Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: RealLifeDeveloper Common

com.reallifedeveloper:rld-common:2.1.2-SNAPSHOT

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
amqp-client-5.25.0.jarpkg:maven/com.rabbitmq/amqp-client@5.25.0 048
antlr4-runtime-4.13.0.jarpkg:maven/org.antlr/antlr4-runtime@4.13.0 030
checker-qual-3.49.5.jarpkg:maven/org.checkerframework/checker-qual@3.49.5 044
error_prone_annotations-2.38.0.jarpkg:maven/com.google.errorprone/error_prone_annotations@2.38.0 029
gson-2.13.1.jarcpe:2.3:a:google:gson:2.13.1:*:*:*:*:*:*:*pkg:maven/com.google.code.gson/gson@2.13.1 0Highest31
jackson-core-2.19.1.jarcpe:2.3:a:fasterxml:jackson-modules-java8:2.19.1:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.1 0Low47
jackson-databind-2.19.1.jarcpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.19.1:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1 0Highest41
jackson-jakarta-rs-base-2.19.1.jarpkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base@2.19.1 038
jackson-jakarta-rs-json-provider-2.19.1.jarpkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1 038
jackson-module-jakarta-xmlbind-annotations-2.19.1.jarpkg:maven/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations@2.19.1 039
jakarta.activation-api-2.1.3.jarpkg:maven/jakarta.activation/jakarta.activation-api@2.1.3 045
jakarta.annotation-api-3.0.0.jarcpe:2.3:a:oracle:projects:3.0.0:*:*:*:*:*:*:*pkg:maven/jakarta.annotation/jakarta.annotation-api@3.0.0 0Low42
jakarta.persistence-api-3.2.0.jarpkg:maven/jakarta.persistence/jakarta.persistence-api@3.2.0 040
jakarta.servlet-api-6.1.0.jarcpe:2.3:a:oracle:projects:6.1.0:*:*:*:*:*:*:*pkg:maven/jakarta.servlet/jakarta.servlet-api@6.1.0 0Low44
jakarta.ws.rs-api-4.0.0.jarcpe:2.3:a:web_project:web:4.0.0:*:*:*:*:*:*:*pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@4.0.0 0Low33
jakarta.xml.bind-api-4.0.2.jarpkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.2 031
jsr305-3.0.2.jarpkg:maven/com.google.code.findbugs/jsr305@3.0.2 017
kafka-clients-3.8.1.jarcpe:2.3:a:apache:kafka:3.8.1:*:*:*:*:*:*:*pkg:maven/org.apache.kafka/kafka-clients@3.8.1HIGH2Highest24
log4j-core-2.25.1.jarcpe:2.3:a:apache:log4j:2.25.1:*:*:*:*:*:*:*pkg:maven/org.apache.logging.log4j/log4j-core@2.25.1 0Highest42
logback-core-1.5.18.jarcpe:2.3:a:qos:logback:1.5.18:*:*:*:*:*:*:*pkg:maven/ch.qos.logback/logback-core@1.5.18 0Highest39
lombok-1.18.38.jar: mavenEcjBootstrapAgent.jar 07
lombok-1.18.38.jarpkg:maven/org.projectlombok/lombok@1.18.38 036
lz4-java-1.8.0.jarpkg:maven/org.lz4/lz4-java@1.8.0 037
markdown4j-2.2-cj-1.1.jarpkg:maven/org.commonjava.googlecode.markdown4j/markdown4j@2.2-cj-1.1 022
micrometer-commons-1.14.8.jarcpe:2.3:a:4d:4d:1.14.8:*:*:*:*:*:*:*pkg:maven/io.micrometer/micrometer-commons@1.14.8 0Low65
slf4j-api-2.0.17.jarpkg:maven/org.slf4j/slf4j-api@2.0.17 029
snappy-java-1.1.10.5.jar: snappyjava.dll 02
snappy-java-1.1.10.5.jar: snappyjava.dll 02
snappy-java-1.1.10.5.jar: snappyjava.dll 02
snappy-java-1.1.10.5.jarcpe:2.3:a:xerial:snappy-java:1.1.10.5:*:*:*:*:*:*:*pkg:maven/org.xerial.snappy/snappy-java@1.1.10.5 0Highest44
spotbugs-annotations-4.9.3.jarpkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.3 053
spring-core-6.2.8.jarcpe:2.3:a:pivotal_software:spring_framework:6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:6.2.8:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-core@6.2.8 0Highest41
spring-data-commons-3.5.1.jarcpe:2.3:a:pivotal_software:spring_data_commons:3.5.1:*:*:*:*:*:*:*pkg:maven/org.springframework.data/spring-data-commons@3.5.1 0Highest32
spring-data-jpa-3.5.1.jarcpe:2.3:a:pivotal_software:spring_data_jpa:3.5.1:*:*:*:*:*:*:*pkg:maven/org.springframework.data/spring-data-jpa@3.5.1 0Highest30
spring-kafka-3.3.7.jarpkg:maven/org.springframework.kafka/spring-kafka@3.3.7 052
spring-retry-2.0.12.jarpkg:maven/org.springframework.retry/spring-retry@2.0.12 048
spring-security-core-6.5.1.jarcpe:2.3:a:pivotal_software:spring_security:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:6.5.1:*:*:*:*:*:*:*
pkg:maven/org.springframework.security/spring-security-core@6.5.1 0Highest38
spring-web-6.2.8.jarcpe:2.3:a:pivotal_software:spring_framework:6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:web_project:web:6.2.8:*:*:*:*:*:*:*
pkg:maven/org.springframework/spring-web@6.2.8 0Highest35
tomcat-jdbc-11.0.9.jarpkg:maven/org.apache.tomcat/tomcat-jdbc@11.0.9 023
tomcat-juli-11.0.9.jarpkg:maven/org.apache.tomcat/tomcat-juli@11.0.9 026
zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll 04
zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll 04
zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll 04
zstd-jni-1.5.6-4.jarpkg:maven/com.github.luben/zstd-jni@1.5.6-4 043

