.7.jar
MD5: 4e8d6cd31f7e6277280c95157ac7845a
SHA1: f127fe5ee53404a8b3697cdd032dd1dd6a29dd77
SHA256:41806757e1d26dae5d6db2ca7d4a5176eed2d6e709cd86564d4a11dab0601742
Referenced In Project/Scope: CORE:compile
jcl-over-slf4j-2.0.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jcommander-1.82.jar

Description:

Command line parsing library for Java

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/beust/jcommander/1.82/jcommander-1.82.jar
MD5: c350dc0db8aa038e6bbaf0050720d69c
SHA1: 0a7c5fef184d238065de38f81bbc6ee50cca2e21
SHA256:deeac157c8de6822878d85d0c7bc8467a19cc8484d37788f7804f039dde280b1
Referenced In Project/Scope: CORE:compile
jcommander-1.82.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.google.zxing/javase@3.5.2

Identifiers

jna-5.13.0.jar

Description:

Java Native Access

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/net/java/dev/jna/jna/5.13.0/jna-5.13.0.jar
MD5: bd2e5bc6b4b020c2d9a6e17a8e9bcef1
SHA1: 1200e7ebeedbe0d10062093f32925a912020e747
SHA256:66d4f819a062a51a1d5627bffc23fac55d1677f0e0a1feba144aabdd670a64bb
Referenced In Project/Scope: CORE:compile
jna-5.13.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jna-5.13.0.jar: jnidispatch.dll

File Path: /home/ed/Programs/mvn-repository/net/java/dev/jna/jna/5.13.0/jna-5.13.0.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 1d3902f504da15af632c84e5c0219f63
SHA1: dbb6d15f1c240778bd76715b6eb4254e4712e31f
SHA256:29fe4c6371b0b1685909c5b5f69d4976244006f81a2ffc9342a8948bbd8fa8a0
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

jna-5.13.0.jar: jnidispatch.dll

File Path: /home/ed/Programs/mvn-repository/net/java/dev/jna/jna/5.13.0/jna-5.13.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 34d12b1e2af72d9bb267bbc8c0d53e4a
SHA1: d9ed8776645f6b4f52df16132450863c47ea92d7
SHA256:13b2cac3f50368ab97fa2e3b0d0d2cb612f68449d5bbd6de187fc85ee4469d03
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

jna-5.13.0.jar: jnidispatch.dll

File Path: /home/ed/Programs/mvn-repository/net/java/dev/jna/jna/5.13.0/jna-5.13.0.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 676f82a561fafeec6d8cf6d8319dee2d
SHA1: 01759bb9e7dd8513c1d25baff2c8ab3298db720d
SHA256:1b06cba48eea2ad4881bc88a2749e40500dbc87c1a2149290eb61d473a64e4c1
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

jna-platform-5.13.0.jar

Description:

Java Native Access Platform

License:

LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/net/java/dev/jna/jna-platform/5.13.0/jna-platform-5.13.0.jar
MD5: 7cc7af47ad1f151faa57ef0624b2f271
SHA1: 88e9a306715e9379f3122415ef4ae759a352640d
SHA256:474d7b88f6e97009b6ec1d98c3024dd95c23187c65dabfbc35331bcac3d173dd
Referenced In Project/Scope: CORE:compile
jna-platform-5.13.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

jsoup-1.17.1.jar

Description:

jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers.

License:

The MIT License: https://jsoup.org/license
File Path: /home/ed/Programs/mvn-repository/org/jsoup/jsoup/1.17.1/jsoup-1.17.1.jar
MD5: 5577bee5bbea235ec21b65643c419f1b
SHA1: 752fccc9fcb6ec5be460a559e92662658a4755fe
SHA256:9da350a86ec44adbe152a7258dbebad0030cb98aff74384b8b83f126223e51a5
Referenced In Project/Scope: CORE:compile
jsoup-1.17.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

jsr305-3.0.1.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/google/code/findbugs/jsr305/3.0.1/jsr305-3.0.1.jar
MD5: c6532beb3f7cc54a8d73d25d5602b9e4
SHA1: f7be08ec23c21485b9b5a1cf1654c2ec8c58168d
SHA256:c885ce34249682bc0236b4a7d56efcc12048e6135a5baf7a9cde8ad8cda13fcd
Referenced In Project/Scope: CORE:provided
jsr305-3.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.google.code.findbugs/annotations@3.0.1u2

Identifiers

logback-core-1.4.14.jar

Description:

logback-core module

License:

http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/ed/Programs/mvn-repository/ch/qos/logback/logback-core/1.4.14/logback-core-1.4.14.jar
MD5: 7367629d307fa3d0b82d76b9d3f1d09a
SHA1: 4d3c2248219ac0effeb380ed4c5280a80bf395e8
SHA256:f8c2f05f42530b1852739507c1792f0080167850ed8f396444c6913d6617a293
Referenced In Project/Scope: CORE:compile
logback-core-1.4.14.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/ch.qos.logback/logback-classic@1.4.14

Identifiers

mariadb-java-client-3.3.2.jar

Description:

JDBC driver for MariaDB and MySQL

License:

LGPL-2.1
File Path: /home/ed/Programs/mvn-repository/org/mariadb/jdbc/mariadb-java-client/3.3.2/mariadb-java-client-3.3.2.jar
MD5: 15d2af531d996b010fa3bb6bbdc6a819
SHA1: c3f513098af6c54702529d3e8758885ad7502dcd
SHA256:2a67ef3cc1ca481965a0e7f2d4174d126f3464d02b4055a441261fad8c196769
Referenced In Project/Scope: CORE:compile
mariadb-java-client-3.3.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

micrometer-commons-1.12.1.jar

Description:

Module containing common code

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/io/micrometer/micrometer-commons/1.12.1/micrometer-commons-1.12.1.jar
MD5: 2518ae277e56aea5e37e3fc2f578dfa4
SHA1: abcc6b294e60582afdfae6c559c94ad1d412ce2d
SHA256:295785b04cd4de7711bb16730da5e9829bac55a8879d52120625dac6c89904ed
Referenced In Project/Scope: CORE:compile
micrometer-commons-1.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

micrometer-observation-1.12.1.jar

Description:

Module containing Observation related code

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/io/micrometer/micrometer-observation/1.12.1/micrometer-observation-1.12.1.jar
MD5: b55c9caac5c8f778996937c3f6cf4101
SHA1: fbd0e0e9b6a36effd53e0eee35b050ed1f548ae5
SHA256:48f6607b248e8b77ee9f7b3934f70124471daf947b30480c1b9c0e9d9f996c83
Referenced In Project/Scope: CORE:compile
micrometer-observation-1.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

mysql-connector-j-8.0.33.jar

Description:

JDBC Type 4 driver for MySQL.

License:

The GNU General Public License, v2 with Universal FOSS Exception, v1.0
File Path: /home/ed/Programs/mvn-repository/com/mysql/mysql-connector-j/8.0.33/mysql-connector-j-8.0.33.jar
MD5: 801b67e18f23e4e9ec392812a1c108d4
SHA1: 9e64d997873abc4318620264703d3fdb6b02dd5a
SHA256:e2a3b2fc726a1ac64e998585db86b30fa8bf3f706195b78bb77c5f99bf877bd9
Referenced In Project/Scope: CORE:compile
mysql-connector-j-8.0.33.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

CVE-2023-22102  

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
NVD-CWE-noinfo

CVSSv3:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:1.6/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

nimbus-jose-jwt-9.37.3.jar (shaded: com.google.code.gson:gson:2.10.1)

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/nimbusds/nimbus-jose-jwt/9.37.3/nimbus-jose-jwt-9.37.3.jar/META-INF/maven/com.google.code.gson/gson/pom.xml
MD5: c13f373086992bab8989b514941891a6
SHA1: ce159faf33c1e665e1f3a785a5d678a2b20151bc
SHA256:d2b115634f5c085db4b9c9ffc2658e89e231fdbfbe2242121a1cd95d4d948dd7
Referenced In Project/Scope: CORE:compile

Identifiers

nimbus-jose-jwt-9.37.3.jar

Description:

        Java library for Javascript Object Signing and Encryption (JOSE) and
        JSON Web Tokens (JWT)
    

