Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 2.x] Escape/Unescape pipe UserInfo in ThreadContext #802

Closed
wants to merge 1 commit into from

Escape/Unescape pipe UserInfo in ThreadContext (#801)

0ff2c92
Select commit
Loading
Failed to load commit list.
Closed

[Backport 2.x] Escape/Unescape pipe UserInfo in ThreadContext #802

Escape/Unescape pipe UserInfo in ThreadContext (#801)
0ff2c92
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Mar 19, 2025 in 4m 34s

Security Report

4 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2024-12798

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.3.14/436bd0d56730df756cff6d12d0f97df6f275e4a/logback-core-1.3.14.jar

Dependency Hierarchy:

-> ktlint-0.47.1.jar (Root Library)

   -> logback-classic-1.3.14.jar

     -> ❌ logback-core-1.3.14.jar (Vulnerable Library)

Medium 6.6 logback-core-1.3.14.jar Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13;ch.qos.logback:logback-classic:1.3.15,1.5.13 None
CVE-2024-12798

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-classic/1.3.14/a2f0045eae641a356b74afb0d3b85268181a93cf/logback-classic-1.3.14.jar

Dependency Hierarchy:

-> ktlint-0.47.1.jar (Root Library)

   -> ❌ logback-classic-1.3.14.jar (Vulnerable Library)

Medium 6.6 logback-classic-1.3.14.jar Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13;ch.qos.logback:logback-classic:1.3.15,1.5.13 None
CVE-2021-28170

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.glassfish/javax.el/3.0.0/dd532526e7c8de48e40419e6af1183658a973379/javax.el-3.0.0.jar

Dependency Hierarchy:

-> cron-utils-9.1.6.jar (Root Library)

   -> ❌ javax.el-3.0.0.jar (Vulnerable Library)

Medium 5.3 javax.el-3.0.0.jar Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 #608
CVE-2024-12801

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.3.14/436bd0d56730df756cff6d12d0f97df6f275e4a/logback-core-1.3.14.jar

Dependency Hierarchy:

-> ktlint-0.47.1.jar (Root Library)

   -> logback-classic-1.3.14.jar

     -> ❌ logback-core-1.3.14.jar (Vulnerable Library)

Medium 4.4 logback-core-1.3.14.jar Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13 None

Base branch total remaining vulnerabilities: 0
Base branch commit: ef830db407b83d6c05c9d031a9fe74dcb6ee1614


Total libraries scanned: 163

Scan token: ed19fcae45e6419ca9e472b82417d981