Dependencies (vulnerable)

amqp-client-5.25.0.jar

Description:

The RabbitMQ Java client library allows Java applications to interface with RabbitMQ.

License:

AL 2.0: https://www.apache.org/licenses/LICENSE-2.0.html
GPL v2: https://www.gnu.org/licenses/gpl-2.0.txt
MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/
File Path: C:\Users\Henrik\.m2\repository\com\rabbitmq\amqp-client\5.25.0\amqp-client-5.25.0.jar
MD5: c2e27869a87b0127a78d37dc25bb26c0
SHA1: f3303742cae7b0ef37b9966a54de82b635dc0207
SHA256:5aa96f005084139eb1077d94b55dc6428eca7da7e2cc53eab44a773391f8aa8f
Referenced In Project/Scope: RealLifeDeveloper Common:compile
amqp-client-5.25.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

antlr4-runtime-4.13.0.jar

Description:

The ANTLR 4 Runtime

License:

https://www.antlr.org/license.html
File Path: C:\Users\Henrik\.m2\repository\org\antlr\antlr4-runtime\4.13.0\antlr4-runtime-4.13.0.jar
MD5: bff95723c494b332b14575d713a65df4
SHA1: 5a02e48521624faaf5ff4d99afc88b01686af655
SHA256:bd7f7b5d07bc0b047f10915b32ca4bb1de9e57d8049098882e4453c88c076a5d
Referenced In Project/Scope: RealLifeDeveloper Common:compile
antlr4-runtime-4.13.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.data/spring-data-jpa@3.5.1

Identifiers

checker-qual-3.49.5.jar

Description:

checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.

License:

The MIT License: http://opensource.org/licenses/MIT
File Path: C:\Users\Henrik\.m2\repository\org\checkerframework\checker-qual\3.49.5\checker-qual-3.49.5.jar
MD5: a6525c2747603fb3ec22d18c4adc7419
SHA1: f0d119b5a4adb4164e9d6fa9fd3ffa5d0e458963
SHA256:508c83c62c344f6f7ee28f47b88a8797d6116d043bfd1ca0576c828dd1df2880
Referenced In Project/Scope: RealLifeDeveloper Common:provided
checker-qual-3.49.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

error_prone_annotations-2.38.0.jar

Description:

Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\google\errorprone\error_prone_annotations\2.38.0\error_prone_annotations-2.38.0.jar
MD5: 912f8206614000252841d89cb0461895
SHA1: fc0ae991433e8590ba51cd558421478318a74c8c
SHA256:6661d5335090a5fc61dd869d2095bc6c1e2156e3aa47a6e4ababdf64c99a7889
Referenced In Project/Scope: RealLifeDeveloper Common:compile
error_prone_annotations-2.38.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.google.code.gson/gson@2.13.1

Identifiers

gson-2.13.1.jar

Description:

Gson JSON library

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\google\code\gson\gson\2.13.1\gson-2.13.1.jar
MD5: d82c16b045ce4832679d70f26a67b30c
SHA1: 853ce06c11316b33a8eae5e9095da096a9528b8f
SHA256:94855942d4992f112946d3de1c334e709237b8126d8130bf07807c018a4a2120
Referenced In Project/Scope: RealLifeDeveloper Common:compile
gson-2.13.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

jackson-core-2.19.1.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\fasterxml\jackson\core\jackson-core\2.19.1\jackson-core-2.19.1.jar
MD5: 52aec5a03ab9fd81dcc8fee45952da17
SHA1: 6e5a8cb8a6cada322497cefb7726657d98aaee15
SHA256:c46369e1a21810100adbc92503b62f15a9ef1640427932f4fe1588ef7ce7e480
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jackson-core-2.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1

Identifiers

jackson-databind-2.19.1.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\fasterxml\jackson\core\jackson-databind\2.19.1\jackson-databind-2.19.1.jar
MD5: c0afda7ea90602055f7ddca32f2c48ad
SHA1: e8cb8e76faea3e0791165f5d3614fc45933b2ee0
SHA256:0bc539401d52c6b14e668947c851dcc49f78a4ada3d1fc8e8f71440613fc26ce
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jackson-databind-2.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1

Identifiers

jackson-jakarta-rs-base-2.19.1.jar

Description:

Pile of code that is shared by all Jackson-based Jakarta-RS
providers.
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\fasterxml\jackson\jakarta\rs\jackson-jakarta-rs-base\2.19.1\jackson-jakarta-rs-base-2.19.1.jar
MD5: 481478fe0fcb05e4d40bc3afd7281872
SHA1: b74a8afaeeeaac42d88569c182103e93b637ac9e
SHA256:0794947b195305c98684d50294c405396fe633bc576138c11a06f6c508b2dd03
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jackson-jakarta-rs-base-2.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1

Identifiers

jackson-jakarta-rs-json-provider-2.19.1.jar

Description:

Functionality to handle JSON input/output for Jakarta-RS implementations
(like Jersey and RESTeasy) using standard Jackson data binding.
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\fasterxml\jackson\jakarta\rs\jackson-jakarta-rs-json-provider\2.19.1\jackson-jakarta-rs-json-provider-2.19.1.jar
MD5: 66b37e3693a4ff2b698b51182dfeb36f
SHA1: 3f2914238b711ae9fdc059725451bae635272c75
SHA256:ae2f53ddfd0d81963805aa5a5e8efbe421af696a3cb4f91b48d01351523fadf9
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jackson-jakarta-rs-json-provider-2.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

jackson-module-jakarta-xmlbind-annotations-2.19.1.jar

Description:

Support for using Jakarta XML Bind (aka JAXB 3.0) annotations as an alternative
  to "native" Jackson annotations, for configuring data-binding.

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\fasterxml\jackson\module\jackson-module-jakarta-xmlbind-annotations\2.19.1\jackson-module-jakarta-xmlbind-annotations-2.19.1.jar
MD5: 793b6b030e963c32081c2e0c5ad02a35
SHA1: 810d73cd2e2f27e01a50789520485292d9dba4f2
SHA256:bffdf874b869fce700440f77082a7b8074a42913f0cd504202498aee05b469a3
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jackson-module-jakarta-xmlbind-annotations-2.19.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1

Identifiers

jakarta.activation-api-2.1.3.jar

Description:

  Specification

License:

EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: C:\Users\Henrik\.m2\repository\jakarta\activation\jakarta.activation-api\2.1.3\jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256:01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jakarta.activation-api-2.1.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider@2.19.1

Identifiers

jakarta.annotation-api-3.0.0.jar

Description:

Jakarta Annotations API

License:

EPL 2.0: https://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: C:\Users\Henrik\.m2\repository\jakarta\annotation\jakarta.annotation-api\3.0.0\jakarta.annotation-api-3.0.0.jar
MD5: 7faffaab962918da4cf5ddfd76609dd2
SHA1: 54f928fadec906a99d558536756d171917b9d936
SHA256:b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jakarta.annotation-api-3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.data/spring-data-jpa@3.5.1

Identifiers

jakarta.persistence-api-3.2.0.jar

Description:

Jakarta Persistence 3.2 API jar

License:

Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: C:\Users\Henrik\.m2\repository\jakarta\persistence\jakarta.persistence-api\3.2.0\jakarta.persistence-api-3.2.0.jar
MD5: 79acec18d202797dcba1fff596a47684
SHA1: bb75a113f3fa191c2c7ee7b206d8e674251b3129
SHA256:be8a26b0e75c84c1b7600f759256fbc68d60333d89ec0ce3f784fc3ffa09aa8c
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jakarta.persistence-api-3.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

jakarta.servlet-api-6.1.0.jar

Description:

Jakarta Servlet 6.1

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: C:\Users\Henrik\.m2\repository\jakarta\servlet\jakarta.servlet-api\6.1.0\jakarta.servlet-api-6.1.0.jar
MD5: 314c930b3e40ac1abc3529c7c9942f09
SHA1: 1169a246913fe3823782af7943e7a103634867c5
SHA256:8a31f465f3593bf2351531a5c952014eb839da96a605b5825b93dd54714c48c4
Referenced In Project/Scope: RealLifeDeveloper Common:provided
jakarta.servlet-api-6.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

jakarta.ws.rs-api-4.0.0.jar

Description:

Jakarta RESTful Web Services

License:

https://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html
File Path: C:\Users\Henrik\.m2\repository\jakarta\ws\rs\jakarta.ws.rs-api\4.0.0\jakarta.ws.rs-api-4.0.0.jar
MD5: 9b7cc90c000f193157d60d95caf45972
SHA1: c27a67f84ca491efcb3fa68f4df926e8a110069e
SHA256:6368b126cbcf34e694bb9ba5b9fe3e5040b7acea7ce622e636d698bb085fd2a6
Referenced In Project/Scope: RealLifeDeveloper Common:provided
jakarta.ws.rs-api-4.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

jakarta.xml.bind-api-4.0.2.jar

Description:

Jakarta XML Binding API 4.0 Design Specification

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: C:\Users\Henrik\.m2\repository\jakarta\xml\bind\jakarta.xml.bind-api\4.0.2\jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256:0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: RealLifeDeveloper Common:compile
jakarta.xml.bind-api-4.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@7.0.5.Final

Identifiers

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\com\google\code\findbugs\jsr305\3.0.2\jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: RealLifeDeveloper Common:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.3

Identifiers

kafka-clients-3.8.1.jar

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\apache\kafka\kafka-clients\3.8.1\kafka-clients-3.8.1.jar
MD5: 439e11bddafaa80e634a55409d719552
SHA1: fd79e3aa252c6d818334e9c0bac8166b426e498c
SHA256:d6d8c4ad7ab00c6adb03ad9ad7188af32fa7c5de62ca1d8625e086512987a584
Referenced In Project/Scope: RealLifeDeveloper Common:compile
kafka-clients-3.8.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.kafka/spring-kafka@3.3.7

Identifiers

CVE-2025-27818  

A possible security vulnerability has been identified in Apache Kafka.
This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config
and a SASL-based security protocol, which has been possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0).
When configuring the broker via config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config`
property for any of the connector's Kafka clients to "com.sun.security.auth.module.LdapLoginModule", which can be done via the
`producer.override.sasl.jaas.config`, `consumer.override.sasl.jaas.config`, or `admin.override.sasl.jaas.config` properties.
This will allow the server to connect to the attacker's LDAP server
and deserialize the LDAP response, which the attacker can use to execute java deserialization gadget chains on the Kafka connect server.
Attacker can cause unrestricted deserialization of untrusted data (or) RCE vulnerability when there are gadgets in the classpath.

Since Apache Kafka 3.0.0, users are allowed to specify these properties in connector configurations for Kafka Connect clusters running with out-of-the-box
configurations. Before Apache Kafka 3.0.0, users may not specify these properties unless the Kafka Connect cluster has been reconfigured with a connector
client override policy that permits them.