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/com/nimbusds/nimbus-jose-jwt/9.37.3/nimbus-jose-jwt-9.37.3.jar
MD5: a2ecba11e197522b7f963cbcf0b59715
SHA1: 700f71ffefd60c16bd8ce711a956967ea9071cec
SHA256:12ae4a3a260095d7aeba2adea7ae396e8b9570db8b7b409e09a824c219cc0444
Referenced In Project/Scope: CORE:compile
nimbus-jose-jwt-9.37.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

ojdbc10-19.3.0.0.jar

Description:

Oracle JDBC Driver compatible with JDK10 and JDK11

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/ojdbc10/19.3.0.0/ojdbc10-19.3.0.0.jar
MD5: 4c78ba260b5c62dc32754a26d5f654f0
SHA1: bba59347e68c9416d14fcc9a9209e869f842e48d
SHA256:fa22689cd3fbb037f4ec864125ebe78325f3811fc50cf194c6bd70fe7e514568
Referenced In Project/Scope: CORE:compile
ojdbc10-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

ons-19.3.0.0.jar

Description:

Java Client-Side Oracle Notification Services(ONS) 

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/ons/19.3.0.0/ons-19.3.0.0.jar
MD5: ac4a31065dcbf2286a46cb68e9f4d1fd
SHA1: cf3f3ef525c61a27fe9952652a156ddd738b1cd5
SHA256:6e3f243700716c4fa2e9ddfaa08c9394ad6fda3a640d3bef03941f7b573df9d7
Referenced In Project/Scope: CORE:compile
ons-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

openpdf-1.3.35.jar

Description:

Open and Free PDF library.

License:

https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html, https://www.mozilla.org/en-US/MPL/2.0/
File Path: /home/ed/Programs/mvn-repository/com/github/librepdf/openpdf/1.3.35/openpdf-1.3.35.jar
MD5: b5ab43b404d5c496dac010e8bf7816a6
SHA1: 75d51b3afe693385ffc5f296109547ced38889d5
SHA256:f72e4ac5ccb7d871288105f79559ecce62dfa4f23359b1f5538309c8847d6d90
Referenced In Project/Scope: CORE:compile
openpdf-1.3.35.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

oraclepki-19.3.0.0.jar

Description:

Oracle PKI to access Oracle Wallets from Java 

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/oraclepki/19.3.0.0/oraclepki-19.3.0.0.jar
MD5: babe79be0b8106cd1090a7194994b300
SHA1: 0e52a34f271c6c62ee1a73b71cc19da5459b709f
SHA256:04bdcbaa8da2c5800403ad0f448bec2867c6e9a12665d3f2c2aba1539dec24dc
Referenced In Project/Scope: CORE:compile
oraclepki-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

osdt_core-19.3.0.0.jar

Description:

osdt_core.jar to access Oracle Wallets from Java 

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/osdt_core/19.3.0.0/osdt_core-19.3.0.0.jar
MD5: 74366ecfe0555a7ee277d1ce11a4933e
SHA1: 2e01c262879c97de876c238966eb1da48542f2e8
SHA256:c7a90c07a12e73d03c1edd6a02e699001213e698fe0f5225a2771ccd46ab0b63
Referenced In Project/Scope: CORE:compile
osdt_core-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

postgresql-42.7.1.jar

Description:

PostgreSQL JDBC Driver Postgresql

License:

BSD-2-Clause: https://jdbc.postgresql.org/about/license.html
File Path: /home/ed/Programs/mvn-repository/org/postgresql/postgresql/42.7.1/postgresql-42.7.1.jar
MD5: b4eb1aeaee4d3465b58f910ef47a0d49
SHA1: 66098cc4f7dca6f7f5b4b847c5cc8699fc079e5b
SHA256:49bba9c3200d4f64ae73903d56ce1bd09c74517dfe31acb44745506b4fcede53
Referenced In Project/Scope: CORE:compile
postgresql-42.7.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

protobuf-java-3.21.9.jar

Description:

    Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an
    efficient yet extensible format.
  

