Update dependency com.sparkjava:spark-core to v2.9.4 (master) #13
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
You have successfully remediated 35 vulnerabilities, but introduced 10 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|
CVE-2023-36478Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
7.5 | Not Defined | 1.1% | jetty-http-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty.http2:http2-hpack:9.4.53.v20231009,10.0.16,11.0.16;org.eclipse.jetty.http3:http3-qpack:10.0.16,11.0.16;org.eclipse.jetty:jetty-http:9.4.53.v20231009,10.0.16,11.0.16 | None | ||
CVE-2024-13009Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
7.2 | Not Defined | 0.0% | jetty-server-9.4.48.v20220622.jar | Upgrade to version: https://github.com/jetty/jetty.project.git - jetty-9.4.57.v20241219 | None | ||
CVE-2024-8184Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
5.9 | Not Defined | 0.1% | jetty-server-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-server:9.4.56,10.0.24,11.0.24,12.0.9, org.eclipse.jetty.ee9:jetty-ee9-nested:9.4.56,10.0.24,11.0.24,12.0.9 | None | ||
CVE-2023-40167Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
5.3 | Not Defined | 2.7% | jetty-http-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-http:9.4.52.v20230823,10.0.16,11.0.16,12.0.1 | None | ||
CVE-2023-26048Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
5.3 | Not Defined | 36.1% | jetty-server-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14;org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14 | None | ||
WS-2023-0236Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-xml/9.4.48.v20220622/2c8b7ad6b64437a693cd30666f3def666aac8207/jetty-xml-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> jetty-webapp-9.4.48.v20220622.jar -> ❌ jetty-xml-9.4.48.v20220622.jar (Vulnerable Library) |
3.9 | Not Defined | jetty-xml-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-xml:10.0.16,11.0.16,12.0.0 | None | |||
CVE-2024-6763Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
3.7 | Not Defined | 0.1% | jetty-http-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12 | None | ||
CVE-2024-6763Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
3.7 | Not Defined | 0.1% | jetty-server-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12 | None | ||
CVE-2023-26049Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
2.4 | Not Defined | 0.3% | jetty-http-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-http:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14 | None | ||
CVE-2023-26049Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
2.4 | Not Defined | 0.3% | jetty-server-9.4.48.v20220622.jar | Upgrade to version: org.eclipse.jetty:jetty-http:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2019-10241 | jetty-servlet-9.4.4.v20170414.jar |
| CVE-2023-26049 | jetty-http-9.4.4.v20170414.jar |
| CVE-2024-6763 | jetty-http-9.4.4.v20170414.jar |
| CVE-2023-36478 | jetty-http-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-client-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-servlet-9.4.4.v20170414.jar |
| CVE-2019-10241 | jetty-util-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-http-9.4.4.v20170414.jar |
| CVE-2017-7656 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-12538 | jetty-server-9.4.4.v20170414.jar |
| CVE-2024-8184 | jetty-server-9.4.4.v20170414.jar |
| CVE-2020-27216 | jetty-webapp-9.4.4.v20170414.jar |
| CVE-2017-7657 | jetty-http-9.4.4.v20170414.jar |
| CVE-2017-7656 | jetty-http-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-util-9.4.4.v20170414.jar |
| CVE-2023-26048 | jetty-server-9.4.4.v20170414.jar |
| CVE-2021-34428 | jetty-server-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-server-9.4.4.v20170414.jar |
| CVE-2021-28169 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-9735 | jetty-util-9.4.4.v20170414.jar |
| CVE-2017-7658 | jetty-http-9.4.4.v20170414.jar |
| CVE-2019-10241 | jetty-server-9.4.4.v20170414.jar |
| CVE-2020-27218 | jetty-server-9.4.4.v20170414.jar |
| CVE-2019-10247 | jetty-server-9.4.4.v20170414.jar |
| CVE-2023-26049 | jetty-server-9.4.4.v20170414.jar |
| CVE-2021-28169 | jetty-http-9.4.4.v20170414.jar |
| CVE-2024-6763 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-9159 | spark-core-2.6.0.jar |
| CVE-2017-7658 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-7657 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-server-9.4.4.v20170414.jar |
| WS-2023-0236 | jetty-xml-9.4.4.v20170414.jar |
| CVE-2024-13009 | jetty-server-9.4.4.v20170414.jar |
| CVE-2023-40167 | jetty-http-9.4.4.v20170414.jar |
| CVE-2021-28165 | jetty-io-9.4.4.v20170414.jar |
Base branch total remaining vulnerabilities: 98
Base branch commit: null
Total libraries scanned: 44
Scan token: ec592f9c56db488e9534ae7358ddfcaa