Since Apache Kafka 3.9.1/4.0.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage
in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" are disabled in Apache Kafka Connect 3.9.1/4.0.0. 

We advise the Kafka users to validate connector configurations and only allow trusted LDAP configurations. Also examine connector dependencies for 
vulnerable versions and either upgrade their connectors, upgrading that specific dependency, or removing the connectors as options for remediation. Finally,
in addition to leveraging the "org.apache.kafka.disallowed.login.modules" system property, Kafka Connect users can also implement their own connector
client config override policy, which can be used to control which Kafka client properties can be overridden directly in a connector config and which cannot.
CWE-502 Deserialization of Untrusted Data

CVSSv3:
  • Base Score: HIGH (8.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2025-27817  

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use the "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url" configuratin to read arbitrary contents of the disk and environment variables or make requests to an unintended location. In particular, this flaw may be used in Apache Kafka Connect to escalate from REST API access to filesystem/environment/URL access, which may be undesirable in certain environments, including SaaS products. 

Since Apache Kafka 3.9.1/4.0.0, we have added a system property ("-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls") to set the allowed urls in SASL JAAS configuration. In 3.9.1, it accepts all urls by default for backward compatibility. However in 4.0.0 and newer, the default value is empty list and users have to set the allowed urls explicitly.
CWE-918 Server-Side Request Forgery (SSRF)

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

log4j-core-2.25.1.jar

Description:

A versatile, industrial-grade, and reference implementation of the Log4j API.
    It bundles a rich set of components to assist various use cases:
    Appenders targeting files, network sockets, databases, SMTP servers;
    Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;
    Filters that can be configured using log event rates, regular expressions, scripts, time, etc.
    It contains several extension points to introduce custom components, if needed.

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\apache\logging\log4j\log4j-core\2.25.1\log4j-core-2.25.1.jar
MD5: ec95ac453934a56229ace160e28aa791
SHA1: 32b3a228d5a30a4528b6c7354fe6cff9524d89e7
SHA256:78c232747855464b182f0abf78a99a22c88d4d270ff585343dab55576d7420e2
Referenced In Project/Scope: RealLifeDeveloper Common:compile
log4j-core-2.25.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

logback-core-1.5.18.jar

Description:

logback-core module

License:

http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: C:\Users\Henrik\.m2\repository\ch\qos\logback\logback-core\1.5.18\logback-core-1.5.18.jar
MD5: 10bcea83842beead15f072799b9c923d
SHA1: 6c0375624f6f36b4e089e2488ba21334a11ef13f
SHA256:85139e7b57b464f8e5e36326dd81317648bed199ccc4f98cd42585f8d7571027
Referenced In Project/Scope: RealLifeDeveloper Common:compile
logback-core-1.5.18.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

lombok-1.18.38.jar: mavenEcjBootstrapAgent.jar

File Path: C:\Users\Henrik\.m2\repository\org\projectlombok\lombok\1.18.38\lombok-1.18.38.jar\lombok\launch\mavenEcjBootstrapAgent.jar
MD5: 885d5d6be90a5dcd4b82cdf741e3f31a
SHA1: e1f7f1779f40157fd0b984c1bc32a0cb45cae66e
SHA256:74a80a6ee84e5c6fe497dfcc46a46dbe30578525e747eb531e918ee0750c8da9
Referenced In Project/Scope: RealLifeDeveloper Common:provided

Identifiers

  • None

lombok-1.18.38.jar

Description:

Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: C:\Users\Henrik\.m2\repository\org\projectlombok\lombok\1.18.38\lombok-1.18.38.jar
MD5: 789cacd8d3969e9d23e6e6baec747f70
SHA1: 57f8f5e02e92a30fd21b80cbd426a4172b5f8e29
SHA256:1e1e427c36ff63c44fd30ef292d9e773ea3154460ab6265d3fed7e6f5bc50fb9
Referenced In Project/Scope: RealLifeDeveloper Common:provided
lombok-1.18.38.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

lz4-java-1.8.0.jar

Description:

Java ports and bindings of the LZ4 compression algorithm and the xxHash hashing algorithm