License:

https://opensource.org/licenses/BSD-3-Clause
File Path: /home/ed/Programs/mvn-repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar
MD5: 3b4b9fcc1feaaa49edf970fd4915a0dc
SHA1: ed1240d9231044ce6ccf1978512f6e44416bb7e7
SHA256:1b78b4a76a71512debfdff8f8fc5aef6bfd459f65758fecf7aff245e6e6301e4
Referenced In Project/Scope: CORE:compile
protobuf-java-3.21.9.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

resilience4j-circuitbreaker-2.2.0.jar

Description:

Resilience4j is a lightweight, easy-to-use fault tolerance library designed for Java8 and functional programming

License:

Apache-2.0: https://github.com/resilience4j/resilience4j/blob/master/LICENSE.txt
File Path: /home/ed/Programs/mvn-repository/io/github/resilience4j/resilience4j-circuitbreaker/2.2.0/resilience4j-circuitbreaker-2.2.0.jar
MD5: cd68419d2a18356559957b0c0b0e27d2
SHA1: dd296acf884f278c33d262e757ccedbe402926af
SHA256:b87b0de1051e466190a2ea35f53e5c67d9268fb4000400e07bd1cbf9f006fbf4
Referenced In Project/Scope: CORE:compile
resilience4j-circuitbreaker-2.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

resilience4j-core-2.2.0.jar

Description:

Resilience4j is a lightweight, easy-to-use fault tolerance library designed for Java8 and functional programming

License:

Apache-2.0: https://github.com/resilience4j/resilience4j/blob/master/LICENSE.txt
File Path: /home/ed/Programs/mvn-repository/io/github/resilience4j/resilience4j-core/2.2.0/resilience4j-core-2.2.0.jar
MD5: b611481f2f07e337aa9a3ea0fe30fa35
SHA1: 61b780cfbfbc41d7b8b26278ca3b81c034330457
SHA256:6200917bb21c30134c27e3de8bc8c6e4a7760d87579a0dc4e2dc54888beab5ce
Referenced In Project/Scope: CORE:compile
resilience4j-core-2.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.resilience4j/resilience4j-circuitbreaker@2.2.0

Identifiers

simplefan-19.3.0.0.jar

Description:

Oracle Simple FAN 

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/simplefan/19.3.0.0/simplefan-19.3.0.0.jar
MD5: 9a1f7448f4c1fb779b1d8816e51a2c2f
SHA1: bcbfbb3cc529995f33c8694eb7cbc605c129e4e6
SHA256:5138d658edff0e0106f0559f68c72fb90f1cd34381492995b75d0012ea9e12f2
Referenced In Project/Scope: CORE:compile
simplefan-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

slf4j-api-2.0.9.jar

Description:

The slf4j API

License:

http://www.opensource.org/licenses/mit-license.php
File Path: /home/ed/Programs/mvn-repository/org/slf4j/slf4j-api/2.0.9/slf4j-api-2.0.9.jar
MD5: 45630e54b0f0ac2b3c80462515ad8fda
SHA1: 7cf2726fdcfbc8610f9a71fb3ed639871f315340
SHA256:0818930dc8d7debb403204611691da58e49d42c50b6ffcfdce02dadb7c3c2b6c
Referenced In Project/Scope: CORE:compile
slf4j-api-2.0.9.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

spring-core-6.1.2.jar

Description:

Spring Core

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ed/Programs/mvn-repository/org/springframework/spring-core/6.1.2/spring-core-6.1.2.jar
MD5: 98bedebd5de314d344ed3a7dcad01c66
SHA1: e43c71a9eaca454654621f7d272f15b53c68d583
SHA256:8e3f7378e98c26500bdb5ecd6865778f57a22787eb2f11b9bd5fb8e438a0c631
Referenced In Project/Scope: CORE:compile
spring-core-6.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

spring-web-6.1.2.jar

Description:

Spring Web

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ed/Programs/mvn-repository/org/springframework/spring-web/6.1.2/spring-web-6.1.2.jar
MD5: a39761bc7a706c70f6ca3ab805a97b34
SHA1: 0f26b98778376cc39afb04fbb6fdd7543bef89f2
SHA256:3f2012a24c6213f155b6bc69aa3ecafe2a373c1e92a26dbecc62ff575c3a1fb3
Referenced In Project/Scope: CORE:compile
spring-web-6.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

sqlite-jdbc-3.44.1.0.jar

Description:

