[Backport 2.x] Escape/Unescape pipe UserInfo in ThreadContext #802
Security Report
4 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-12798Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.3.14/436bd0d56730df756cff6d12d0f97df6f275e4a/logback-core-1.3.14.jar Dependency Hierarchy: -> ktlint-0.47.1.jar (Root Library) -> logback-classic-1.3.14.jar -> ❌ logback-core-1.3.14.jar (Vulnerable Library) |
6.6 | logback-core-1.3.14.jar | Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13;ch.qos.logback:logback-classic:1.3.15,1.5.13 | None | |
CVE-2024-12798Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-classic/1.3.14/a2f0045eae641a356b74afb0d3b85268181a93cf/logback-classic-1.3.14.jar Dependency Hierarchy: -> ktlint-0.47.1.jar (Root Library) -> ❌ logback-classic-1.3.14.jar (Vulnerable Library) |
6.6 | logback-classic-1.3.14.jar | Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13;ch.qos.logback:logback-classic:1.3.15,1.5.13 | None | |
CVE-2021-28170Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.glassfish/javax.el/3.0.0/dd532526e7c8de48e40419e6af1183658a973379/javax.el-3.0.0.jar Dependency Hierarchy: -> cron-utils-9.1.6.jar (Root Library) -> ❌ javax.el-3.0.0.jar (Vulnerable Library) |
5.3 | javax.el-3.0.0.jar | Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 | #608 | |
CVE-2024-12801Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.3.14/436bd0d56730df756cff6d12d0f97df6f275e4a/logback-core-1.3.14.jar Dependency Hierarchy: -> ktlint-0.47.1.jar (Root Library) -> logback-classic-1.3.14.jar -> ❌ logback-core-1.3.14.jar (Vulnerable Library) |
4.4 | logback-core-1.3.14.jar | Upgrade to version: ch.qos.logback:logback-core:1.3.15,1.5.13 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: ef830db407b83d6c05c9d031a9fe74dcb6ee1614
Total libraries scanned: 163
Scan token: ed19fcae45e6419ca9e472b82417d981