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\lz4\lz4-java\1.8.0\lz4-java-1.8.0.jar
MD5: 936a927700aa8fc3b75d21d7571171f6
SHA1: 4b986a99445e49ea5fbf5d149c4b63f6ed6c6780
SHA256:d74a3334fb35195009b338a951f918203d6bbca3d1d359033dc33edd1cadc9ef
Referenced In Project/Scope: RealLifeDeveloper Common:runtime
lz4-java-1.8.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.kafka/spring-kafka@3.3.7

Identifiers

markdown4j-2.2-cj-1.1.jar

Description:

An OSGi-fied version of markdown4j

File Path: C:\Users\Henrik\.m2\repository\org\commonjava\googlecode\markdown4j\markdown4j\2.2-cj-1.1\markdown4j-2.2-cj-1.1.jar
MD5: ab033e59e040e34bb79bb2220b0b7207
SHA1: 9e920737c365f0a7985d2050bb99a7edd36b6e19
SHA256:28eb991f702c6d85d6cafd68c24d1ce841d1f5c995c943f25aedb433c0c13f60
Referenced In Project/Scope: RealLifeDeveloper Common:compile
markdown4j-2.2-cj-1.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

micrometer-commons-1.14.8.jar

Description:

Module containing common code

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\io\micrometer\micrometer-commons\1.14.8\micrometer-commons-1.14.8.jar
MD5: afc6a3ed0d778c9748ed3636d5bfac35
SHA1: 51baec7ebe61f1cd38db19b35e57ac248345cc5f
SHA256:277cd6ec84a392e1ae056129078344493fbfbf60cf15f3e88e29d26f8a6b62c7
Referenced In Project/Scope: RealLifeDeveloper Common:compile
micrometer-commons-1.14.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework/spring-context@6.2.8

Identifiers

slf4j-api-2.0.17.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: C:\Users\Henrik\.m2\repository\org\slf4j\slf4j-api\2.0.17\slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256:7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: RealLifeDeveloper Common:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

snappy-java-1.1.10.5.jar: snappyjava.dll

File Path: C:\Users\Henrik\.m2\repository\org\xerial\snappy\snappy-java\1.1.10.5\snappy-java-1.1.10.5.jar\org\xerial\snappy\native\Windows\aarch64\snappyjava.dll
MD5: e048fff98f2eab2d60b8d1b0ba68c738
SHA1: 2b35231edb0e225390bb9811a859ffdac70a4f5c
SHA256:c8ffc0b29a931c12c134e62d78e78e60f4cb07d341176363729ad9ca64f65008
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

snappy-java-1.1.10.5.jar: snappyjava.dll

File Path: C:\Users\Henrik\.m2\repository\org\xerial\snappy\snappy-java\1.1.10.5\snappy-java-1.1.10.5.jar\org\xerial\snappy\native\Windows\x86\snappyjava.dll
MD5: bf5815cae57523b4abc1e534c42be880
SHA1: 076d9af93933210cb53a952a88b8163b3b0210f5
SHA256:dd61eba39e26462d12828ca2c85a31bb6beec3ee0b27409ad78a92131a3a318a
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

snappy-java-1.1.10.5.jar: snappyjava.dll

File Path: C:\Users\Henrik\.m2\repository\org\xerial\snappy\snappy-java\1.1.10.5\snappy-java-1.1.10.5.jar\org\xerial\snappy\native\Windows\x86_64\snappyjava.dll
MD5: bbf1620e74dd44a34e5a86ccd1c9dc70
SHA1: e4150416cdb0f65ee39e0f1c0c921e3ff9937d4e
SHA256:3879fdfd746b77f29e6fade812669796c8dfcf4db2f5d5409b10c5e584ae5494
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

snappy-java-1.1.10.5.jar

Description:

snappy-java: A fast compression/decompression library

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.html
File Path: C:\Users\Henrik\.m2\repository\org\xerial\snappy\snappy-java\1.1.10.5\snappy-java-1.1.10.5.jar
MD5: a52ffcdbbe525b486237a7098e5c5ff7
SHA1: ac605269f3598506196e469f1fb0d7ed5c55059e
SHA256:0f3f1857ed33116583f480b4df5c0218836c47bfbc9c6221c0d73f356decf37b
Referenced In Project/Scope: RealLifeDeveloper Common:runtime
snappy-java-1.1.10.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.kafka/spring-kafka@3.3.7

Identifiers

spotbugs-annotations-4.9.3.jar

Description:

Annotations the SpotBugs tool supports

License:

GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: C:\Users\Henrik\.m2\repository\com\github\spotbugs\spotbugs-annotations\4.9.3\spotbugs-annotations-4.9.3.jar
MD5: 6149845e438bd5a34ebaf81f8bc9e243
SHA1: 4d362bffcfdfd734999e94d7d98fde678aae71cf
SHA256:13532bfe2f45fcd491432221df72d9cd0efb8f987c9245e12befa192c8925ce3
Referenced In Project/Scope: RealLifeDeveloper Common:provided
spotbugs-annotations-4.9.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

spring-core-6.2.8.jar

Description:

Spring Core

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: C:\Users\Henrik\.m2\repository\org\springframework\spring-core\6.2.8\spring-core-6.2.8.jar
MD5: 4db163bd5ffe489aaf0d3c44f47d66e5
SHA1: 2caf1cef93252f5ef2b7f334b8b4d61f3aecad15
SHA256:27f640340164d74a0e90ee176b75d5a18a93f82fa96f444a757acf0bf3ae7257
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-core-6.2.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework/spring-context@6.2.8

Identifiers

spring-data-commons-3.5.1.jar

Description:

Core Spring concepts underpinning every Spring Data module.

File Path: C:\Users\Henrik\.m2\repository\org\springframework\data\spring-data-commons\3.5.1\spring-data-commons-3.5.1.jar
MD5: 92c4cf932de3c0f2a6c786faae21c83a
SHA1: 90bd3f9edcc3b98e0d49657f3f2152e933b42ae8
SHA256:139fcb68434b4188fa2363e01e8a0a150fbe69f9945c175e4992825cb0fc21d7
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-data-commons-3.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.data/spring-data-jpa@3.5.1

Identifiers

spring-data-jpa-3.5.1.jar

Description:

Spring Data module for JPA repositories.

File Path: C:\Users\Henrik\.m2\repository\org\springframework\data\spring-data-jpa\3.5.1\spring-data-jpa-3.5.1.jar
MD5: 48d14d6ae41fb3d1d3b4f9a710d3c38c
SHA1: 7d34c2d8c8bcd96f5ce3f012c2a88d682a86e14b
SHA256:c18353bfa941d5fd7d38fd7ddf7bf8548ea2dc6af397847b6384e8d0bb029467
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-data-jpa-3.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

spring-kafka-3.3.7.jar

Description:

Spring Kafka Support

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\springframework\kafka\spring-kafka\3.3.7\spring-kafka-3.3.7.jar
MD5: 280a5ca1e4c3b8b5cf6c44bb1017ae38
SHA1: 824e65af5590797390b77bbdd2f55570627cface
SHA256:ed50c5ac2caa4266ae0c2abcee2b8caf14b926e89e85545fada920b56c46d896
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-kafka-3.3.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

spring-retry-2.0.12.jar

Description:

Spring Retry provides an abstraction around retrying failed operations, with an
		emphasis on declarative control of the process and policy-based behaviour that is
		easy to extend and customize. For instance, you can configure a plain POJO
		operation to retry if it fails, based on the type of exception, and with a fixed
		or exponential backoff.

License:

Apache 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\springframework\retry\spring-retry\2.0.12\spring-retry-2.0.12.jar
MD5: a396632dbe08ae5e1b6c77c49677f6d1
SHA1: 62a14736086ffd6f382f0df3bf066a5a34f174fa
SHA256:15e5b238080e05b97d7603472887d658fc018340539b3f0777bc92445bf91dad
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-retry-2.0.12.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.kafka/spring-kafka@3.3.7

Identifiers

spring-security-core-6.5.1.jar

Description:

Spring Security

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: C:\Users\Henrik\.m2\repository\org\springframework\security\spring-security-core\6.5.1\spring-security-core-6.5.1.jar
MD5: 09455e524246114166548b90c8624e39
SHA1: e7df1e6596b39b39f4a01000cab0318c0ed17ab0
SHA256:2da6ce414d447a8c410304b5afaa2f997f81c7cbf098e8e074e44edd8be24392
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-security-core-6.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

spring-web-6.2.8.jar

Description:

Spring Web

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: C:\Users\Henrik\.m2\repository\org\springframework\spring-web\6.2.8\spring-web-6.2.8.jar
MD5: 893e8b28ec10e50cbd0b99476d6e6e29
SHA1: 7b6a4ffb12639779721bc5adbc7f5ba80db72ff9
SHA256:152405afabc056dc8007dca8ef105503c7cbbb132f7d1ab75fef3e27eaabd461
Referenced In Project/Scope: RealLifeDeveloper Common:compile
spring-web-6.2.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

tomcat-jdbc-11.0.9.jar

Description:

Tomcat JDBC Pool Package

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\apache\tomcat\tomcat-jdbc\11.0.9\tomcat-jdbc-11.0.9.jar
MD5: 33339b1830be7d0da11db3f0490753dc
SHA1: 9912f3b1f61f912e255e926dc43824254c658c15
SHA256:9b7d7ad6194c2ee0e0450444c064e5b0b08bdd31a6b35549d6761bda161d4cb0
Referenced In Project/Scope: RealLifeDeveloper Common:compile
tomcat-jdbc-11.0.9.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.reallifedeveloper/rld-common@2.1.2-SNAPSHOT

Identifiers

tomcat-juli-11.0.9.jar

Description:

Tomcat Core Logging Package

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Henrik\.m2\repository\org\apache\tomcat\tomcat-juli\11.0.9\tomcat-juli-11.0.9.jar
MD5: 01302f90fde99c9291317ee15d80ece3
SHA1: 2e0e74acdc27fb46cab23d88d397936aecc72f34
SHA256:ff6f058a86efbbbd4b211b5cc7a2c12b3000298ce9c7bbdeac59b3d7c6d8c911
Referenced In Project/Scope: RealLifeDeveloper Common:compile
tomcat-juli-11.0.9.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.tomcat/tomcat-jdbc@11.0.9

Identifiers

zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll

File Path: C:\Users\Henrik\.m2\repository\com\github\luben\zstd-jni\1.5.6-4\zstd-jni-1.5.6-4.jar\win\aarch64\libzstd-jni-1.5.6-4.dll
MD5: b08a5ca6634687278c4997c8ce65aca2
SHA1: 7dc3e4a45c1c62dff69a02b745c6ca468e870165
SHA256:0bf2e9da03c099466622889b1615b4b569423c6cf6b8e21c2ee7a770723752e9
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll

File Path: C:\Users\Henrik\.m2\repository\com\github\luben\zstd-jni\1.5.6-4\zstd-jni-1.5.6-4.jar\win\amd64\libzstd-jni-1.5.6-4.dll
MD5: ac975e13cee15f26ae3ccef464d9304b
SHA1: 778a639b54df79a883c71ecf4a14647d88b4099b
SHA256:d655eec0e2af60b4147dd5e9defba321a237aba97215656d22eecfcf2fc0d770
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

zstd-jni-1.5.6-4.jar: libzstd-jni-1.5.6-4.dll

File Path: C:\Users\Henrik\.m2\repository\com\github\luben\zstd-jni\1.5.6-4\zstd-jni-1.5.6-4.jar\win\x86\libzstd-jni-1.5.6-4.dll
MD5: 9c9f391cf64b05c87c7c342d249265a0
SHA1: 03df582c031b68b713e056d4029b576649404f83
SHA256:93c6bdfeafa9a1593d4a280accd03417161c0b8ef3f9021210ce31b9b7814577
Referenced In Project/Scope: RealLifeDeveloper Common:runtime

Identifiers

  • None

zstd-jni-1.5.6-4.jar

Description:

JNI bindings for Zstd native library that provides fast and high compression lossless algorithm for Java and all JVM languages.

License:

BSD 2-Clause License: https://opensource.org/licenses/BSD-2-Clause
File Path: C:\Users\Henrik\.m2\repository\com\github\luben\zstd-jni\1.5.6-4\zstd-jni-1.5.6-4.jar
MD5: 808e96f7bc2d4a3c5f68e95786f74cc9
SHA1: ba9e303e0b5e94cdd0017390d7d8c06f47fd61f7
SHA256:793ca8734aa15687e7e64564eab8b6ae9ee2720eae27aa663074682144b1c386
Referenced In Project/Scope: RealLifeDeveloper Common:runtime
zstd-jni-1.5.6-4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.springframework.kafka/spring-kafka@3.3.7

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.