SQLite JDBC library

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/xerial/sqlite-jdbc/3.44.1.0/sqlite-jdbc-3.44.1.0.jar
MD5: 595940ed571cbc2bb771c8fdbe30350c
SHA1: 012e6182deef32d366ade664aa33bec9f4dd3ffe
SHA256:e7f9ac47f4ae61f2e63157a1f97e0750cb6fd90c9d0bf25f188260e732f284fa
Referenced In Project/Scope: CORE:compile
sqlite-jdbc-3.44.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll

File Path: /home/ed/Programs/mvn-repository/org/xerial/sqlite-jdbc/3.44.1.0/sqlite-jdbc-3.44.1.0.jar/org/sqlite/native/Windows/aarch64/sqlitejdbc.dll
MD5: ce75734cdb53aab66aa77c7a14c116af
SHA1: 0c4fe25bf9a5e7a3706227d42bfcf12d6e8db121
SHA256:6afde351ba082e446a04fcb656b6438b8ab0568ed5df94273cc0e643fb0c2356
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll

File Path: /home/ed/Programs/mvn-repository/org/xerial/sqlite-jdbc/3.44.1.0/sqlite-jdbc-3.44.1.0.jar/org/sqlite/native/Windows/armv7/sqlitejdbc.dll
MD5: 3e5c736ce4cc6207078ff98b402c46cc
SHA1: f26c42c2ff3a050fe6bc88872c2b8732eef2621b
SHA256:253b4dee0397003c4049fd97fc1d868874fc6a37ce3bbd69488fbdd695493f24
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll

File Path: /home/ed/Programs/mvn-repository/org/xerial/sqlite-jdbc/3.44.1.0/sqlite-jdbc-3.44.1.0.jar/org/sqlite/native/Windows/x86/sqlitejdbc.dll
MD5: 395f3f3e482a15932e93c4ea5957bb66
SHA1: 5efb64df0aa24bd86965770012cac5303e613ccb
SHA256:d19150a9c336b1d01b614a99a76c05328aa37841fbd37aafeea6503f3cd056c1
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

sqlite-jdbc-3.44.1.0.jar: sqlitejdbc.dll

File Path: /home/ed/Programs/mvn-repository/org/xerial/sqlite-jdbc/3.44.1.0/sqlite-jdbc-3.44.1.0.jar/org/sqlite/native/Windows/x86_64/sqlitejdbc.dll
MD5: e1d69e2d6b6b96891a16068b9e4cf439
SHA1: e32f4dc6dbe9e5cd3a33508757feec9f5d4e198a
SHA256:393e8faa8231ac4090f4feabecaf2db00c7bff4b2671c685850b36910d694967
Referenced In Project/Scope: CORE:compile

Identifiers

  • None

txw2-4.0.4.jar

Description:

        TXW is a library that allows you to write XML documents.
    

File Path: /home/ed/Programs/mvn-repository/org/glassfish/jaxb/txw2/4.0.4/txw2-4.0.4.jar
MD5: 8d3e81725d90d0c42dcdd04b471f5dfa
SHA1: cfd2bcf08782673ac370694fdf2cf76dbaa607ef
SHA256:32e7bd5178e29f2294d03d2793c41e54e52358b6ab95cd1343f26c1c2b274227
Referenced In Project/Scope: CORE:compile
txw2-4.0.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-spring@6.1.2

Identifiers

ucp-19.3.0.0.jar

Description:

Oracle Universal Connection Pool (UCP)

License:

Oracle Free Use Terms and Conditions (FUTC)
File Path: /home/ed/Programs/mvn-repository/com/oracle/ojdbc/ucp/19.3.0.0/ucp-19.3.0.0.jar
MD5: 9845d08450b16c7ae81da60689d27f3c
SHA1: 796b661b0bb1818b7c04171837356acddcea504c
SHA256:23d8debe40a764df74d5eda7e8c1ce9b2c190a34f739ca4d751eaa94114d31cc
Referenced In Project/Scope: CORE:compile
ucp-19.3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

velocity-engine-core-2.3.jar (shaded: commons-io:commons-io:2.8.0)

Description:

The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
  

File Path: /home/ed/Programs/mvn-repository/org/apache/velocity/velocity-engine-core/2.3/velocity-engine-core-2.3.jar/META-INF/maven/commons-io/commons-io/pom.xml
MD5: bde9745d9cea5e45d720cb5a860f1fc6
SHA1: 9bde4473ef8c6f2e5aef5bc5fbf357663a90834e
SHA256:d7c8641a37d6e76f36fb9e81fc1420e26a09d63fa32f00f74764de067ca8347d
Referenced In Project/Scope: CORE:compile

