Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.1.9Report Generated On : Mon, 29 Jun 2026 17:04:39 GMTDependencies Scanned : 98 (57 unique)Vulnerable Dependencies : 2 Vulnerabilities Found : 2Vulnerabilities Suppressed : 0 ... NVD API Last Checked : 2026-06-29T17:03:07ZNVD API Last Modified : 2026-06-29T16:57:39ZSummary Summary of Vulnerable Dependencies (click to show all)
ffl-core-api-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-api/target/ffl-core-api-3.1.2.jarMD5: 91aa589edaef05ce5d234f224bb18e3fSHA1: e1ecfafdf6671afd88cb26ccd8f9f18a0bc7c5f2SHA256: fe852a63a0224eaf2c8bb0d2cf6bdeaf0b2f965215f1a9bfd904e74cccde86e4
Evidence Type Source Name Value Confidence Vendor file name ffl-core-api High Vendor jar package name api Highest Vendor jar package name core Highest Vendor jar package name ffl Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-core-api Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-api-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-api High Product jar package name api Highest Product jar package name core Highest Product jar package name ffl Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-api High Product pom artifactid ffl-core-api Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-api-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-api@3.1.2 (Confidence :High) ffl-core-commons-3.1.2-repackaged.jarDescription:
Module contenant le core du back-office File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jarMD5: 5eac73bdf0b7ef91bdbefeff3a2d658aSHA1: f0679df4eba1bd0e35e3275d255303c11e31488aSHA256: afb1daa3538df962fafc173b9203b1a67ba7cd34f8e62a0a3830cd9a3fe843aa
Evidence Type Source Name Value Confidence Vendor file name ffl-core-commons High Vendor jar package name com Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest spring-boot-classes BOOT-INF/classes/ Low Vendor Manifest spring-boot-classpath-index BOOT-INF/classpath.idx Low Vendor Manifest spring-boot-layers-index BOOT-INF/layers.idx Low Vendor Manifest spring-boot-lib BOOT-INF/lib/ Low Vendor pom artifactid ffl-core-commons Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-commons High Product jar package name boot Highest Product jar package name boot-inf Highest Product jar package name classes Highest Product jar package name com Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-commons High Product Manifest spring-boot-classes BOOT-INF/classes/ Low Product Manifest spring-boot-classpath-index BOOT-INF/classpath.idx Low Product Manifest spring-boot-layers-index BOOT-INF/layers.idx Low Product Manifest spring-boot-lib BOOT-INF/lib/ Low Product pom artifactid ffl-core-commons Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-commons@3.1.2 (Confidence :High) ffl-core-commons-3.1.2-repackaged.jar: commons-lang3-3.20.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17, 21 and 25 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/commons-lang3-3.20.0.jar
MD5: 4b29562ded527aa074e1d44f8646dac5
SHA1: 65897b3e5731220962e659e001904af3c3cbeba9
SHA256: 69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 25 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 25 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.20.0 High Version Manifest Bundle-Version 3.20.0 High Version Manifest Implementation-Version 3.20.0 High Version pom parent-version 3.20.0 Low Version pom version 3.20.0 Highest
Related Dependencies ffl-core-database-3.1.2.jar: commons-lang3-3.20.0.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/commons-lang3-3.20.0.jar MD5: 4b29562ded527aa074e1d44f8646dac5 SHA1: 65897b3e5731220962e659e001904af3c3cbeba9 SHA256: 69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4 pkg:maven/org.apache.commons/commons-lang3@3.20.0 ffl-core-commons-3.1.2-repackaged.jar: jackson-annotations-2.17.2.jarDescription:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/jackson-annotations-2.17.2.jar
MD5: e68e7e593ae47e106421688707683297
SHA1: 147b7b9412ffff24339f8aba080b292448e08698
SHA256: 873a606e23507969f9bbbea939d5e19274a88775ea5a169ba7e2d795aa5156e1
Evidence Type Source Name Value Confidence Vendor file name jackson-annotations High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-annotations Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-annotations High Vendor pom parent-artifactid jackson-parent Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-annotations High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name Jackson-annotations Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Product Manifest Implementation-Title Jackson-annotations High Product Manifest specification-title Jackson-annotations Medium Product pom artifactid jackson-annotations Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-annotations High Product pom parent-artifactid jackson-parent Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.17.2 High Version Manifest Bundle-Version 2.17.2 High Version Manifest Implementation-Version 2.17.2 High Version pom parent-version 2.17.2 Low Version pom version 2.17.2 Highest
ffl-core-commons-3.1.2-repackaged.jar: jakarta.annotation-api-2.1.1.jarDescription:
Jakarta Annotations API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Evidence Type Source Name Value Confidence Vendor file name jakarta.annotation-api High Vendor jar package name annotation Highest Vendor jar package name jakarta Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.annotation-api Low Vendor pom developer name Dmitry Kornilov Medium Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid jakarta.annotation Highest Vendor pom name Jakarta Annotations API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest Product file name jakarta.annotation-api High Product jar package name annotation Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Annotations API Medium Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Product pom artifactid jakarta.annotation-api Highest Product pom developer name Dmitry Kornilov Low Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid jakarta.annotation Highest Product pom name Jakarta Annotations API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium Version file version 2.1.1 High Version Manifest Bundle-Version 2.1.1 High Version Manifest Implementation-Version 2.1.1 High Version pom parent-version 2.1.1 Low Version pom version 2.1.1 Highest
Related Dependencies ffl-core-database-3.1.2.jar: jakarta.annotation-api-2.1.1.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.annotation-api-2.1.1.jar MD5: 5dac2f68e8288d0add4dc92cb161711d SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3 SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1 pkg:maven/jakarta.annotation/jakarta.annotation-api@2.1.1 (Confidence :High) cpe:2.3:a:oracle:projects:2.1.1:*:*:*:*:*:*:* (Confidence :Low) suppress ffl-core-commons-3.1.2-repackaged.jar: jul-to-slf4j-2.0.18.jarDescription:
JUL to SLF4J bridge License:
https://opensource.org/license/mit File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/jul-to-slf4j-2.0.18.jar
MD5: f339bf7648049b2105e180cab6c45c9d
SHA1: 79739c98001d5c9d078d087d5a348ec9e474ec8f
SHA256: cbb7d1aaaa9e871eb1a06594abd911bf97027152976edf1edc315be75239204e
Evidence Type Source Name Value Confidence Vendor file name jul-to-slf4j High Vendor jar package name bridge Highest Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor Manifest multi-release true Low Vendor pom artifactid jul-to-slf4j Low Vendor pom groupid org.slf4j Highest Vendor pom name JUL to SLF4J bridge High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name jul-to-slf4j High Product jar package name bridge Highest Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name JUL to SLF4J bridge Medium Product Manifest bundle-symbolicname jul.to.slf4j Medium Product Manifest Implementation-Title jul-to-slf4j High Product Manifest multi-release true Low Product pom artifactid jul-to-slf4j Highest Product pom groupid org.slf4j Highest Product pom name JUL to SLF4J bridge High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 2.0.18 High Version Manifest Bundle-Version 2.0.18 High Version Manifest Implementation-Version 2.0.18 High Version pom version 2.0.18 Highest
Related Dependencies ffl-core-database-3.1.2.jar: jul-to-slf4j-2.0.18.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jul-to-slf4j-2.0.18.jar MD5: f339bf7648049b2105e180cab6c45c9d SHA1: 79739c98001d5c9d078d087d5a348ec9e474ec8f SHA256: cbb7d1aaaa9e871eb1a06594abd911bf97027152976edf1edc315be75239204e pkg:maven/org.slf4j/jul-to-slf4j@2.0.18 pkg:maven/org.slf4j/jul-to-slf4j@2.0.18 (Confidence :High) ffl-core-commons-3.1.2-repackaged.jar: log4j-api-2.25.4.jarDescription:
The logging API of the Log4j project.
Library and application code can log through this API.
It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core. License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/log4j-api-2.25.4.jar
MD5: 5efb17ae45b749c1fbfedb3d93375cfc
SHA1: 89ff2217b193fb187b134aa6ebcbfa8a28b018a9
SHA256: c4b642a7f047275215de117e0e3847eb2c7711d84a0aa7433e7b3c096daf341d
Evidence Type Source Name Value Confidence Vendor file name log4j-api High Vendor jar package name apache Highest Vendor jar package name log4j Highest Vendor jar package name logging Highest Vendor jar package name org Highest Vendor jar package name simple Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-api Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j API High Vendor pom parent-artifactid log4j Low Vendor pom url https://logging.apache.org/log4j/2.x/ Highest Product file name log4j-api High Product jar package name apache Highest Product jar package name log4j Highest Product jar package name logging Highest Product jar package name org Highest Product jar package name simple Highest Product jar package name util Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-activationpolicy lazy Low Product Manifest Bundle-Name Apache Log4j API Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Product Manifest Implementation-Title Apache Log4j API High Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low Product Manifest specification-title Apache Log4j API Medium Product pom artifactid log4j-api Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j API High Product pom parent-artifactid log4j Medium Product pom url https://logging.apache.org/log4j/2.x/ Medium Version file version 2.25.4 High Version Manifest Bundle-Version 2.25.4 High Version Manifest Implementation-Version 2.25.4 High Version pom version 2.25.4 Highest
Related Dependencies ffl-core-database-3.1.2.jar: log4j-api-2.25.4.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/log4j-api-2.25.4.jar MD5: 5efb17ae45b749c1fbfedb3d93375cfc SHA1: 89ff2217b193fb187b134aa6ebcbfa8a28b018a9 SHA256: c4b642a7f047275215de117e0e3847eb2c7711d84a0aa7433e7b3c096daf341d pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4 ffl-core-commons-3.1.2-repackaged.jar: log4j-to-slf4j-2.25.4.jarDescription:
Forwards the Log4j API calls to SLF4J.
