Skip to content

Update dependency com.sparkjava:spark-core to v2.9.4

fefe74a
Select commit
Loading
Failed to load commit list.
Open

Update dependency com.sparkjava:spark-core to v2.9.4 (master) #13

Update dependency com.sparkjava:spark-core to v2.9.4
fefe74a
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Aug 4, 2025 in 50m 14s

Security Report

❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

You have successfully remediated 35 vulnerabilities, but introduced 10 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue Reachability
CVE-2023-36478

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> websocket-server-9.4.48.v20220622.jar

     -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library)

High 7.5 Not Defined 1.1% jetty-http-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty.http2:http2-hpack:9.4.53.v20231009,10.0.16,11.0.16;org.eclipse.jetty.http3:http3-qpack:10.0.16,11.0.16;org.eclipse.jetty:jetty-http:9.4.53.v20231009,10.0.16,11.0.16 None
CVE-2024-13009

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library)

High 7.2 Not Defined 0.0% jetty-server-9.4.48.v20220622.jar Upgrade to version: https://github.com/jetty/jetty.project.git - jetty-9.4.57.v20241219 None
CVE-2024-8184

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library)

Medium 5.9 Not Defined 0.1% jetty-server-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-server:9.4.56,10.0.24,11.0.24,12.0.9, org.eclipse.jetty.ee9:jetty-ee9-nested:9.4.56,10.0.24,11.0.24,12.0.9 None
CVE-2023-40167

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> websocket-server-9.4.48.v20220622.jar

     -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library)

Medium 5.3 Not Defined 2.7% jetty-http-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-http:9.4.52.v20230823,10.0.16,11.0.16,12.0.1 None
CVE-2023-26048

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library)

Medium 5.3 Not Defined 36.1% jetty-server-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14;org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14 None
WS-2023-0236

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-xml/9.4.48.v20220622/2c8b7ad6b64437a693cd30666f3def666aac8207/jetty-xml-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> jetty-webapp-9.4.48.v20220622.jar

     -> ❌ jetty-xml-9.4.48.v20220622.jar (Vulnerable Library)

Low 3.9 Not Defined jetty-xml-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-xml:10.0.16,11.0.16,12.0.0 None
CVE-2024-6763

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> websocket-server-9.4.48.v20220622.jar

     -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library)

Low 3.7 Not Defined 0.1% jetty-http-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12 None
CVE-2024-6763

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library)

Low 3.7 Not Defined 0.1% jetty-server-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12 None
CVE-2023-26049

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> websocket-server-9.4.48.v20220622.jar

     -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library)

Low 2.4 Not Defined 0.3% jetty-http-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-http:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14 None
CVE-2023-26049

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar

Dependency Hierarchy:

-> spark-core-2.9.4.jar (Root Library)

   -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library)

Low 2.4 Not Defined 0.3% jetty-server-9.4.48.v20220622.jar Upgrade to version: org.eclipse.jetty:jetty-http:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-runner:9.4.51.v20230217,10.0.14,11.0.14, org.eclipse.jetty:jetty-server:9.4.51.v20230217,10.0.14,11.0.14 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2019-10241 jetty-servlet-9.4.4.v20170414.jar
CVE-2023-26049 jetty-http-9.4.4.v20170414.jar
CVE-2024-6763 jetty-http-9.4.4.v20170414.jar
CVE-2023-36478 jetty-http-9.4.4.v20170414.jar
CVE-2022-2047 jetty-client-9.4.4.v20170414.jar
CVE-2018-12536 jetty-servlet-9.4.4.v20170414.jar
CVE-2019-10241 jetty-util-9.4.4.v20170414.jar
CVE-2022-2047 jetty-http-9.4.4.v20170414.jar
CVE-2017-7656 jetty-server-9.4.4.v20170414.jar
CVE-2018-12538 jetty-server-9.4.4.v20170414.jar
CVE-2024-8184 jetty-server-9.4.4.v20170414.jar
CVE-2020-27216 jetty-webapp-9.4.4.v20170414.jar
CVE-2017-7657 jetty-http-9.4.4.v20170414.jar
CVE-2017-7656 jetty-http-9.4.4.v20170414.jar
CVE-2018-12536 jetty-util-9.4.4.v20170414.jar
CVE-2023-26048 jetty-server-9.4.4.v20170414.jar
CVE-2021-34428 jetty-server-9.4.4.v20170414.jar
CVE-2022-2047 jetty-server-9.4.4.v20170414.jar
CVE-2021-28169 jetty-server-9.4.4.v20170414.jar
CVE-2017-9735 jetty-util-9.4.4.v20170414.jar
CVE-2017-7658 jetty-http-9.4.4.v20170414.jar
CVE-2019-10241 jetty-server-9.4.4.v20170414.jar
CVE-2020-27218 jetty-server-9.4.4.v20170414.jar
CVE-2019-10247 jetty-server-9.4.4.v20170414.jar
CVE-2023-26049 jetty-server-9.4.4.v20170414.jar
CVE-2021-28169 jetty-http-9.4.4.v20170414.jar
CVE-2024-6763 jetty-server-9.4.4.v20170414.jar
CVE-2018-9159 spark-core-2.6.0.jar
CVE-2017-7658 jetty-server-9.4.4.v20170414.jar
CVE-2017-7657 jetty-server-9.4.4.v20170414.jar
CVE-2018-12536 jetty-server-9.4.4.v20170414.jar
WS-2023-0236 jetty-xml-9.4.4.v20170414.jar
CVE-2024-13009 jetty-server-9.4.4.v20170414.jar
CVE-2023-40167 jetty-http-9.4.4.v20170414.jar
CVE-2021-28165 jetty-io-9.4.4.v20170414.jar

Base branch total remaining vulnerabilities: 98
Base branch commit: null


Total libraries scanned: 44

Scan token: ec592f9c56db488e9534ae7358ddfcaa