Identifiers

velocity-engine-core-2.3.jar

Description:

Apache Velocity is a general purpose template engine.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/org/apache/velocity/velocity-engine-core/2.3/velocity-engine-core-2.3.jar
MD5: e761e6088b946b42289c5d676a515581
SHA1: e2133b723d0e42be74880d34de6bf6538ea7f915
SHA256:b086cee8fd8183e240b4afcf54fe38ec33dd8eb0da414636e5bf7aa4d9856629
Referenced In Project/Scope: CORE:compile
velocity-engine-core-2.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

waffle-jna-3.3.0.jar

Description:

WAFFLE JNA implementation

File Path: /home/ed/Programs/mvn-repository/com/github/waffle/waffle-jna/3.3.0/waffle-jna-3.3.0.jar
MD5: 7d4ab9e0376129387e6565b040f2c0af
SHA1: 6c1a06b345702bb1dfd77006af926b091bded851
SHA256:301cb389402618a0a8e7fb56c4b47e20f1f9c774f99a3d7272435bae2d323580
Referenced In Project/Scope: CORE:compile
waffle-jna-3.3.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.libraries/bundle-hibernate@6.4.1

Identifiers

xercesImpl-2.12.2.jar

Description:

      Xerces2 provides high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces continues to build upon the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program.

      The Apache Xerces2 parser is the reference implementation of XNI but other parser components, configurations, and parsers can be written using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.

      Xerces2 provides fully conforming XML Schema 1.0 and 1.1 processors. An experimental implementation of the "XML Schema Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010)" is also provided for evaluation. For more information, refer to the XML Schema page.

      Xerces2 also provides a complete implementation of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML Catalogs v1.1.

      Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that it does not yet provide an option to enable normalization checking as described in section 2.13 of this specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.  
	

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ed/Programs/mvn-repository/xerces/xercesImpl/2.12.2/xercesImpl-2.12.2.jar
MD5: 40e4f2d5aacfbf51a9a1572d77a0e5e9
SHA1: f051f988aa2c9b4d25d05f95742ab0cc3ed789e2
SHA256:6fc991829af1708d15aea50c66f0beadcd2cfeb6968e0b2f55c1b0909883fe16
Referenced In Project/Scope: CORE:compile
xercesImpl-2.12.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/io.github.together.modules/core@3.1.0

Identifiers

  • pkg:maven/xerces/xercesImpl@2.12.2  (Confidence:High)
  • cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*  (Confidence:Low)  

CVE-2017-10355 (OSSINDEX)  

sonatype-2017-0348 - xerces:xercesImpl - Denial of Service (DoS)

The software contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.
CWE-833 Deadlock

CVSSv3:
  • Base Score: MEDIUM (5.900000095367432)
  • Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:xerces:xercesImpl:2.12.2:*:*:*:*:*:*:*

xml-apis-1.4.01.jar

Description:

xml-commons provides an Apache-hosted set of DOM, SAX, and 
    JAXP interfaces for use in other xml-based projects. Our hope is that we 
    can standardize on both a common version and packaging scheme for these 
    critical XML standards interfaces to make the lives of both our developers 
    and users easier. The External Components portion of xml-commons contains 
    interfaces that are defined by external standards organizations. For DOM, 
    that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for 
    JAXP it's Sun.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
The SAX License: http://www.saxproject.org/copying.html
The W3C License: http://www.w3.org/TR/2004/REC-DOM-Level-3-Core-20040407/java-binding.zip
File Path: /home/ed/Programs/mvn-repository/xml-apis/xml-apis/1.4.01/xml-apis-1.4.01.jar
MD5: 7eaad6fea5925cca6c36ee8b3e02ac9d
SHA1: 3789d9fada2d3d458c4ba2de349d48780f381ee3
SHA256:a840968176645684bb01aed376e067ab39614885f9eee44abe35a5f20ebe7fad
Referenced In Project/Scope: CORE:compile
xml-apis-1.4.01.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/xerces/xercesImpl@2.12.2

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.