(Refer to the `log4j-slf4j[2]-impl` artifacts for forwarding SLF4J to the Log4j API.) License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/log4j-to-slf4j-2.25.4.jar
MD5: b3d45f5534aa71da607e403ce1519977
SHA1: 68df56640a5d245192e91bd2ac89e504b477cc10
SHA256: d7b78fc0aaaa5e8ada388b29d718b0ab187e512965bed0b259bb4ab299f13db2
Evidence Type Source Name Value Confidence Vendor file name log4j-to-slf4j High Vendor jar package name apache Highest Vendor jar package name logging Highest Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release false Low Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-to-slf4j Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Log4j API to SLF4J Adapter High Vendor pom parent-artifactid log4j Low Vendor pom url https://logging.apache.org/log4j/2.x/ Highest Product file name log4j-to-slf4j High Product jar package name apache Highest Product jar package name logging Highest Product jar package name slf4j Highest Product jar package name slf4jprovider Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-activationpolicy lazy Low Product Manifest Bundle-Name Log4j API to SLF4J Adapter Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium Product Manifest Implementation-Title Log4j API to SLF4J Adapter High Product Manifest multi-release false Low Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low Product Manifest specification-title Log4j API to SLF4J Adapter Medium Product pom artifactid log4j-to-slf4j Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Log4j API to SLF4J Adapter High Product pom parent-artifactid log4j Medium Product pom url https://logging.apache.org/log4j/2.x/ Medium Version file version 2.25.4 High Version Manifest Bundle-Version 2.25.4 High Version Manifest Implementation-Version 2.25.4 High Version pom version 2.25.4 Highest
Related Dependencies ffl-core-database-3.1.2.jar: log4j-to-slf4j-2.25.4.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/log4j-to-slf4j-2.25.4.jar MD5: b3d45f5534aa71da607e403ce1519977 SHA1: 68df56640a5d245192e91bd2ac89e504b477cc10 SHA256: d7b78fc0aaaa5e8ada388b29d718b0ab187e512965bed0b259bb4ab299f13db2 pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.25.4 pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.25.4 (Confidence :High) ffl-core-commons-3.1.2-repackaged.jar: logback-core-1.5.34.jarDescription:
logback-core module License:
https://www.eclipse.org/legal/epl-v20.html, https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/logback-core-1.5.34.jar
MD5: ef459237a22ab546dd001ff612dce80d
SHA1: 378692f76c337b3325c15bffb89e013dc1f897b4
SHA256: 42eda264c0c650c2bec59e66151a88b708a8663dc1b49d788202d53e78b8caae
Evidence Type Source Name Value Confidence Vendor file name logback-core High Vendor jar package name ch Highest Vendor jar package name core Highest Vendor jar package name logback Highest Vendor jar package name qos Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest Implementation-Vendor QOS.ch High Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest specification-vendor QOS.ch Low Vendor pom artifactid logback-core Low Vendor pom groupid ch.qos.logback Highest Vendor pom name Logback Core Module High Vendor pom parent-artifactid logback-parent Low Product file name logback-core High Product jar package name 21 Highest Product jar package name ch Highest Product jar package name core Highest Product jar package name logback Highest Product jar package name qos Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Core Module Medium Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest Implementation-Title Logback Core Module High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest specification-title Logback Core Module Medium Product pom artifactid logback-core Highest Product pom groupid ch.qos.logback Highest Product pom name Logback Core Module High Product pom parent-artifactid logback-parent Medium Version file version 1.5.34 High Version Manifest Bundle-Version 1.5.34 High Version Manifest Implementation-Version 1.5.34 High Version pom version 1.5.34 Highest
Related Dependencies ffl-core-commons-3.1.2-repackaged.jar: logback-classic-1.5.34.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/logback-classic-1.5.34.jar MD5: eeec5f5930eaaaa84b192f59161d79c0 SHA1: e598899bad5824511cd3019299254230468e1fa2 SHA256: b65e05076a5c1aadb659b4fe4bc5fee31cb26cd70390292eb03e4a7a24cff10f pkg:maven/ch.qos.logback/logback-classic@1.5.34 ffl-core-database-3.1.2.jar: logback-core-1.5.34.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/logback-core-1.5.34.jar MD5: ef459237a22ab546dd001ff612dce80d SHA1: 378692f76c337b3325c15bffb89e013dc1f897b4 SHA256: 42eda264c0c650c2bec59e66151a88b708a8663dc1b49d788202d53e78b8caae pkg:maven/ch.qos.logback/logback-core@1.5.34 ffl-core-commons-3.1.2-repackaged.jar: mapstruct-1.5.5.Final.jarDescription:
An annotation processor for generating type-safe bean mappers License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/mapstruct-1.5.5.Final.jar
MD5: 9f2f737ffa2496ca5c40dcc323068803
SHA1: 2ca3cbe39b6e9ea8d5ea521965a89bef2a1e8eeb
SHA256: 6391e07982855dd804d825b63a55ab9251003716547216e5f581123c841328d5
Evidence Type Source Name Value Confidence Vendor file name mapstruct High Vendor jar package name mapstruct Highest Vendor Manifest automatic-module-name org.mapstruct Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.mapstruct Medium Vendor pom artifactid mapstruct Low Vendor pom groupid org.mapstruct Highest Vendor pom name MapStruct Core High Vendor pom parent-artifactid mapstruct-parent Low Product file name mapstruct High Product jar package name mappers Highest Product jar package name mapstruct Highest Product Manifest automatic-module-name org.mapstruct Medium Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name MapStruct Core Medium Product Manifest bundle-symbolicname org.mapstruct Medium Product pom artifactid mapstruct Highest Product pom groupid org.mapstruct Highest Product pom name MapStruct Core High Product pom parent-artifactid mapstruct-parent Medium Version Manifest Bundle-Version 1.5.5.Final High Version pom version 1.5.5.Final Highest
Related Dependencies ffl-core-database-3.1.2.jar: mapstruct-1.5.5.Final.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/mapstruct-1.5.5.Final.jar MD5: 9f2f737ffa2496ca5c40dcc323068803 SHA1: 2ca3cbe39b6e9ea8d5ea521965a89bef2a1e8eeb SHA256: 6391e07982855dd804d825b63a55ab9251003716547216e5f581123c841328d5 pkg:maven/org.mapstruct/mapstruct@1.5.5.Final pkg:maven/org.mapstruct/mapstruct@1.5.5.Final (Confidence :High) ffl-core-commons-3.1.2-repackaged.jar: micrometer-commons-1.15.12.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/micrometer-commons-1.15.12.jarMD5: 8172f342d797138ec7a1a20e0332568cSHA1: eb539638d48571fa6ce4ea3eb8417cab37a63438SHA256: 4b779cf7acb0534bb1f8e964f25200037ecb3944368f859a630fa637d6d5d7c0
Evidence Type Source Name Value Confidence Vendor file name micrometer-commons High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name micrometer Highest Vendor jar package name micrometer Low Vendor Manifest automatic-module-name micrometer.commons Medium Vendor Manifest branch HEAD Low Vendor Manifest build-date 2026-06-08_05:57:33 Low Vendor Manifest build-date-utc 2026-06-08T05:57:33.437169978Z Low Vendor Manifest build-host 320eea4f7654 Low Vendor Manifest build-job deploy Low Vendor Manifest build-number 70801 Low Vendor Manifest build-timezone Etc/UTC Low Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low Vendor Manifest built-os Linux Low Vendor Manifest built-status release Low Vendor Manifest bundle-symbolicname micrometer-commons Medium Vendor Manifest change dc2e5e2 Low Vendor Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /micrometer-commons Low Product file name micrometer-commons High Product jar package name common Low Product jar package name io Highest Product jar package name micrometer Highest Product jar package name micrometer Low Product Manifest automatic-module-name micrometer.commons Medium Product Manifest branch HEAD Low Product Manifest build-date 2026-06-08_05:57:33 Low Product Manifest build-date-utc 2026-06-08T05:57:33.437169978Z Low Product Manifest build-host 320eea4f7654 Low Product Manifest build-job deploy Low Product Manifest build-number 70801 Low Product Manifest build-timezone Etc/UTC Low Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low Product Manifest built-os Linux Low Product Manifest built-status release Low Product Manifest Bundle-Name micrometer-commons Medium Product Manifest bundle-symbolicname micrometer-commons Medium Product Manifest change dc2e5e2 Low Product Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.15.12 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /micrometer-commons Low Version file version 1.15.12 High Version Manifest Implementation-Version 1.15.12 High
Related Dependencies ffl-core-database-3.1.2.jar: micrometer-commons-1.15.12.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/micrometer-commons-1.15.12.jar MD5: 8172f342d797138ec7a1a20e0332568c SHA1: eb539638d48571fa6ce4ea3eb8417cab37a63438 SHA256: 4b779cf7acb0534bb1f8e964f25200037ecb3944368f859a630fa637d6d5d7c0 ffl-core-commons-3.1.2-repackaged.jar: micrometer-observation-1.15.12.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/micrometer-observation-1.15.12.jarMD5: b6ea6ebf93debb874d7c10f3ae79a471SHA1: 1d96fcaec8d2516236dfcb9914108e14bfd02238SHA256: 54483e68ed44af1bb0c36d1df2235d36f233e459d52f5a3be3e69813827a6300
Evidence Type Source Name Value Confidence Vendor file name micrometer-observation High Vendor jar package name io Low Vendor jar package name micrometer Highest Vendor jar package name micrometer Low Vendor jar package name observation Highest Vendor jar package name observation Low Vendor Manifest automatic-module-name micrometer.observation Medium Vendor Manifest branch HEAD Low Vendor Manifest build-date 2026-06-08_05:57:34 Low Vendor Manifest build-date-utc 2026-06-08T05:57:34.134088941Z Low Vendor Manifest build-host 320eea4f7654 Low Vendor Manifest build-job deploy Low Vendor Manifest build-number 70801 Low Vendor Manifest build-timezone Etc/UTC Low Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low Vendor Manifest built-os Linux Low Vendor Manifest built-status release Low Vendor Manifest bundle-symbolicname micrometer-observation Medium Vendor Manifest change dc2e5e2 Low Vendor Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /micrometer-observation Low Product file name micrometer-observation High Product jar package name io Highest Product jar package name micrometer Highest Product jar package name micrometer Low Product jar package name observation Highest Product jar package name observation Low Product Manifest automatic-module-name micrometer.observation Medium Product Manifest branch HEAD Low Product Manifest build-date 2026-06-08_05:57:34 Low Product Manifest build-date-utc 2026-06-08T05:57:34.134088941Z Low Product Manifest build-host 320eea4f7654 Low Product Manifest build-job deploy Low Product Manifest build-number 70801 Low Product Manifest build-timezone Etc/UTC Low Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/70801 Low Product Manifest built-os Linux Low Product Manifest built-status release Low Product Manifest Bundle-Name micrometer-observation Medium Product Manifest bundle-symbolicname micrometer-observation Medium Product Manifest change dc2e5e2 Low Product Manifest full-change dc2e5e2ea33a41a271b4b40e796ef39f1ed056af Low Product Manifest Implementation-Title io.micrometer#micrometer-observation;1.15.12 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /micrometer-observation Low Version file version 1.15.12 High Version Manifest Implementation-Version 1.15.12 High
Related Dependencies ffl-core-database-3.1.2.jar: micrometer-observation-1.15.12.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/micrometer-observation-1.15.12.jar MD5: b6ea6ebf93debb874d7c10f3ae79a471 SHA1: 1d96fcaec8d2516236dfcb9914108e14bfd02238 SHA256: 54483e68ed44af1bb0c36d1df2235d36f233e459d52f5a3be3e69813827a6300 ffl-core-commons-3.1.2-repackaged.jar: slf4j-api-2.0.18.jarDescription:
The slf4j API License:
https://opensource.org/license/mit File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/slf4j-api-2.0.18.jar
MD5: fe2837bd49bfb76657419002fed20ca9
SHA1: 78a9e7a37cd6360e0b818e86341b24123d28d4df
SHA256: 44508fd1576500688c790b190acdd16fec4f8c79a3e0b900afd70503cf055f55
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor Manifest multi-release true Low Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name SLF4J API Module Medium Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product Manifest multi-release true Low Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 2.0.18 High Version Manifest Bundle-Version 2.0.18 High Version Manifest Implementation-Version 2.0.18 High Version pom version 2.0.18 Highest
Related Dependencies ffl-core-database-3.1.2.jar: slf4j-api-2.0.18.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/slf4j-api-2.0.18.jar MD5: fe2837bd49bfb76657419002fed20ca9 SHA1: 78a9e7a37cd6360e0b818e86341b24123d28d4df SHA256: 44508fd1576500688c790b190acdd16fec4f8c79a3e0b900afd70503cf055f55 pkg:maven/org.slf4j/slf4j-api@2.0.18 pkg:maven/org.slf4j/slf4j-api@2.0.18 (Confidence :High) ffl-core-commons-3.1.2-repackaged.jar: snakeyaml-2.3.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/snakeyaml-2.3.jar
MD5: 2a1c2ee8923dcd6bd6d025751af5df37
SHA1: 936b36210e27320f920536f695cf1af210c44586
SHA256: 63a76fe66b652360bd4c2c107e6f0258daa7d4bb492008ba8c26fcd230ff9146
Evidence Type Source Name Value Confidence Vendor file name snakeyaml High Vendor jar package name emitter Highest Vendor jar package name org Highest Vendor jar package name parser Highest Vendor jar package name snakeyaml Highest Vendor jar package name yaml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest multi-release true Low Vendor pom artifactid snakeyaml Low Vendor pom developer email alexander.maslov@gmail.com Low Vendor pom developer email public.somov@gmail.com Low Vendor pom developer id asomov Medium Vendor pom developer id maslovalex Medium Vendor pom developer name Alexander Maslov Medium Vendor pom developer name Andrey Somov Medium Vendor pom groupid org.yaml Highest Vendor pom name SnakeYAML High Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest Product file name snakeyaml High Product jar package name emitter Highest Product jar package name org Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name yaml Highest Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest multi-release true Low Product pom artifactid snakeyaml Highest Product pom developer email alexander.maslov@gmail.com Low Product pom developer email public.somov@gmail.com Low Product pom developer id asomov Low Product pom developer id maslovalex Low Product pom developer name Alexander Maslov Low Product pom developer name Andrey Somov Low Product pom groupid org.yaml Highest Product pom name SnakeYAML High Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium Version file version 2.3 High Version pom version 2.3 Highest
Related Dependencies ffl-core-database-3.1.2.jar: snakeyaml-2.3.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/snakeyaml-2.3.jar MD5: 2a1c2ee8923dcd6bd6d025751af5df37 SHA1: 936b36210e27320f920536f695cf1af210c44586 SHA256: 63a76fe66b652360bd4c2c107e6f0258daa7d4bb492008ba8c26fcd230ff9146 pkg:maven/org.yaml/snakeyaml@2.3 ffl-core-commons-3.1.2-repackaged.jar: spring-aop-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-aop-6.2.19.jarMD5: 36ab0f0a76202a0f8cd077fd323372a5SHA1: 86a538bb7b2be38a0afc4ef049784def10a86c62SHA256: a11b93539d80b02caf76171db2da96df39abebbfef49a2fadd6dda0779f2e20b
Evidence Type Source Name Value Confidence Vendor file name spring-aop High Vendor hint analyzer vendor pivotal software Highest Vendor jar package name aop Highest Vendor jar package name aop Low Vendor jar package name springframework Low Vendor Manifest automatic-module-name spring.aop Medium Product file name spring-aop High Product jar package name aop Highest Product jar package name aop Low Product Manifest automatic-module-name spring.aop Medium Product Manifest Implementation-Title spring-aop High Version file version 6.2.19 High Version Manifest Implementation-Version 6.2.19 High
Related Dependencies ffl-core-commons-3.1.2-repackaged.jar: spring-beans-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-beans-6.2.19.jar MD5: ae0cf6f1e373577d322e17c350d0fb15 SHA1: 6d6b4774db3b036df46be6332d93b09d70e5c147 SHA256: 846dc8f30a639a36eb551ee99a30469be4d11bd285ca9daf164d98321571b404 ffl-core-commons-3.1.2-repackaged.jar: spring-context-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-context-6.2.19.jar MD5: 77c848b32f387021e0b690be9cd24de8 SHA1: e218e4c4ecad1e821905628b2c4ce8561d937baa SHA256: ead4b645f94a7f665f00093eaafde634e97b34524294de653b51e43e0b3fc4a4 ffl-core-commons-3.1.2-repackaged.jar: spring-expression-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-expression-6.2.19.jar MD5: 233e2f7ced4637cad68a9449844e9a6b SHA1: c7202d23797fa778c5ed55e502ac1a9f0d34012a SHA256: d710a44417d890353895b341a722d7d08199e2b7da52f0a11c0e92571e1d6e19 ffl-core-commons-3.1.2-repackaged.jar: spring-jcl-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-jcl-6.2.19.jar MD5: cd5278839172f3b30b1e90bc70d9b864 SHA1: 39b9c7d631961f3649511b08ef167420b086184b SHA256: 9994478bcea1423b8892d4eb0db942c94da0090167c3c684050c1eaef04491d0 ffl-core-database-3.1.2.jar: spring-aop-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-aop-6.2.19.jar MD5: 36ab0f0a76202a0f8cd077fd323372a5 SHA1: 86a538bb7b2be38a0afc4ef049784def10a86c62 SHA256: a11b93539d80b02caf76171db2da96df39abebbfef49a2fadd6dda0779f2e20b ffl-core-commons-3.1.2-repackaged.jar: spring-boot-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-boot-3.5.15.jarMD5: cd0efbe329f64325061488023e25de14SHA1: c06a102c231e4a0a53085d93c3a121f3a05d6825SHA256: 1d3ea175f61f492d95cbca457d6cc9cf1b696b550422c1b424d50dfa58f7da15
Evidence Type Source Name Value Confidence Vendor file name spring-boot High Vendor jar package name boot Highest Vendor jar package name boot Low Vendor jar package name springframework Low Vendor Manifest automatic-module-name spring.boot Medium Vendor Manifest build-jdk-spec 17 Low Product file name spring-boot High Product jar package name boot Highest Product jar package name boot Low Product Manifest automatic-module-name spring.boot Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot High Version file version 3.5.15 High Version Manifest Implementation-Version 3.5.15 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-boot-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-boot-3.5.15.jar MD5: cd0efbe329f64325061488023e25de14 SHA1: c06a102c231e4a0a53085d93c3a121f3a05d6825 SHA256: 1d3ea175f61f492d95cbca457d6cc9cf1b696b550422c1b424d50dfa58f7da15 ffl-core-commons-3.1.2-repackaged.jar: spring-boot-autoconfigure-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-boot-autoconfigure-3.5.15.jarMD5: 90d33d85f52755cace278df3bdd9f89fSHA1: 2ae6e14e304afe1e56bca3eb607e89b6dbf76f77SHA256: 180af16bbaa61ae70b3d8c533fe36264b1305d4a6916965ed86d0f4e47b73b3b
Evidence Type Source Name Value Confidence Vendor file name spring-boot-autoconfigure High Vendor jar package name autoconfigure Highest Vendor jar package name autoconfigure Low Vendor jar package name boot Highest Vendor jar package name boot Low Vendor jar package name springframework Low Vendor Manifest automatic-module-name spring.boot.autoconfigure Medium Vendor Manifest build-jdk-spec 17 Low Product file name spring-boot-autoconfigure High Product jar package name autoconfigure Highest Product jar package name autoconfigure Low Product jar package name boot Highest Product jar package name boot Low Product Manifest automatic-module-name spring.boot.autoconfigure Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot AutoConfigure High Version file version 3.5.15 High Version Manifest Implementation-Version 3.5.15 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-boot-autoconfigure-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-boot-autoconfigure-3.5.15.jar MD5: 90d33d85f52755cace278df3bdd9f89f SHA1: 2ae6e14e304afe1e56bca3eb607e89b6dbf76f77 SHA256: 180af16bbaa61ae70b3d8c533fe36264b1305d4a6916965ed86d0f4e47b73b3b ffl-core-commons-3.1.2-repackaged.jar: spring-boot-jarmode-tools-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-boot-jarmode-tools-3.5.15.jarMD5: a2c10f599de1331f1421794afeaf0be8SHA1: a7ab70a942a3ea366cef12d2610dcb65cd92b771SHA256: 0ef100c6915f599606de3d46ae898e7d46594a47db311071a488ee50b2f58a55
Evidence Type Source Name Value Confidence Vendor file name spring-boot-jarmode-tools High Vendor jar package name boot Highest Vendor jar package name boot Low Vendor jar package name jarmode Highest Vendor jar package name jarmode Low Vendor jar package name springframework Low Vendor jar package name tools Highest Vendor Manifest automatic-module-name spring.boot.jarmode.tools Medium Vendor Manifest build-jdk-spec 17 Low Product file name spring-boot-jarmode-tools High Product jar package name boot Highest Product jar package name boot Low Product jar package name jarmode Highest Product jar package name jarmode Low Product jar package name tools Highest Product jar package name tools Low Product Manifest automatic-module-name spring.boot.jarmode.tools Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot Jarmode Tools High Version file version 3.5.15 High Version Manifest Implementation-Version 3.5.15 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-boot-jarmode-tools-3.5.15.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-boot-jarmode-tools-3.5.15.jar MD5: a2c10f599de1331f1421794afeaf0be8 SHA1: a7ab70a942a3ea366cef12d2610dcb65cd92b771 SHA256: 0ef100c6915f599606de3d46ae898e7d46594a47db311071a488ee50b2f58a55 ffl-core-commons-3.1.2-repackaged.jar: spring-core-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-core-6.2.19.jarMD5: 4afe3968028c2b743dbff2d79013e144SHA1: 691459d4644894dae8e5c2d9550a4cfb8302f62fSHA256: 52146689e71a911c92bac26677d73c692512a739893a57710cc233591756bff6
Evidence Type Source Name Value Confidence Vendor file name spring-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name springframework Low Vendor Manifest automatic-module-name spring.core Medium Vendor Manifest multi-release true Low Product file name spring-core High Product hint analyzer product springsource_spring_framework Highest Product jar package name core Highest Product Manifest automatic-module-name spring.core Medium Product Manifest Implementation-Title spring-core High Product Manifest multi-release true Low Version file version 6.2.19 High Version Manifest Implementation-Version 6.2.19 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-core-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-core-6.2.19.jar MD5: 4afe3968028c2b743dbff2d79013e144 SHA1: 691459d4644894dae8e5c2d9550a4cfb8302f62f SHA256: 52146689e71a911c92bac26677d73c692512a739893a57710cc233591756bff6 ffl-core-commons-3.1.2-repackaged.jar: spring-security-web-6.5.11.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-security-web-6.5.11.jarMD5: 9e6b94f61b08fe8d113a7835bb994576SHA1: eeee13020ef81f290633e68fe062bccba062774eSHA256: 50df9fc76162d33cf8b5410cf7a7a969abd42a5ecddb284aab4f453cb5512306
Evidence Type Source Name Value Confidence Vendor file name spring-security-web High Vendor hint analyzer vendor pivotal software Highest Vendor jar package name security Highest Vendor jar package name security Low Vendor jar package name springframework Low Vendor jar package name web Highest Vendor jar package name web Low Vendor Manifest automatic-module-name spring.security.web Medium Product file name spring-security-web High Product jar package name security Highest Product jar package name security Low Product jar package name web Highest Product jar package name web Low Product Manifest automatic-module-name spring.security.web Medium Product Manifest Implementation-Title spring-security-web High Version file version 6.5.11 High Version Manifest Implementation-Version 6.5.11 High
Related Dependencies ffl-core-commons-3.1.2-repackaged.jar: spring-security-config-6.5.11.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-security-config-6.5.11.jar MD5: 56a1f736ee4e6e8557ea360d0ae995c3 SHA1: c698bc32f1f10f85b3ade54575077eaebc9b86c3 SHA256: 218685930013a2d1c126a896490ac3c44cf6fe90cf3d0286f2266bb877f916f7 ffl-core-commons-3.1.2-repackaged.jar: spring-security-core-6.5.11.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-security-core-6.5.11.jar MD5: 697081575fdb870e6c77e4f489acb192 SHA1: d57309ff65d122a2fa45a3a8f47b01e9183cb6e6 SHA256: 26ac26527cc015c5c71f3832add705a2410129a8f8de847054f2bc3b1d2e4465 ffl-core-commons-3.1.2-repackaged.jar: spring-security-crypto-6.5.11.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-security-crypto-6.5.11.jar MD5: d9fb7f74b14c2c049d46d0454f138247 SHA1: 2cbc07fa7650ef2f49bcc5ac35e7666c79614f55 SHA256: dcdd2f3b2d5d2bb1531986b5cc1737b464a76d8b5831f93fc8da9cdd67e6797f ffl-core-database-3.1.2.jar: spring-security-web-6.5.11.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-security-web-6.5.11.jar MD5: 9e6b94f61b08fe8d113a7835bb994576 SHA1: eeee13020ef81f290633e68fe062bccba062774e SHA256: 50df9fc76162d33cf8b5410cf7a7a969abd42a5ecddb284aab4f453cb5512306 CVE-2018-1258 suppress
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - PATCH,THIRD_PARTY_ADVISORY security_alert@emc.com - THIRD_PARTY_ADVISORY security_alert@emc.com - THIRD_PARTY_ADVISORY,VDB_ENTRY security_alert@emc.com - THIRD_PARTY_ADVISORY,VDB_ENTRY security_alert@emc.com - THIRD_PARTY_ADVISORY,VDB_ENTRY security_alert@emc.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
ffl-core-commons-3.1.2-repackaged.jar: spring-security-web-6.5.11.jar: spring-security-webauthn.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-security-web-6.5.11.jar/org/springframework/security/spring-security-webauthn.jsMD5: d8d90d854a23d021c2e758b3eebce213SHA1: 7814ccd3adc2388f52b2658bf5fc30b457949ab6SHA256: 044a2b8d7e995bff815565678631a2d3a5cc0aa96ef8ac35cfacb579307f77a9
Evidence Type Source Name Value Confidence
Related Dependencies ffl-core-database-3.1.2.jar: spring-security-web-6.5.11.jar: spring-security-webauthn.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-security-web-6.5.11.jar/org/springframework/security/spring-security-webauthn.js MD5: d8d90d854a23d021c2e758b3eebce213 SHA1: 7814ccd3adc2388f52b2658bf5fc30b457949ab6 SHA256: 044a2b8d7e995bff815565678631a2d3a5cc0aa96ef8ac35cfacb579307f77a9 ffl-core-commons-3.1.2-repackaged.jar: spring-web-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2-repackaged.jar/BOOT-INF/lib/spring-web-6.2.19.jarMD5: 1d5ca2b445acea292d5787536c069a36SHA1: f1dc7b238611aeaf9e256a230aa089057cf0e5b3SHA256: ca88e364ecebee61163e2260e8a20584138eca74e28a050d6a2ef6302bad2f2d
Evidence Type Source Name Value Confidence Vendor file name spring-web High Vendor hint analyzer vendor pivotal software Highest Vendor jar package name springframework Low Vendor jar package name web Highest Vendor jar package name web Low Vendor Manifest automatic-module-name spring.web Medium Product file name spring-web High Product jar package name web Highest Product jar package name web Low Product Manifest automatic-module-name spring.web Medium Product Manifest Implementation-Title spring-web High Version file version 6.2.19 High Version Manifest Implementation-Version 6.2.19 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-web-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-web-6.2.19.jar MD5: 1d5ca2b445acea292d5787536c069a36 SHA1: f1dc7b238611aeaf9e256a230aa089057cf0e5b3 SHA256: ca88e364ecebee61163e2260e8a20584138eca74e28a050d6a2ef6302bad2f2d ffl-core-commons-3.1.2.jarDescription:
Module contenant le core du back-office File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/ffl-core-commons-3.1.2.jarMD5: acba71f2def9032f781209b8b46c522eSHA1: e303db85305a6185d46e8b0b9534094bd54f1cf6SHA256: 804540b2eef9b4f39704cd0f47d4716bea77c1f25a106590442f73f595442d8b
Evidence Type Source Name Value Confidence Vendor file name ffl-core-commons High Vendor jar package name commons Highest Vendor jar package name core Highest Vendor jar package name ffl Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-core-commons Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-commons High Product jar package name commons Highest Product jar package name core Highest Product jar package name ffl Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-commons High Product pom artifactid ffl-core-commons Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
Related Dependencies ffl-core-database-3.1.2.jar: ffl-core-commons-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/ffl-core-commons-3.1.2.jar MD5: acba71f2def9032f781209b8b46c522e SHA1: e303db85305a6185d46e8b0b9534094bd54f1cf6 SHA256: 804540b2eef9b4f39704cd0f47d4716bea77c1f25a106590442f73f595442d8b pkg:maven/com.sintia.ffl.core/ffl-core-commons@3.1.2 pkg:maven/com.sintia.ffl.core/ffl-core-commons@3.1.2 (Confidence :High) ffl-core-dal-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-dal/target/ffl-core-dal-3.1.2.jarMD5: ff777361988cc87e0e23b84d4de9a801SHA1: 6c4a698fcf633c4d7827e0769d3668ff22f0b46cSHA256: 9cb460771d9d13b3574e85c7ba6650d800b021f116aba004353f606841768843
Evidence Type Source Name Value Confidence Vendor file name ffl-core-dal High Vendor jar package name core Highest Vendor jar package name dal Highest Vendor jar package name ffl Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-core-dal Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-dal-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-dal High Product jar package name core Highest Product jar package name dal Highest Product jar package name ffl Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-dal High Product pom artifactid ffl-core-dal Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-dal-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-dal@3.1.2 (Confidence :High) ffl-core-database-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jarMD5: 41b13ecbfa11b3bd2e61f48b016d27fcSHA1: 303e063e10ddfadbaf8e9b897d7e98fa307c7b7dSHA256: bb3ab9fe98aef17e4c40d89029e703d9509cc5f7ab61fc0cb74b7f575212599d
Evidence Type Source Name Value Confidence Vendor file name ffl-core-database High Vendor jar package name com Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest spring-boot-classes BOOT-INF/classes/ Low Vendor Manifest spring-boot-classpath-index BOOT-INF/classpath.idx Low Vendor Manifest spring-boot-layers-index BOOT-INF/layers.idx Low Vendor Manifest spring-boot-lib BOOT-INF/lib/ Low Vendor pom artifactid ffl-core-database Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-database-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-database High Product jar package name boot Highest Product jar package name boot-inf Highest Product jar package name classes Highest Product jar package name com Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-database High Product Manifest spring-boot-classes BOOT-INF/classes/ Low Product Manifest spring-boot-classpath-index BOOT-INF/classpath.idx Low Product Manifest spring-boot-layers-index BOOT-INF/layers.idx Low Product Manifest spring-boot-lib BOOT-INF/lib/ Low Product pom artifactid ffl-core-database Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-database-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-database@3.1.2 (Confidence :High) ffl-core-database-3.1.2.jar: HikariCP-6.3.3.jarDescription:
Ultimate JDBC Connection Pool License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/HikariCP-6.3.3.jar
MD5: a5c7bb14f24a598a87118c9f73641466
SHA1: 7c5aec1e47a97ff40977e0193018865304ea9585
SHA256: 709f378c05756280939ce50fc1b1f1a53bb8e1899dc1b249f21f12703640b48b
Evidence Type Source Name Value Confidence Vendor file name HikariCP High Vendor jar package name hikari Highest Vendor jar package name pool Highest Vendor jar package name zaxxer Highest Vendor Manifest automatic-module-name com.zaxxer.hikari Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/brettwooldridge Low Vendor Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Vendor pom artifactid HikariCP Low Vendor pom developer email brett.wooldridge@gmail.com Low Vendor pom developer name Brett Wooldridge Medium Vendor pom groupid com.zaxxer Highest Vendor pom name HikariCP High Vendor pom organization name Zaxxer.com High Vendor pom organization url brettwooldridge Medium Vendor pom url brettwooldridge/HikariCP Highest Product file name HikariCP High Product jar package name hikari Highest Product jar package name pool Highest Product jar package name zaxxer Highest Product Manifest automatic-module-name com.zaxxer.hikari Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/brettwooldridge Low Product Manifest Bundle-Name HikariCP Medium Product Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Product pom artifactid HikariCP Highest Product pom developer email brett.wooldridge@gmail.com Low Product pom developer name Brett Wooldridge Low Product pom groupid com.zaxxer Highest Product pom name HikariCP High Product pom organization name Zaxxer.com Low Product pom url brettwooldridge High Product pom url brettwooldridge/HikariCP High Version file version 6.3.3 High Version Manifest Bundle-Version 6.3.3 High Version pom version 6.3.3 Highest
pkg:maven/com.zaxxer/HikariCP@6.3.3 (Confidence :High) ffl-core-database-3.1.2.jar: angus-activation-2.0.3.jarDescription:
Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/angus-activation-2.0.3.jar
MD5: ad20392145690b36b4f950fe31a31a2a
SHA1: 7f80607ea5014fef0b1779e6c33d63a88a45a563
SHA256: a6bd35c538cf90fff941ad6258c40c08fca0b5c9c3f536c657114f27ce0527a7
Evidence Type Source Name Value Confidence Vendor file name angus-activation High Vendor jar package name activation Highest Vendor jar package name angus Highest Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname angus-activation Medium Vendor Manifest extension-name org.eclipse.angus Medium Vendor Manifest implementation-build-id 2.0.3-RELEASE-6eff4c5 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid angus-activation Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Activation Registries High Vendor pom parent-artifactid angus-activation-project Low Product file name angus-activation High Product jar package name activation Highest Product jar package name angus Highest Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Angus Activation Registries Medium Product Manifest bundle-symbolicname angus-activation Medium Product Manifest extension-name org.eclipse.angus Medium Product Manifest implementation-build-id 2.0.3-RELEASE-6eff4c5 Low Product Manifest Implementation-Title Angus Activation Registries High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid angus-activation Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Activation Registries High Product pom parent-artifactid angus-activation-project Medium Version file version 2.0.3 High Version Manifest Bundle-Version 2.0.3 High Version pom version 2.0.3 Highest
pkg:maven/org.eclipse.angus/angus-activation@2.0.3 (Confidence :High) ffl-core-database-3.1.2.jar: antlr4-runtime-4.13.0.jarDescription:
The ANTLR 4 Runtime License:
https://www.antlr.org/license.html File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/antlr4-runtime-4.13.0.jar
MD5: bff95723c494b332b14575d713a65df4
SHA1: 5a02e48521624faaf5ff4d99afc88b01686af655
SHA256: bd7f7b5d07bc0b047f10915b32ca4bb1de9e57d8049098882e4453c88c076a5d
Evidence Type Source Name Value Confidence Vendor file name antlr4-runtime High Vendor jar package name antlr Highest Vendor jar package name runtime Highest Vendor Manifest automatic-module-name org.antlr.antlr4.runtime Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.antlr.org/ Low Vendor Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Vendor Manifest Implementation-Vendor ANTLR High Vendor pom artifactid antlr4-runtime Low Vendor pom groupid org.antlr Highest Vendor pom name ANTLR 4 Runtime High Vendor pom parent-artifactid antlr4-master Low Product file name antlr4-runtime High Product jar package name antlr Highest Product jar package name runtime Highest Product Manifest automatic-module-name org.antlr.antlr4.runtime Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.antlr.org/ Low Product Manifest Bundle-Name ANTLR 4 Runtime Medium Product Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Product Manifest Implementation-Title ANTLR 4 Runtime High Product pom artifactid antlr4-runtime Highest Product pom groupid org.antlr Highest Product pom name ANTLR 4 Runtime High Product pom parent-artifactid antlr4-master Medium Version file version 4.13.0 High Version Manifest Bundle-Version 4.13.0 High Version Manifest Implementation-Version 4.13.0 High Version pom version 4.13.0 Highest
pkg:maven/org.antlr/antlr4-runtime@4.13.0 (Confidence :High) ffl-core-database-3.1.2.jar: byte-buddy-1.17.8.jarDescription:
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/byte-buddy-1.17.8.jar
MD5: ac7292226046cb7206b349e21affecfe
SHA1: af5735f63d00ca47a9375fae5c7471a36331c6ed
SHA256: 2b5ddc8c1f4234bdb7cb45338a8e10a13e0e3ca473e91d5d821d681127ea8ba1
Evidence Type Source Name Value Confidence Vendor file name byte-buddy High Vendor jar package name asm Highest Vendor jar package name build Highest Vendor jar package name bytebuddy Highest Vendor jar package name net Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Vendor Manifest multi-release true Low Vendor pom artifactid byte-buddy Low Vendor pom groupid net.bytebuddy Highest Vendor pom name Byte Buddy (without dependencies) High Vendor pom parent-artifactid byte-buddy-parent Low Product file name byte-buddy High Product jar package name asm Highest Product jar package name build Highest Product jar package name bytebuddy Highest Product jar package name net Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Byte Buddy (without dependencies) Medium Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Product Manifest multi-release true Low Product pom artifactid byte-buddy Highest Product pom groupid net.bytebuddy Highest Product pom name Byte Buddy (without dependencies) High Product pom parent-artifactid byte-buddy-parent Medium Version file version 1.17.8 High Version Manifest Bundle-Version 1.17.8 High Version pom version 1.17.8 Highest
pkg:maven/net.bytebuddy/byte-buddy@1.17.8 (Confidence :High) ffl-core-database-3.1.2.jar: classmate-1.7.3.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/classmate-1.7.3.jar
MD5: d1a4a85ab782827adfa82772e3b5f483
SHA1: f61c7e7b81e9249b0f6a05914eff9d54fb09f4a0
SHA256: 75fbda45456f123fb6e2028a6189442d8d0730b357adce4c0a6d7e789f70669b
Evidence Type Source Name Value Confidence Vendor file name classmate High Vendor jar package name classmate Highest Vendor jar package name fasterxml Highest Vendor jar package name types Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid classmate Low Vendor pom developer email blangel@ocheyedan.net Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id blangel Medium Vendor pom developer id tatu Medium Vendor pom developer name Brian Langel Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml Highest Vendor pom name ClassMate High Vendor pom organization name fasterxml.com High Vendor pom organization url https://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom url FasterXML/java-classmate Highest Product file name classmate High Product jar package name classmate Highest Product jar package name fasterxml Highest Product jar package name types Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest Implementation-Title ClassMate High Product Manifest specification-title ClassMate Medium Product pom artifactid classmate Highest Product pom developer email blangel@ocheyedan.net Low Product pom developer email tatu@fasterxml.com Low Product pom developer id blangel Low Product pom developer id tatu Low Product pom developer name Brian Langel Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml Highest Product pom name ClassMate High Product pom organization name fasterxml.com Low Product pom organization url https://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom url FasterXML/java-classmate High Version file version 1.7.3 High Version Manifest Bundle-Version 1.7.3 High Version Manifest Implementation-Version 1.7.3 High Version pom parent-version 1.7.3 Low Version pom version 1.7.3 Highest
pkg:maven/com.fasterxml/classmate@1.7.3 (Confidence :High) ffl-core-database-3.1.2.jar: flyway-core-11.7.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/flyway-core-11.7.2.jarMD5: 4c980ae9d24be75b9522f8f4ed0b60bcSHA1: 2e40f0465ab29c807a38aae56b4e636451a9ff99SHA256: ff01fab3bcfd79e9345df191ecf82cbe1f9f65a757266158bd691564b1c1282c
Evidence Type Source Name Value Confidence Vendor file name flyway-core High Vendor jar package name core Highest Vendor jar package name flyway Highest Vendor jar package name flywaydb Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid flyway-core Low Vendor pom groupid org.flywaydb Highest Vendor pom parent-artifactid flyway-parent Low Product file name flyway-core High Product jar package name core Highest Product jar package name flyway Highest Product jar package name flywaydb Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid flyway-core Highest Product pom groupid org.flywaydb Highest Product pom parent-artifactid flyway-parent Medium Version file version 11.7.2 High Version pom version 11.7.2 Highest
pkg:maven/org.flywaydb/flyway-core@11.7.2 (Confidence :High) ffl-core-database-3.1.2.jar: flyway-database-postgresql-11.7.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/flyway-database-postgresql-11.7.2.jarMD5: 7f4b3e8a8ef177fa1d9e6815cdddfbacSHA1: 6cca0e7f6fdded39ddc302c97d9e12ecc8c9b96aSHA256: 1d586e14ea772c75613df2c27ddc20f5c065e8a32283815338611af82e48f9a2
Evidence Type Source Name Value Confidence Vendor file name flyway-database-postgresql High Vendor jar package name database Highest Vendor jar package name flywaydb Highest Vendor jar package name postgresql Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid flyway-database-postgresql Low Vendor pom groupid org.flywaydb Highest Vendor pom parent-artifactid flyway-parent Low Product file name flyway-database-postgresql High Product jar package name database Highest Product jar package name flywaydb Highest Product jar package name postgresql Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid flyway-database-postgresql Highest Product pom groupid org.flywaydb Highest Product pom parent-artifactid flyway-parent Medium Version file version 11.7.2 High Version pom version 11.7.2 Highest
pkg:maven/org.flywaydb/flyway-database-postgresql@11.7.2 (Confidence :High) ffl-core-database-3.1.2.jar: hibernate-commons-annotations-7.0.3.Final.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/hibernate-commons-annotations-7.0.3.Final.jarMD5: 6698f99235fe6d36c42caaf2e6b52797SHA1: e183c4be8bb41d12e9f19b374e00c34a0a85f439SHA256: 0db2fd57d5e43688ac6ed5cdf36deaf05d84340dcc24c2dd2a2114de38e5175d
Evidence Type Source Name Value Confidence Vendor file name hibernate-commons-annotations High Vendor jar package name annotations Low Vendor jar package name common Low Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Product file name hibernate-commons-annotations High Product jar package name annotations Low Product jar package name common Low Product jar package name hibernate Highest Product jar package name reflection Low Product Manifest implementation-url http://hibernate.org Low Version file version 7.0.3 High Version Manifest Implementation-Version 7.0.3.Final High
ffl-core-database-3.1.2.jar: hibernate-core-6.6.9.Final.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/hibernate-core-6.6.9.Final.jarMD5: 670b53c7af3752a2da8222bf10440121SHA1: ebc13d6e7e5d7cf756bd4e1bc0caddc178d10422SHA256: bfcd55203f0c8d2e42f58d8a21d1a94aeb592ccd05ea6f94f9b0feeb1b0d64ab
Evidence Type Source Name Value Confidence Vendor file name hibernate-core High Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor Manifest automatic-module-name org.hibernate.orm.core Medium Vendor Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.core Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest specification-vendor Hibernate.org Low Product file name hibernate-core High Product jar package name hibernate Highest Product Manifest automatic-module-name org.hibernate.orm.core Medium Product Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Product Manifest Bundle-Name hibernate-core Medium Product Manifest bundle-symbolicname org.hibernate.orm.core Medium Product Manifest Implementation-Title hibernate-core High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest specification-title hibernate-core Medium Version file version 6.6.9 High Version Manifest Implementation-Version 6.6.9.Final High
ffl-core-database-3.1.2.jar: istack-commons-runtime-4.1.2.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/istack-commons-runtime-4.1.2.jar
MD5: 535154ef647af2a52478c4debec93659
SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739
SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee
Evidence Type Source Name Value Confidence Vendor file name istack-commons-runtime High Vendor jar package name istack Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor Manifest implementation-build-id 4.1.2 - 343a28e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor pom artifactid istack-commons-runtime Low Vendor pom groupid com.sun.istack Highest Vendor pom name istack common utility code runtime High Vendor pom parent-artifactid istack-commons Low Product file name istack-commons-runtime High Product jar package name istack Highest Product jar package name sun Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest implementation-build-id 4.1.2 - 343a28e Low Product pom artifactid istack-commons-runtime Highest Product pom groupid com.sun.istack Highest Product pom name istack common utility code runtime High Product pom parent-artifactid istack-commons Medium Version file version 4.1.2 High Version Manifest Bundle-Version 4.1.2 High Version Manifest implementation-build-id 4.1.2 Low Version pom version 4.1.2 Highest
pkg:maven/com.sun.istack/istack-commons-runtime@4.1.2 (Confidence :High) ffl-core-database-3.1.2.jar: jackson-annotations-2.21.jarDescription:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jackson-annotations-2.21.jar
MD5: e0d0c3e7300954f73e43c67d933aaea4
SHA1: b1bc1868bf02dc0bd6c7836257a036a331005309
SHA256: 53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b
Evidence Type Source Name Value Confidence Vendor file name jackson-annotations High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-annotations Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-annotations High Vendor pom parent-artifactid jackson-parent Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-annotations High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name Jackson-annotations Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Product Manifest Implementation-Title Jackson-annotations High Product Manifest specification-title Jackson-annotations Medium Product pom artifactid jackson-annotations Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-annotations High Product pom parent-artifactid jackson-parent Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.21 High Version Manifest Implementation-Version 2.21 High Version pom version 2.21 Highest
ffl-core-database-3.1.2.jar: jackson-core-2.21.4.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jackson-core-2.21.4.jar
MD5: 2f3d2557bb48afa00fe924c9689ab3b6
SHA1: 56a503ba45016714394807ea89f95f5093760089
SHA256: 4b40a06396f239f8de2da57419adde6e94e5edc18a2171d471ea05eeed4e5c2d
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name com Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name com Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name json Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.21.4 High Version Manifest Bundle-Version 2.21.4 High Version Manifest Implementation-Version 2.21.4 High Version pom version 2.21.4 Highest
ffl-core-database-3.1.2.jar: jackson-databind-2.21.4.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jackson-databind-2.21.4.jar
MD5: 99769ad660a66c43caee5d539d19ed96
SHA1: 09e495680be707d466527d734368ebf36e464da2
SHA256: 3888e9e69ab66fbacaacc9aea0e9ffbf15368288e4aca468b024dba11c09fbf9
Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.21.4 High Version Manifest Bundle-Version 2.21.4 High Version Manifest Implementation-Version 2.21.4 High Version pom version 2.21.4 Highest
CVE-2026-54515 suppress
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4. CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
ffl-core-database-3.1.2.jar: jackson-dataformat-toml-2.21.4.jarDescription:
Support for reading and writing TOML-encoded data via Jackson abstractions.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jackson-dataformat-toml-2.21.4.jar
MD5: 691ba4fd665a8ba54c046c55b9aebecf
SHA1: 08a16502ac35d743e3ca0d2351174766e8be5b24
SHA256: c22e9f650a45d5697116e9beb85cb218792f03d19cf79134e692fe1a65f50cc6
Evidence Type Source Name Value Confidence Vendor file name jackson-dataformat-toml High Vendor jar package name dataformat Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name toml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-toml Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-dataformat-toml Low Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor pom name Jackson-dataformat-TOML High Vendor pom parent-artifactid jackson-dataformats-text Low Vendor pom url FasterXML/jackson-dataformats-text Highest Product file name jackson-dataformat-toml High Product jar package name dataformat Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name toml Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Product Manifest Bundle-Name Jackson-dataformat-TOML Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-toml Medium Product Manifest Implementation-Title Jackson-dataformat-TOML High Product Manifest multi-release true Low Product Manifest specification-title Jackson-dataformat-TOML Medium Product pom artifactid jackson-dataformat-toml Highest Product pom groupid com.fasterxml.jackson.dataformat Highest Product pom name Jackson-dataformat-TOML High Product pom parent-artifactid jackson-dataformats-text Medium Product pom url FasterXML/jackson-dataformats-text High Version file version 2.21.4 High Version Manifest Bundle-Version 2.21.4 High Version Manifest Implementation-Version 2.21.4 High Version pom version 2.21.4 Highest
ffl-core-database-3.1.2.jar: jackson-datatype-jsr310-2.21.4.jarDescription:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jackson-datatype-jsr310-2.21.4.jar
MD5: 8d64e799458e78f5d46765da252270fa
SHA1: 51f9ede30826b05cdf8a70b47bc68bd6271dfaaa
SHA256: d1ac4b98b70304e56448423589fde5e775b100889643ad1ead62cc7811633684
Evidence Type Source Name Value Confidence Vendor file name jackson-datatype-jsr310 High Vendor jar package name datatype Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name jsr310 Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-datatype-jsr310 Low Vendor pom developer email nicholas@nicholaswilliams.net Low Vendor pom developer id beamerblvd Medium Vendor pom developer name Nick Williams Medium Vendor pom groupid com.fasterxml.jackson.datatype Highest Vendor pom name Jackson datatype: JSR310 High Vendor pom parent-artifactid jackson-modules-java8 Low Vendor pom parent-groupid com.fasterxml.jackson.module Medium Product file name jackson-datatype-jsr310 High Product jar package name datatype Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jsr310 Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Product Manifest Bundle-Name Jackson datatype: JSR310 Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Product Manifest Implementation-Title Jackson datatype: JSR310 High Product Manifest multi-release true Low Product Manifest specification-title Jackson datatype: JSR310 Medium Product pom artifactid jackson-datatype-jsr310 Highest Product pom developer email nicholas@nicholaswilliams.net Low Product pom developer id beamerblvd Low Product pom developer name Nick Williams Low Product pom groupid com.fasterxml.jackson.datatype Highest Product pom name Jackson datatype: JSR310 High Product pom parent-artifactid jackson-modules-java8 Medium Product pom parent-groupid com.fasterxml.jackson.module Medium Version file version 2.21.4 High Version Manifest Bundle-Version 2.21.4 High Version Manifest Implementation-Version 2.21.4 High Version pom version 2.21.4 Highest
pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.21.4 (Confidence :High) cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.4:*:*:*:*:*:*:* (Confidence :Low) suppress ffl-core-database-3.1.2.jar: jakarta.activation-api-2.1.4.jarDescription:
Specification License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.activation-api-2.1.4.jar
MD5: bc1602eee7bc61a0b86f14bbbb0cc794
SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8
SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation-api High Vendor jar package name activation Highest Vendor jar package name jakarta Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest implementation-build-id 3dad341 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.activation-api Low Vendor pom developer email bill.shannon@oracle.com Low Vendor pom developer id shannon Medium Vendor pom developer name Bill Shannon Medium Vendor pom developer org Oracle Medium Vendor pom groupid jakarta.activation Highest Vendor pom name Jakarta Activation API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url jakartaee/jaf-api Highest Vendor pom (hint) developer org sun Medium Product file name jakarta.activation-api High Product jar package name activation Highest Product jar package name jakarta Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation API Medium Product Manifest bundle-symbolicname jakarta.activation-api Medium Product Manifest extension-name jakarta.activation Medium Product Manifest implementation-build-id 3dad341 Low Product Manifest Implementation-Title Jakarta Activation API High Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid jakarta.activation-api Highest Product pom developer email bill.shannon@oracle.com Low Product pom developer id shannon Low Product pom developer name Bill Shannon Low Product pom developer org Oracle Low Product pom groupid jakarta.activation Highest Product pom name Jakarta Activation API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url jakartaee/jaf-api High Version file version 2.1.4 High Version Manifest Bundle-Version 2.1.4 High Version pom parent-version 2.1.4 Low Version pom version 2.1.4 Highest
pkg:maven/jakarta.activation/jakarta.activation-api@2.1.4 (Confidence :High) ffl-core-database-3.1.2.jar: jakarta.inject-api-2.0.1.jarDescription:
Jakarta Dependency Injection License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.inject-api-2.0.1.jar
MD5: 72003bf6efcc8455d414bbd7da86c11c
SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e
SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c
Evidence Type Source Name Value Confidence Vendor file name jakarta.inject-api High Vendor jar package name inject Highest Vendor jar package name jakarta Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Vendor pom artifactid jakarta.inject-api Low Vendor pom developer email asd[at]redhat[dot]com Low Vendor pom developer email manovotn[at]redhat[dot]com Low Vendor pom developer email mkouba[at]redhat[dot]com Low Vendor pom developer email tremes[at]redhat[dot]com Low Vendor pom developer id asabotdu Medium Vendor pom developer id manovotn Medium Vendor pom developer id mkouba Medium Vendor pom developer id tremes Medium Vendor pom developer name Antoine Sabot-Durand Medium Vendor pom developer name Martin Kouba Medium Vendor pom developer name Matej Novotny Medium Vendor pom developer name Tomas Remes Medium Vendor pom developer org Red Hat Inc. Medium Vendor pom groupid jakarta.inject Highest Vendor pom name Jakarta Dependency Injection High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url eclipse-ee4j/injection-api Highest Product file name jakarta.inject-api High Product jar package name inject Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Dependency Injection Medium Product Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Product pom artifactid jakarta.inject-api Highest Product pom developer email asd[at]redhat[dot]com Low Product pom developer email manovotn[at]redhat[dot]com Low Product pom developer email mkouba[at]redhat[dot]com Low Product pom developer email tremes[at]redhat[dot]com Low Product pom developer id asabotdu Low Product pom developer id manovotn Low Product pom developer id mkouba Low Product pom developer id tremes Low Product pom developer name Antoine Sabot-Durand Low Product pom developer name Martin Kouba Low Product pom developer name Matej Novotny Low Product pom developer name Tomas Remes Low Product pom developer org Red Hat Inc. Low Product pom groupid jakarta.inject Highest Product pom name Jakarta Dependency Injection High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j/injection-api High Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1 (Confidence :High) ffl-core-database-3.1.2.jar: jakarta.persistence-api-3.1.0.jarDescription:
Jakarta Persistence 3.1 API jar License:
Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.persistence-api-3.1.0.jar
MD5: 35a1b7dfb38cf44ff795be607b0e6b5b
SHA1: 66901fa1c373c6aff65c13791cc11da72060a8d6
SHA256: 475389446d35c6f46c565728b756dc508c284644ea2690644e0d8e7e339d42fd
Evidence Type Source Name Value Confidence Vendor file name jakarta.persistence-api High Vendor jar package name jakarta Highest Vendor jar package name persistence Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.persistence-api Medium Vendor Manifest extension-name jakarta.persistence Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.persistence-api Low Vendor pom developer id lukasj Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.persistence Highest Vendor pom name Jakarta Persistence API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url eclipse-ee4j/jpa-api Highest Product file name jakarta.persistence-api High Product jar package name jakarta Highest Product jar package name persistence Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Persistence API jar Medium Product Manifest bundle-symbolicname jakarta.persistence-api Medium Product Manifest extension-name jakarta.persistence Medium Product pom artifactid jakarta.persistence-api Highest Product pom developer id lukasj Low Product pom developer name Lukas Jungmann Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.persistence Highest Product pom name Jakarta Persistence API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j/jpa-api High Version file version 3.1.0 High Version Manifest Bundle-Version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
pkg:maven/jakarta.persistence/jakarta.persistence-api@3.1.0 (Confidence :High) ffl-core-database-3.1.2.jar: jakarta.transaction-api-2.0.1.jarDescription:
Jakarta Transactions License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.transaction-api-2.0.1.jar
MD5: 5315974a3935e342b40849478e1c9966
SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a
SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875
Evidence Type Source Name Value Confidence Vendor file name jakarta.transaction-api High Vendor jar package name jakarta Highest Vendor jar package name transaction Highest Vendor Manifest automatic-module-name jakarta.transaction Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/eclipse-ee4j Low Vendor Manifest bundle-symbolicname jakarta.transaction-api Medium Vendor Manifest extension-name jakarta.transaction Medium Vendor Manifest Implementation-Vendor EE4J Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid jakarta.transaction-api Low Vendor pom developer id stephen_felts Medium Vendor pom developer name Stephen Felts Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.transaction Highest Vendor pom name API High Vendor pom organization name EE4J Community High Vendor pom organization url eclipse-ee4j Medium Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.jta Highest Product file name jakarta.transaction-api High Product jar package name jakarta Highest Product jar package name transaction Highest Product Manifest automatic-module-name jakarta.transaction Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/eclipse-ee4j Low Product Manifest Bundle-Name jakarta.transaction API Medium Product Manifest bundle-symbolicname jakarta.transaction-api Medium Product Manifest extension-name jakarta.transaction Medium Product pom artifactid jakarta.transaction-api Highest Product pom developer id stephen_felts Low Product pom developer name Stephen Felts Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.transaction Highest Product pom name API High Product pom organization name EE4J Community Low Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j High Product pom url https://projects.eclipse.org/projects/ee4j.jta Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.1 (Confidence :High) cpe:2.3:a:oracle:projects:2.0.1:*:*:*:*:*:*:* (Confidence :Low) suppress ffl-core-database-3.1.2.jar: jakarta.xml.bind-api-4.0.5.jarDescription:
Jakarta XML Binding API 4.0 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jakarta.xml.bind-api-4.0.5.jar
MD5: 935053b2c792f34c7ea3a238ea96f3ac
SHA1: 161811f36cad3c65991502e80317f2f6703361df
SHA256: 5e489b6c874c4119e003ff1403db523ee3a8959ec499f3de29e77245efccf216
Evidence Type Source Name Value Confidence Vendor file name jakarta.xml.bind-api High Vendor jar package name bind Highest Vendor jar package name jakarta Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest extension-name jakarta.xml.bind Medium Vendor Manifest implementation-build-id 33af600 Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.xml.bind-api Low Vendor pom groupid jakarta.xml.bind Highest Vendor pom name Jakarta XML Binding API High Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low Product file name jakarta.xml.bind-api High Product jar package name bind Highest Product jar package name jakarta Highest Product jar package name xml Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta XML Binding API Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest extension-name jakarta.xml.bind Medium Product Manifest implementation-build-id 33af600 Low Product pom artifactid jakarta.xml.bind-api Highest Product pom groupid jakarta.xml.bind Highest Product pom name Jakarta XML Binding API High Product pom parent-artifactid jakarta.xml.bind-api-parent Medium Version file version 4.0.5 High Version Manifest Bundle-Version 4.0.5 High Version Manifest Implementation-Version 4.0.5 High Version pom version 4.0.5 Highest
pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.5 (Confidence :High) ffl-core-database-3.1.2.jar: jandex-3.2.0.jarDescription:
SmallRye Build Parent POM License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jandex-3.2.0.jar
MD5: 703254a1bd4c37efeebdc0a283c65565
SHA1: f17ad860f62a08487b9edabde608f8ac55c62fa7
SHA256: 6da3e9ce8d0c0a433f3e7ce610a3c66accb00c71fee67aa0ff3e5a841395ac15
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor jar package name jandex Highest Vendor jar package name jboss Highest Vendor Manifest automatic-module-name org.jboss.jandex Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-symbolicname io.smallrye.jandex Medium Vendor Manifest multi-release true Low Vendor pom artifactid jandex Low Vendor pom groupid io.smallrye Highest Vendor pom name Jandex: Core High Vendor pom parent-artifactid jandex-parent Low Product file name jandex High Product jar package name jandex Highest Product jar package name jboss Highest Product Manifest automatic-module-name org.jboss.jandex Medium Product Manifest build-jdk-spec 17 Low Product Manifest Bundle-Name Jandex: Core Medium Product Manifest bundle-symbolicname io.smallrye.jandex Medium Product Manifest multi-release true Low Product pom artifactid jandex Highest Product pom groupid io.smallrye Highest Product pom name Jandex: Core High Product pom parent-artifactid jandex-parent Medium Version file version 3.2.0 High Version Manifest Bundle-Version 3.2.0 High Version pom version 3.2.0 Highest
pkg:maven/io.smallrye/jandex@3.2.0 (Confidence :High) ffl-core-database-3.1.2.jar: jaxb-core-4.0.9.jarDescription:
JAXB Core module. Contains sources required by XJC, JXC and Runtime modules. License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jaxb-core-4.0.9.jar
MD5: cfe79c0de53d009f9b171d1320f7879a
SHA1: 3f32ec949d109d666fa30994223d1c25a47b105f
SHA256: 6b014df25d22c8446cc2df0a378c5b2137747f197a731d99eb24c756b26f7e8d
Evidence Type Source Name Value Confidence Vendor file name jaxb-core High Vendor jar package name core Highest Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Vendor Manifest git-revision e155f35 Low Vendor Manifest implementation-build-id 4.0.9 - e155f35 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-core Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Core High Vendor pom parent-artifactid jaxb-parent Low Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-core High Product jar package name core Highest Product jar package name glassfish Highest Product jar package name jaxb Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Core Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Product Manifest git-revision e155f35 Low Product Manifest implementation-build-id 4.0.9 - e155f35 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-core Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Core High Product pom parent-artifactid jaxb-parent Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.9 High Version Manifest build-version 4.0.9 Medium Version Manifest Bundle-Version 4.0.9 High Version Manifest implementation-build-id 4.0.9 Low Version pom version 4.0.9 Highest
pkg:maven/org.glassfish.jaxb/jaxb-core@4.0.9 (Confidence :High) ffl-core-database-3.1.2.jar: jaxb-runtime-4.0.9.jarDescription:
JAXB (JSR 222) Reference Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jaxb-runtime-4.0.9.jar
MD5: 5a09f7188a527773fc71f0ac8ca30652
SHA1: 500c199572538675d2819c938fbafe34935d8d6b
SHA256: 93e09b7316b6af68d6e2083e4c297daf28e8957f45d725077af812c0b12c39ab
Evidence Type Source Name Value Confidence Vendor file name jaxb-runtime High Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor jar package name runtime Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Vendor Manifest git-revision e155f35 Low Vendor Manifest implementation-build-id 4.0.9 - e155f35 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-runtime Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-runtime High Product jar package name glassfish Highest Product jar package name jaxb Highest Product jar package name runtime Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Runtime Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product Manifest git-revision e155f35 Low Product Manifest implementation-build-id 4.0.9 - e155f35 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-runtime Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Runtime High Product pom parent-artifactid jaxb-runtime-parent Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.9 High Version Manifest build-version 4.0.9 Medium Version Manifest Bundle-Version 4.0.9 High Version Manifest implementation-build-id 4.0.9 Low Version pom version 4.0.9 Highest
pkg:maven/org.glassfish.jaxb/jaxb-runtime@4.0.9 (Confidence :High) ffl-core-database-3.1.2.jar: jboss-logging-3.6.3.Final.jarDescription:
The JBoss Logging Framework License:
Apache License 2.0: https://repository.jboss.org/licenses/apache-2.0.txt File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/jboss-logging-3.6.3.Final.jar
MD5: b4cf5872f18b3e80e18769d51c7ae9b2
SHA1: 1cc9f976725720bb4a66f80af3e3aa6b9890d969
SHA256: 7c12ee575508f81e22b1db9334b969d0ec54ef0fd1dcba24eeab1a44235fc366
Evidence Type Source Name Value Confidence Vendor file name jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest build-jdk-spec 25 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url https://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging 3 High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Vendor pom url https://www.jboss.org Highest Product file name jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product Manifest build-jdk-spec 25 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url https://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Logging 3 Medium Product pom artifactid jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging 3 High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Product pom url https://www.jboss.org Medium Version Manifest Bundle-Version 3.6.3.Final High Version Manifest Implementation-Version 3.6.3.Final High Version pom parent-version 3.6.3.Final Low Version pom version 3.6.3.Final Highest
pkg:maven/org.jboss.logging/jboss-logging@3.6.3.Final (Confidence :High) ffl-core-database-3.1.2.jar: postgresql-42.7.11.jarDescription:
Java JDBC driver for PostgreSQL database License:
BSD-2-Clause File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/postgresql-42.7.11.jar
MD5: b969f87f07d6434bd77cdc5e440da49a
SHA1: 4c21cdd1b3938f400703716d37c4e8ca4d332808
SHA256: 1981b31d3993c58702783c1cddf10a34e48c1f413d70ff1cb6def0a143484647
Evidence Type Source Name Value Confidence Vendor file name postgresql High Vendor jar package name jdbc Highest Vendor jar package name org Highest Vendor jar package name postgresql Highest Vendor jar package name postgresql Low Vendor Manifest automatic-module-name org.postgresql.jdbc Medium Vendor Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver";effective:=active Low Vendor Manifest specification-vendor Oracle Corporation Low Product file name postgresql High Product hint analyzer product pgjdbc Highest Product hint analyzer product postgresql_jdbc_driver Highest Product jar package name driver Highest Product jar package name jdbc Highest Product jar package name org Highest Product jar package name osgi Highest Product jar package name postgresql Highest Product Manifest automatic-module-name org.postgresql.jdbc Medium Product Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver";effective:=active Low Product Manifest specification-title JDBC Medium Version file version 42.7.11 High Version Manifest Implementation-Version 42.7.11 High
ffl-core-database-3.1.2.jar: spring-tx-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-tx-6.2.19.jarMD5: 0a3ba16888dc23fdd52ba7b36bc01835SHA1: 0aa1a170d935a3c39176d27a2353c34c2861b7dcSHA256: 34a1b6f5d87ef4cca6849e1bc70a0f965eec6476737b3cae73ff2561a266ef73
Evidence Type Source Name Value Confidence Vendor file name spring-tx High Vendor hint analyzer vendor pivotal software Highest Vendor jar package name springframework Low Vendor jar package name transaction Low Vendor Manifest automatic-module-name spring.tx Medium Product file name spring-tx High Product jar package name transaction Low Product Manifest automatic-module-name spring.tx Medium Product Manifest Implementation-Title spring-tx High Version file version 6.2.19 High Version Manifest Implementation-Version 6.2.19 High
Related Dependencies ffl-core-database-3.1.2.jar: spring-beans-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-beans-6.2.19.jar MD5: ae0cf6f1e373577d322e17c350d0fb15 SHA1: 6d6b4774db3b036df46be6332d93b09d70e5c147 SHA256: 846dc8f30a639a36eb551ee99a30469be4d11bd285ca9daf164d98321571b404 ffl-core-database-3.1.2.jar: spring-context-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-context-6.2.19.jar MD5: 77c848b32f387021e0b690be9cd24de8 SHA1: e218e4c4ecad1e821905628b2c4ce8561d937baa SHA256: ead4b645f94a7f665f00093eaafde634e97b34524294de653b51e43e0b3fc4a4 ffl-core-database-3.1.2.jar: spring-expression-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-expression-6.2.19.jar MD5: 233e2f7ced4637cad68a9449844e9a6b SHA1: c7202d23797fa778c5ed55e502ac1a9f0d34012a SHA256: d710a44417d890353895b341a722d7d08199e2b7da52f0a11c0e92571e1d6e19 ffl-core-database-3.1.2.jar: spring-jcl-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-jcl-6.2.19.jar MD5: cd5278839172f3b30b1e90bc70d9b864 SHA1: 39b9c7d631961f3649511b08ef167420b086184b SHA256: 9994478bcea1423b8892d4eb0db942c94da0090167c3c684050c1eaef04491d0 ffl-core-database-3.1.2.jar: spring-jdbc-6.2.19.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/spring-jdbc-6.2.19.jar MD5: 05da1adb03141a0e3c93861f6ab10a98 SHA1: d7b6ea705a71dbbb4499437dd54b9217ce6c251a SHA256: c81fd8aca952aac243d9327af12596c2058012c9d3784f1313477a6d2cc56306 ffl-core-database-3.1.2.jar: txw2-4.0.9.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-database/target/ffl-core-database-3.1.2.jar/BOOT-INF/lib/txw2-4.0.9.jarMD5: 09ca7799e2d1a5b484e1290db7bb9344SHA1: 70325ebdebca3e7aae1dfa395fd41fc25d8a6f4eSHA256: d6343e5945d87266ca4e8974a0a2a876e1bd147a00fb65ed3f2e1a3a00f3a82a
Evidence Type Source Name Value Confidence Vendor file name txw2 High Vendor jar package name txw Highest Vendor jar package name txw2 Highest Vendor jar package name xml Highest Vendor Manifest git-revision e155f35 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid txw2 Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name txw2 High Product jar package name txw Highest Product jar package name txw2 Highest Product jar package name xml Highest Product Manifest git-revision e155f35 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid txw2 Highest Product pom groupid org.glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.9 High Version Manifest build-version 4.0.9 Medium Version pom version 4.0.9 Highest
pkg:maven/org.glassfish.jaxb/txw2@4.0.9 (Confidence :High) ffl-core-services-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-services/target/ffl-core-services-3.1.2.jarMD5: 3caf2052bb5247e1760db46a40f6263fSHA1: 5dea62b046a57b41e738d7853f3ba40f6084700eSHA256: 93184fe8dc8fce3bda2a4881ff4cff76eb03b8af4b29ea691c8e19058193c922
Evidence Type Source Name Value Confidence Vendor file name ffl-core-services High Vendor jar package name core Highest Vendor jar package name ffl Highest Vendor jar package name services Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-core-services Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-services-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-services High Product jar package name core Highest Product jar package name ffl Highest Product jar package name services Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-services High Product pom artifactid ffl-core-services Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-services-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-services@3.1.2 (Confidence :High) ffl-core-sia-3.1.2.jarFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-sia/target/ffl-core-sia-3.1.2.jarMD5: f7eea74e51aeb31ff9c5e51560940e8fSHA1: 6afe94f8eb816c205cc648461cadaeec64a96261SHA256: e90631c1b88b3162c19fc2fa8fb409504a96681e3a39f4e69f5d958513ee9d9c
Evidence Type Source Name Value Confidence Vendor file name ffl-core-sia High Vendor jar package name core Highest Vendor jar package name ffl Highest Vendor jar package name sia Highest Vendor jar package name sintia Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-core-sia Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-sia-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-core-sia High Product jar package name core Highest Product jar package name ffl Highest Product jar package name sia Highest Product jar package name sintia Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-core-sia High Product pom artifactid ffl-core-sia Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-sia-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-core-sia@3.1.2 (Confidence :High) ffl-test-3.1.2.jarDescription:
Module d'outillage de test File Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-test/target/ffl-test-3.1.2.jarMD5: 3640757de9317a508e03edaf743bf4f0SHA1: 01f8c9c08e497dad895d66f7eeb111727dc0457fSHA256: d4c2ad41ff3c86860dcdb3aaa034333696f84c39060185a6d5ab431e017d7124
Evidence Type Source Name Value Confidence Vendor file name ffl-test High Vendor jar package name ffl Highest Vendor jar package name sintia Highest Vendor jar package name test Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid ffl-test Low Vendor pom groupid com.sintia.ffl.core Highest Vendor pom parent-artifactid ffl-parent Low Vendor pom parent-groupid com.sintia.ffl Medium Product file name ffl-test High Product jar package name ffl Highest Product jar package name sintia Highest Product jar package name test Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ffl-test High Product pom artifactid ffl-test Highest Product pom groupid com.sintia.ffl.core Highest Product pom parent-artifactid ffl-parent Medium Product pom parent-groupid com.sintia.ffl Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2 High Version pom version 3.1.2 Highest
pkg:maven/com.sintia.ffl.core/ffl-test@3.1.2 (Confidence :High) prettify.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-api/target/site/jacoco/jacoco-resources/prettify.jsMD5: 4b337aaa3c606cfc1a6ff1986db2c8cbSHA1: 290093755739da933c180ae7e7ebf283724dad1dSHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68
Evidence Type Source Name Value Confidence
Related Dependencies prettify.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-dal/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-services/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-sia/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 sort.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-api/target/site/jacoco/jacoco-resources/sort.jsMD5: af6dc76a8d5e0653f66eb57f2757327dSHA1: 03380a84c61514f773a503de39d517e1bb2d72bbSHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043
Evidence Type Source Name Value Confidence
Related Dependencies sort.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-commons/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-dal/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-services/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /home/azureuser/dependency-check/projects/ffl-core/ffl-core/ffl-core-sia/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043