Skip to content

[NCL-9918] Fix CVEs - #80

Open
patrikk0123 wants to merge 1 commit into
Commonjava:masterfrom
patrikk0123:fixCves
Open

patrikk0123 wants to merge 1 commit into
Commonjava:masterfrom
patrikk0123:fixCves

Conversation

@patrikk0123

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 142 dependencies

Detected 10 vulnerabilities (0 Critical, 7 High, 2 Medium, 1 Low)

+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| SEVERITY |            LIBRARY             |       ID       |                                               TOP FIX                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | parsson-1.1.5.jar              | CVE-2026-9563  | Upgrade to version org.eclipse.parsson:parsson:1.1.8, https://github.com/eclipse-ee4j/parsson.git - |
|          |                                |                | 1.1.8                                                                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | plexus-utils-3.5.1.jar         | CVE-2025-67030 | org.codehaus.plexus:plexus-utils:4.0.3,org.codehaus.plexus:plexus-utils:3.6.1                       |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | quarkus-core-3.6.9.jar         | CVE-2024-2700  | Upgrade to version io.quarkus:quarkus-core:3.8.4,3.9.2,3.2.12.Final                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.26.Final.jar | CVE-2026-15554 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.26.Final.jar | CVE-2026-15561 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.26.Final.jar | CVE-2026-5680  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.4.3.Final,                      |
|          |                                |                | io.undertow:undertow-core:2.4.3.Final                                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | xstream-1.4.20.jar             | CVE-2024-47072 | Upgrade to version com.thoughtworks.xstream:xstream - 1.4.21                                        |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| MEDIUM   | commons-lang3-3.13.0.jar       | CVE-2025-48924 | Upgrade to version  https://github.com/apache/commons-lang.git - commons-lang-3.18.0,               |
|          |                                |                | org.apache.commons:commons-lang3:3.18.0                                                             |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| MEDIUM   | undertow-core-2.3.26.Final.jar | CVE-2026-19879 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| LOW      | jansi-2.4.0.jar                | CVE-2026-8484  | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

http-testserver-core-2.3.4-SNAPSHOT.jar
|-- commons-io-2.15.1.jar
	|-- commons-codec-1.16.0.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
|-- undertow-servlet-2.3.26.Final.jar
	|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-junit4-2.3.4-SNAPSHOT.jar
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.3.26.Final.jar
		|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-junit5-2.3.4-SNAPSHOT.jar
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.3.26.Final.jar
		|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- httpclient-4.5.14.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-quarkus-2.3.4-SNAPSHOT.jar
|-- quarkus-arc-deployment-3.6.9.jar
	|-- quarkus-arc-3.6.9.jar
		|-- quarkus-core-3.6.9.jar [1 HIGH]
	|-- quarkus-core-deployment-3.6.9.jar
		|-- quarkus-bootstrap-maven-resolver-3.6.9.jar
			|-- smallrye-beanbag-maven-1.3.2.jar
				|-- commons-lang3-3.13.0.jar [1 MEDIUM]
				|-- maven-artifact-3.9.6.jar
					|-- commons-lang3-3.13.0.jar [1 MEDIUM]
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-settings-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-resolver-transport-wagon-1.9.18.jar
				|-- wagon-provider-api-3.5.3.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-xml-4.0.0.jar
					|-- maven-xml-impl-4.0.0-alpha-5.jar
						|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- wagon-file-3.5.3.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- wagon-http-3.5.3.jar
				|-- wagon-http-shared-3.5.3.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-embedder-3.9.6.jar
				|-- commons-lang3-3.13.0.jar [1 MEDIUM]
				|-- maven-shared-utils-3.3.4.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
					|-- jansi-2.4.0.jar [1 LOW]
				|-- maven-core-3.9.6.jar
					|-- commons-lang3-3.13.0.jar [1 MEDIUM]
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-model-builder-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-plugin-api-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-sec-dispatcher-2.0.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- jansi-2.4.0.jar [1 LOW]
			|-- maven-resolver-provider-3.9.6.jar
				|-- maven-model-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-repository-metadata-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-settings-builder-3.9.6.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- org.eclipse.sisu.plexus-0.9.0.M2.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
		|-- quarkus-core-3.6.9.jar [1 HIGH]
		|-- readline-2.4.jar
			|-- jansi-2.4.0.jar [1 LOW]
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
|-- quarkus-junit5-3.6.9.jar
	|-- xstream-1.4.20.jar [1 HIGH]
	|-- quarkus-core-3.6.9.jar [1 HIGH]
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.3.26.Final.jar
		|-- undertow-core-2.3.26.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- httpclient-4.5.14.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- jboss-logging-3.6.3.Final.jar
		|-- jboss-logmanager-3.0.4.Final.jar
			|-- parsson-1.1.5.jar [1 HIGH]


No Policy violations were detected

Project 'http-testserver' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=3e4a4791-bd78-42c2-810a-0fe36f078b23
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=377f5a0ae9fd4922a9e55480620df3a0685d6038dc7f41849565798974f4e93d

Mend AI scan succeeded.

Support Token: 2a6853a75baf245b098a515b01e25fa451789044604637

Full logs and artifacts

@dwalluck

Copy link
Copy Markdown
Contributor

Duplicate of #66.

@rnc

rnc commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

@dwalluck I tried asking dependabot to rebase #66 but it just closed it. So this is probably needed.

@rnc

rnc commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

@patrikk0123 Apologies merging the other dependabot PRs caused conflicts...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants