Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.3.2Report Generated On : Oct 23, 2018 at 16:06:34 +02:00Dependencies Scanned : 383 (296 unique)Vulnerable Dependencies : 44 Vulnerabilities Found : 137Vulnerabilities Suppressed : 3... NVD CVE 2002 : 20/10/2018 09:49:35NVD CVE 2003 : 20/10/2018 09:47:04NVD CVE 2004 : 20/10/2018 09:46:21NVD CVE 2005 : 20/10/2018 09:45:02NVD CVE 2006 : 20/10/2018 09:42:51NVD CVE 2007 : 20/10/2018 09:39:31NVD CVE 2008 : 20/10/2018 09:36:21NVD CVE 2009 : 19/10/2018 09:48:16NVD CVE 2010 : 19/10/2018 09:45:17NVD CVE 2011 : 19/10/2018 09:41:18NVD CVE 2012 : 22/10/2018 09:24:35NVD CVE 2013 : 23/10/2018 09:33:09NVD CVE 2014 : 23/10/2018 15:17:55NVD CVE 2015 : 23/10/2018 09:25:40NVD CVE 2016 : 23/10/2018 09:21:31NVD CVE 2017 : 23/10/2018 15:17:54NVD CVE 2018 : 23/10/2018 09:05:31NVD CVE Checked : 23/10/2018 16:05:53NVD CVE Modified : 23/10/2018 14:04:55VersionCheckOn : 1540303553858Display:
Showing Vulnerable Dependencies (click to show all) Dependencies activation-1.1.jarDescription:
JavaBeans Activation Framework (JAF) is a standard extension to the Java platform that lets you take advantage of standard services to: determine the type of an arbitrary piece of data; encapsulate access to it; discover the operations available on it; and instantiate the appropriate bean to perform the operation(s).
License:
Common Development and Distribution License (CDDL) v1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/activation-1.1.jar
MD5: 8ae38e87cd4f86059c0294a8fe3e0b18
SHA1: e6cb541461c2834bdea3eb920f1884d1eb508b50
SHA256: 2881c79c9d6ef01c58e62beea13e9d1ac8b8baa16f2fc198ad6e6776defdcdd3
Evidence Type Source Name Value Confidence Vendor pom artifactid activation Low Vendor pom name JavaBeans Activation Framework (JAF) High Vendor pom description JavaBeans Activation Framework (JAF) is a standard extension to the Java platform that lets you take advantage of standard services to: determine the type of an arbitrary piece of data; encapsulate access to it; discover the operations available on it; and instantiate the appropriate bean to perform the operation(s). Low Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor pom groupid javax.activation Highest Vendor jar package name activation Low Vendor jar package name javax Low Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor central groupid javax.activation Highest Vendor pom url http://java.sun.com/products/javabeans/jaf/index.jsp Highest Vendor file name activation High Product pom artifactid activation Highest Product Manifest extension-name javax.activation Medium Product pom groupid javax.activation Low Product pom name JavaBeans Activation Framework (JAF) High Product pom url http://java.sun.com/products/javabeans/jaf/index.jsp Medium Product central artifactid activation Highest Product pom description JavaBeans Activation Framework (JAF) is a standard extension to the Java platform that lets you take advantage of standard services to: determine the type of an arbitrary piece of data; encapsulate access to it; discover the operations available on it; and instantiate the appropriate bean to perform the operation(s). Low Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium Product file name activation High Product jar package name activation Low Version file version 1.1 Highest Version central version 1.1 Highest Version Manifest Implementation-Version 1.1 High Version pom version 1.1 Highest
aopalliance-1.0.jarDescription:
AOP Alliance License:
Public Domain File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
SHA256: 0addec670fedcd3f113c5c8091d783280d23f75e3acb841b61a9cdb079376a08
Evidence Type Source Name Value Confidence Vendor central groupid aopalliance Highest Vendor pom description AOP Alliance Medium Vendor jar package name intercept Low Vendor pom artifactid aopalliance Low Vendor jar package name aopalliance Low Vendor pom url http://aopalliance.sourceforge.net Highest Vendor pom groupid aopalliance Highest Vendor file name aopalliance High Vendor pom name AOP alliance High Product pom url http://aopalliance.sourceforge.net Medium Product pom description AOP Alliance Medium Product pom groupid aopalliance Low Product jar package name intercept Low Product central artifactid aopalliance Highest Product pom artifactid aopalliance Highest Product file name aopalliance High Product pom name AOP alliance High Version pom version 1.0 Highest Version file version 1.0 Highest Version central version 1.0 Highest
apacheds-i18n-2.0.0-M15.jarDescription:
Internationalization of errors and other messages License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/apacheds-i18n-2.0.0-M15.jar
MD5: f5877c02fd56ade67713560e589c81b9
SHA1: 71c61c84683152ec2a6a65f3f96fe534e304fa22
SHA256: bd3b7cece7fc6364cbce32b9edd0e9628a3e889c6a93cdeff1b5e2131e2a007c
Evidence Type Source Name Value Confidence Vendor jar package name directory Low Vendor pom groupid apache.directory.server Highest Vendor Manifest bundle-symbolicname org.apache.directory.server.i18n Medium Vendor Manifest Implementation-Vendor-Id org.apache.directory.server Medium Vendor central groupid org.apache.directory.server Highest Vendor manifest Bundle-Description Internationalization of errors and other messages Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid apacheds-parent Low Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor jar package name server Low Vendor pom name ApacheDS I18n High Vendor file name apacheds-i18n High Vendor pom description Internationalization of errors and other messages Medium Vendor pom artifactid apacheds-i18n Low Vendor pom parent-groupid org.apache.directory.server Medium Product Manifest Bundle-Name ApacheDS I18n Medium Product jar package name directory Low Product Manifest bundle-symbolicname org.apache.directory.server.i18n Medium Product manifest Bundle-Description Internationalization of errors and other messages Medium Product pom parent-artifactid apacheds-parent Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product pom groupid apache.directory.server Low Product pom parent-groupid org.apache.directory.server Low Product jar package name server Low Product pom name ApacheDS I18n High Product file name apacheds-i18n High Product jar package name i18n Low Product pom artifactid apacheds-i18n Highest Product pom description Internationalization of errors and other messages Medium Product Manifest specification-title ApacheDS I18n Medium Product Manifest Implementation-Title ApacheDS I18n High Product central artifactid apacheds-i18n Highest Version pom version 2.0.0-M15 Highest Version file version 2.0.0.m15 Highest Version Manifest Implementation-Version 2.0.0-M15 High Version central version 2.0.0-M15 Highest
apacheds-kerberos-codec-2.0.0-M15.jarDescription:
The Kerberos protocol encoder/decoder module License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/apacheds-kerberos-codec-2.0.0-M15.jar
MD5: 3118e22eac44e150c383df1d417772f4
SHA1: 1c16e4e477183641c5f0dd5cdecd27ec331bacb5
SHA256: 4996f5b72497e94dd86d64a370158c4fb0049eea9b17ff8b27a4671d6c136ded
Evidence Type Source Name Value Confidence Vendor jar package name directory Low Vendor pom groupid apache.directory.server Highest Vendor Manifest Implementation-Vendor-Id org.apache.directory.server Medium Vendor central groupid org.apache.directory.server Highest Vendor Manifest bundle-symbolicname org.apache.directory.server.kerberos.codec Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid apacheds-kerberos-codec Low Vendor pom parent-artifactid apacheds-parent Low Vendor jar package name apache Low Vendor pom description The Kerberos protocol encoder/decoder module Medium Vendor manifest Bundle-Description The Kerberos protocol encoder/decoder module Medium Vendor pom name ApacheDS Protocol Kerberos Codec High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor jar package name shared Low Vendor file name apacheds-kerberos-codec High Vendor pom parent-groupid org.apache.directory.server Medium Product jar package name directory Low Product Manifest Bundle-Name ApacheDS Protocol Kerberos Codec Medium Product Manifest bundle-symbolicname org.apache.directory.server.kerberos.codec Medium Product pom parent-artifactid apacheds-parent Medium Product pom description The Kerberos protocol encoder/decoder module Medium Product manifest Bundle-Description The Kerberos protocol encoder/decoder module Medium Product pom name ApacheDS Protocol Kerberos Codec High Product jar package name kerberos Low Product Manifest bundle-docurl http://www.apache.org/ Low Product pom groupid apache.directory.server Low Product pom parent-groupid org.apache.directory.server Low Product jar package name shared Low Product Manifest Implementation-Title ApacheDS Protocol Kerberos Codec High Product central artifactid apacheds-kerberos-codec Highest Product file name apacheds-kerberos-codec High Product Manifest specification-title ApacheDS Protocol Kerberos Codec Medium Product pom artifactid apacheds-kerberos-codec Highest Version pom version 2.0.0-M15 Highest Version file version 2.0.0.m15 Highest Version Manifest Implementation-Version 2.0.0-M15 High Version central version 2.0.0-M15 Highest
api-asn1-api-1.0.0-M20.jarDescription:
ASN.1 API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/api-asn1-api-1.0.0-M20.jar
MD5: cf4561832dab76e9f37461342ec18d17
SHA1: 5e6486ffa3125ba44dc410ead166e1d6ba8ac76d
SHA256: 484aaf4b888b0eb699d95bea265c2d5b6ebec951d70e5c5f7691cd52dd4c8298
Evidence Type Source Name Value Confidence Vendor jar package name directory Low Vendor pom parent-artifactid api-asn1-parent Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom description ASN.1 API Medium Vendor pom artifactid api-asn1-api Low Vendor Manifest bundle-symbolicname org.apache.directory.api.asn1.api Medium Vendor jar package name apache Low Vendor pom groupid apache.directory.api Highest Vendor central groupid org.apache.directory.api Highest Vendor pom name Apache Directory API ASN.1 API High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest Implementation-Vendor-Id org.apache.directory.api Medium Vendor pom parent-groupid org.apache.directory.api Medium Vendor file name api-asn1-api High Vendor manifest Bundle-Description ASN.1 API Medium Vendor jar package name api Low Product pom groupid apache.directory.api Low Product jar package name directory Low Product jar package name asn1 Low Product Manifest Bundle-Name Apache Directory API ASN.1 API Medium Product Manifest Implementation-Title Apache Directory API ASN.1 API High Product pom parent-artifactid api-asn1-parent Medium Product Manifest specification-title Apache Directory API ASN.1 API Medium Product pom description ASN.1 API Medium Product central artifactid api-asn1-api Highest Product Manifest bundle-symbolicname org.apache.directory.api.asn1.api Medium Product pom artifactid api-asn1-api Highest Product pom name Apache Directory API ASN.1 API High Product Manifest bundle-docurl http://www.apache.org/ Low Product file name api-asn1-api High Product manifest Bundle-Description ASN.1 API Medium Product pom parent-groupid org.apache.directory.api Low Product jar package name api Low Version pom version 1.0.0-M20 Highest Version file version 1.0.0.m20 Highest Version central version 1.0.0-M20 Highest Version Manifest Implementation-Version 1.0.0-M20 High
api-util-1.0.0-M20.jarDescription:
Utilities shared across this top level project License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/api-util-1.0.0-M20.jar
MD5: 2c5a6722666882024becdd64301be492
SHA1: a871abf060b3cf83fc6dc4d7e3d151fce50ac3cb
SHA256: fd32fd047ccf143c58d093b58811aa81e539f8cf83c1187809f1a241a1df12d1
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Utilities shared across this top level project Medium Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom description Utilities shared across this top level project Medium Vendor pom artifactid api-util Low Vendor pom parent-artifactid api-parent Low Vendor pom parent-groupid org.apache.directory.api Medium Vendor pom name Apache Directory LDAP API Utilities High Vendor Manifest bundle-symbolicname org.apache.directory.api.util Medium Vendor file name api-util High Vendor pom groupid apache.directory.api Highest Product pom groupid apache.directory.api Low Product manifest Bundle-Description Utilities shared across this top level project Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product pom parent-artifactid api-parent Medium Product pom description Utilities shared across this top level project Medium Product Manifest Bundle-Name Apache Directory LDAP API Utilities Medium Product pom parent-groupid org.apache.directory.api Low Product pom name Apache Directory LDAP API Utilities High Product Manifest bundle-symbolicname org.apache.directory.api.util Medium Product file name api-util High Product pom artifactid api-util Highest Version pom version 1.0.0-M20 Highest Version file version 1.0.0.m20 Highest
maven: org.apache.directory.api:api-util:1.0.0-M20 Confidence :Highcpe: cpe:/a:apache:directory_ldap_api:1.0.0.m30 Confidence :Low suppress Published Vulnerabilities CVE-2015-3250 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. Vulnerable Software & Versions:
args4j-2.0.16.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/args4j-2.0.16.jarMD5: 6571d69d142dd2a003c4ffae6138f0eeSHA1: 9f00fb12820743b9e05c686eba543d64dd43f2b1SHA256: c361d3741c1e79550c7fa04d01c699d66e0a16f18a1749eaa1b8b0df61cd0275
Evidence Type Source Name Value Confidence Vendor jar package name kohsuke Low Vendor pom groupid args4j Highest Vendor jar package name spi Low Vendor file name args4j High Vendor pom parent-artifactid args4j-site Low Vendor pom artifactid args4j Low Vendor jar package name args4j Low Vendor pom name args4j High Product jar package name spi Low Product file name args4j High Product pom parent-artifactid args4j-site Medium Product pom groupid args4j Low Product jar package name args4j Low Product pom artifactid args4j Highest Product pom name args4j High Version pom version 2.0.16 Highest Version file version 2.0.16 Highest
maven: args4j:args4j:2.0.16 Confidence :High asm-3.3.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/asm-3.3.1.jarMD5: 1ad1e8959324b0f680b8e62406955642SHA1: 1d5f20b4ea675e6fab6ab79f1cd60ec268ddc015SHA256: c2b39275f8e951bc74750080a1266cdabc39399bc5e13d642bf2d346449df7f3
Evidence Type Source Name Value Confidence Vendor pom artifactid asm Low Vendor pom parent-artifactid asm-parent Low Vendor jar package name objectweb Low Vendor pom name ASM Core High Vendor pom groupid asm Highest Vendor central groupid asm Highest Vendor Manifest Implementation-Vendor France Telecom R&D High Vendor file name asm High Vendor jar package name asm Low Product central artifactid asm Highest Product pom name ASM Core High Product Manifest Implementation-Title ASM High Product pom artifactid asm Highest Product file name asm High Product jar package name asm Low Product pom groupid asm Low Product pom parent-artifactid asm-parent Medium Version Manifest Implementation-Version 3.3.1 High Version pom version 3.3.1 Highest Version central version 3.3.1 Highest Version file version 3.3.1 Highest
avro-1.8.1.jarDescription:
Avro core components License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/avro-1.8.1.jar
MD5: c63b9d628c09e3aa8f46a0ff4ca4129d
SHA1: f4e11d00055760dca33daab193192bd75cc87b59
SHA256: f0ae68f3aac3eddf2d5ec4d75d9fbe1c272d8bf26dea9b72ee9f6331d53cb764
Evidence Type Source Name Value Confidence Vendor pom groupid apache.avro Highest Vendor pom parent-artifactid avro-parent Low Vendor Manifest Implementation-Vendor-Id org.apache.avro Medium Vendor pom url http://avro.apache.org Highest Vendor file name avro High Vendor jar package name com Low Vendor Manifest bundle-symbolicname avro Medium Vendor manifest Bundle-Description Avro core components Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Apache Avro High Vendor pom parent-groupid org.apache.avro Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor jar package name avro Low Vendor pom artifactid avro Low Vendor pom description Avro core components Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name shaded Low Vendor central groupid org.apache.avro Highest Product Manifest Bundle-Name Apache Avro Medium Product pom artifactid avro Highest Product file name avro High Product jar package name com Low Product Manifest bundle-symbolicname avro Medium Product pom parent-artifactid avro-parent Medium Product Manifest specification-title Apache Avro Medium Product manifest Bundle-Description Avro core components Medium Product jar package name google Low Product central artifactid avro Highest Product Manifest Implementation-Title Apache Avro High Product pom name Apache Avro High Product pom parent-groupid org.apache.avro Low Product Manifest bundle-docurl http://www.apache.org/ Low Product pom groupid apache.avro Low Product pom description Avro core components Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product jar package name shaded Low Product pom url http://avro.apache.org Medium Version central version 1.8.1 Highest Version file version 1.8.1 Highest Version pom version 1.8.1 Highest Version Manifest Implementation-Version 1.8.1 High
avro-compiler-1.8.1.jarDescription:
Compilers for Avro IDL and Avro Specific Java API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/avro-compiler-1.8.1.jar
MD5: e9ce07837cf4d6c11fe82810b15984c0
SHA1: a150c5bc9faba3ee4a060944b36d070939559a6b
SHA256: 171dbe867ff21301614aca4825e7b0b5e4f8251c43b8fe9656232602e98794c5
Evidence Type Source Name Value Confidence Vendor pom groupid apache.avro Highest Vendor pom parent-artifactid avro-parent Low Vendor pom url http://avro.apache.org Highest Vendor file name avro-compiler High Vendor Manifest bundle-symbolicname avro-compiler Medium Vendor pom name Apache Avro Compiler High Vendor pom parent-groupid org.apache.avro Medium Vendor pom description Compilers for Avro IDL and Avro Specific Java API Medium Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom artifactid avro-compiler Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor manifest Bundle-Description Compilers for Avro IDL and Avro Specific Java API Medium Product pom artifactid avro-compiler Highest Product file name avro-compiler High Product Manifest bundle-symbolicname avro-compiler Medium Product pom parent-artifactid avro-parent Medium Product pom name Apache Avro Compiler High Product Manifest Bundle-Name Apache Avro Compiler Medium Product pom description Compilers for Avro IDL and Avro Specific Java API Medium Product pom parent-groupid org.apache.avro Low Product Manifest bundle-docurl http://www.apache.org/ Low Product pom groupid apache.avro Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom url http://avro.apache.org Medium Product manifest Bundle-Description Compilers for Avro IDL and Avro Specific Java API Medium Version file version 1.8.1 Highest Version pom version 1.8.1 Highest
maven: org.apache.avro:avro-compiler:1.8.1 Confidence :High avro-ipc-1.8.1.jarDescription:
Avro inter-process communication components License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/avro-ipc-1.8.1.jar
MD5: 9e82a0b2ec1161b45ee9be524fdbb3f0
SHA1: f3434bde10f24da6c0f525dcf928e4fda364e6b5
SHA256: c3f4106f7c5f183a0a142106732177f50500aae343b847f9fa45b82221f951ec
Evidence Type Source Name Value Confidence Vendor pom groupid apache.avro Highest Vendor pom artifactid avro-ipc Low Vendor pom parent-artifactid avro-parent Low Vendor Manifest Implementation-Vendor-Id org.apache.avro Medium Vendor file name avro-ipc High Vendor pom url http://avro.apache.org Highest Vendor pom description Avro inter-process communication components Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-groupid org.apache.avro Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest bundle-symbolicname avro-ipc Medium Vendor manifest Bundle-Description Avro inter-process communication components Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom name Apache Avro IPC High Product Manifest specification-title Apache Avro IPC Medium Product Manifest Implementation-Title Apache Avro IPC High Product file name avro-ipc High Product pom description Avro inter-process communication components Medium Product pom parent-artifactid avro-parent Medium Product pom parent-groupid org.apache.avro Low Product Manifest bundle-docurl http://www.apache.org/ Low Product pom groupid apache.avro Low Product Manifest bundle-symbolicname avro-ipc Medium Product pom artifactid avro-ipc Highest Product manifest Bundle-Description Avro inter-process communication components Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Bundle-Name Apache Avro IPC Medium Product pom name Apache Avro IPC High Product pom url http://avro.apache.org Medium Version file version 1.8.1 Highest Version pom version 1.8.1 Highest Version Manifest Implementation-Version 1.8.1 High
maven: org.apache.avro:avro-ipc:1.8.1 Confidence :High avro-mapred-1.8.1.jarDescription:
An org.apache.hadoop.mapred compatible API for using Avro Serializatin in Hadoop File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/avro-mapred-1.8.1.jarMD5: 1fc5882ada660ac8a2f76ab369dc9929SHA1: 9c513ca68090d1580df1790a12788d08fba81a91SHA256: aa8e86f9f5494eb28d6176720e62bd721b85dd47ed105ea13261815aa991775d
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.avro Highest Vendor pom name Apache Avro Mapred API High Vendor pom artifactid avro-mapred Low Vendor pom parent-artifactid avro-parent Low Vendor Manifest Implementation-Vendor-Id org.apache.avro Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name avro-mapred High Vendor pom description An org.apache.hadoop.mapred compatible API for using Avro Serializatin in Hadoop Medium Vendor pom parent-groupid org.apache.avro Medium Product pom name Apache Avro Mapred API High Product pom groupid apache.avro Low Product pom parent-artifactid avro-parent Medium Product file name avro-mapred High Product pom description An org.apache.hadoop.mapred compatible API for using Avro Serializatin in Hadoop Medium Product Manifest specification-title Apache Avro Mapred API Medium Product Manifest Implementation-Title Apache Avro Mapred API High Product pom parent-groupid org.apache.avro Low Product pom artifactid avro-mapred Highest Version file version 1.8.1 Highest Version pom version 1.8.1 Highest Version Manifest Implementation-Version 1.8.1 High
maven: org.apache.avro:avro-mapred:1.8.1 Confidence :Highcpe: cpe:/a:apache:hadoop:1.8.1 Confidence :Low suppress Published Vulnerabilities CVE-2016-5001 suppress
Severity:Low CVSS Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token. Vulnerable Software & Versions: (show all )
CVE-2017-3161 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. Vulnerable Software & Versions:
CVE-2017-3162 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0. Vulnerable Software & Versions:
bootstrap-3.0.3.jarDescription:
WebJar for Bootstrap License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/bootstrap-3.0.3.jar
MD5: 8a2c981f25963903795453685babda0a
SHA1: 7297fe81dc0e82c44e15232014fd8e1180c0a3bc
SHA256: e84ad1718ab9f5eec39afcdeba0706497328f6e2394bab3dbb501fd367d12548
Evidence Type Source Name Value Confidence Vendor pom description WebJar for Bootstrap Medium Vendor pom groupid webjars Highest Vendor pom name Bootstrap High Vendor file name bootstrap High Vendor pom artifactid bootstrap Low Vendor pom url http://webjars.org Highest Product pom groupid webjars Low Product pom artifactid bootstrap Highest Product pom description WebJar for Bootstrap Medium Product pom name Bootstrap High Product pom url http://webjars.org Medium Product file name bootstrap High Version file version 3.0.3 Highest Version pom version 3.0.3 Highest
maven: org.webjars:bootstrap:3.0.3 Confidence :High cglib-2.2.1-v20090111.jarLicense:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cglib-2.2.1-v20090111.jar
MD5: 88af5931165ac8becab84a157c9bace0
SHA1: 07ce5e983fd0e6c78346f4c9cbfa39d83049dda2
SHA256: 42e1dfb26becbf1a633f25b47e39fcc422b85e77e4c0468d9a44f885f5fa0be2
Evidence Type Source Name Value Confidence Vendor pom groupid sonatype.sisu.inject Highest Vendor pom parent-artifactid forge-parent Low Vendor pom url http://sourceforge.net/projects/cglib/ Highest Vendor central groupid org.sonatype.sisu.inject Highest Vendor jar package name sf Low Vendor pom name CGLIB High Vendor pom artifactid cglib Low Vendor jar package name net Low Vendor file name cglib High Vendor jar package name cglib Low Vendor pom parent-groupid org.sonatype.forge Medium Product pom groupid sonatype.sisu.inject Low Product pom parent-artifactid forge-parent Medium Product jar package name sf Low Product pom name CGLIB High Product central artifactid cglib Highest Product pom parent-groupid org.sonatype.forge Low Product pom url http://sourceforge.net/projects/cglib/ Medium Product file name cglib High Product jar package name cglib Low Product pom artifactid cglib Highest Version file version 2.2.1.v20090111 Highest Version central version 2.2.1-v20090111 Highest Version pom version 2.2.1-v20090111 Highest
cglib-2.2.2.jarDescription:
Code generation library License:
ASF 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cglib-2.2.2.jar
MD5: b3f681be48fce094cf01a045f5bdca6f
SHA1: a47a971686474124562bdd4a7ccbd8ac8c3e8b11
SHA256: a93e4485d274277177480c4afe6ddd8355cda1cacfe356c134e25d65193935fd
Evidence Type Source Name Value Confidence Vendor pom name Code Generation Library High Vendor jar package name sf Low Vendor pom url http://cglib.sourceforge.net/ Highest Vendor pom groupid cglib Highest Vendor pom artifactid cglib Low Vendor jar package name net Low Vendor file name cglib High Vendor pom description Code generation library Medium Vendor jar package name cglib Low Vendor central groupid cglib Highest Product pom name Code Generation Library High Product pom groupid cglib Low Product jar package name sf Low Product central artifactid cglib Highest Product pom url http://cglib.sourceforge.net/ Medium Product file name cglib High Product pom description Code generation library Medium Product jar package name cglib Low Product pom artifactid cglib Highest Version file version 2.2.2 Highest Version central version 2.2.2 Highest Version pom version 2.2.2 Highest
closure-compiler-v20130603.jarDescription:
Closure Compiler is a JavaScript optimizing compiler. It parses your
JavaScript, analyzes it, removes dead code and rewrites and minimizes
what's left. It also checks syntax, variable references, and types, and
warns about common JavaScript pitfalls. It is used in many of Google's
JavaScript apps, including Gmail, Google Web Search, Google Maps, and
Google Docs.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/closure-compiler-v20130603.jar
MD5: 49ce4295fcce117f5f242170ec48bd2e
SHA1: b150c1666154435f43bc4665e202dee7c3c95eb7
SHA256: 6ca35497d82bb61fc779676c508178f79a2457d1b71466c6bae2aa7612fe7975
Evidence Type Source Name Value Confidence Vendor pom url http://code.google.com/p/closure-compiler/ Highest Vendor pom artifactid closure-compiler Low Vendor jar package name javascript Low Vendor pom organization name Google High Vendor pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low Vendor jar package name google Low Vendor pom groupid google.javascript Highest Vendor pom name Closure Compiler High Vendor pom organization url http://www.google.com Medium Vendor file name closure-compiler-v20130603 High Vendor jar package name jscomp Low Vendor central groupid com.google.javascript Highest Product central artifactid closure-compiler Highest Product pom name Closure Compiler High Product jar package name javascript Low Product pom groupid google.javascript Low Product pom artifactid closure-compiler Highest Product pom organization url http://www.google.com Low Product pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low Product file name closure-compiler-v20130603 High Product pom organization name Google Low Product jar package name jscomp Low Product pom url http://code.google.com/p/closure-compiler/ Medium Version file name closure-compiler-v20130603 Medium Version central version v20130603 Highest Version pom version v20130603 Highest Version file version 20130603 Medium
Published Vulnerabilities CVE-2017-17689 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-310 Cryptographic Issues
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. Vulnerable Software & Versions: (show all )
commons-beanutils-1.7.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-beanutils-1.7.0.jarMD5: 0f18acf5fa857f9959675e14d901a7ceSHA1: 5675fd96b29656504b86029551973d60fb41339bSHA256: 24bcaa20ccbdc7c856ce0c0aea144566943403e2e9f27bd9779cda1d76823ef4
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor pom artifactid commons-beanutils Low Vendor Manifest specification-vendor Apache Software Foundation Low Vendor file name commons-beanutils High Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor jar package name beanutils Low Vendor Manifest extension-name org.apache.commons.beanutils Medium Vendor central groupid commons-beanutils Highest Vendor pom groupid commons-beanutils Highest Vendor jar package name apache Low Product jar package name commons Low Product pom artifactid commons-beanutils Highest Product file name commons-beanutils High Product jar package name beanutils Low Product Manifest specification-title Jakarta Commons Beanutils Medium Product Manifest extension-name org.apache.commons.beanutils Medium Product Manifest Implementation-Title org.apache.commons.beanutils High Product pom groupid commons-beanutils Low Product central artifactid commons-beanutils Highest Version file version 1.7.0 Highest Version central version 1.7.0 Highest Version pom version 1.7.0 Highest
Published Vulnerabilities CVE-2014-0114 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. Vulnerable Software & Versions: (show all )
commons-beanutils-core-1.8.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-beanutils-core-1.8.0.jarMD5: a33ba25ae637909a97a60ff1d1b38857SHA1: 175dc721f87e4bc5cc0573f990e28c3cf9117508SHA256: 9038c7ddc61d3d8089eb5a52a24b430a202617d57d2d344a93b68e4eafefefde
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor central groupid commons-beanutils Highest Vendor pom artifactid commons-beanutils-core Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name apache Low Vendor file name commons-beanutils-core High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://commons.apache.org/beanutils/ Highest Vendor pom name Commons BeanUtils Core High Vendor jar package name beanutils Low Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom groupid commons-beanutils Highest Product jar package name commons Low Product pom parent-groupid org.apache Low Product pom groupid commons-beanutils Low Product pom artifactid commons-beanutils-core Highest Product central artifactid commons-beanutils-core Highest Product file name commons-beanutils-core High Product pom name Commons BeanUtils Core High Product jar package name beanutils Low Product pom parent-artifactid apache Medium Product Manifest specification-title Commons BeanUtils Core Medium Product pom url http://commons.apache.org/beanutils/ Medium Product Manifest Implementation-Title Commons BeanUtils Core High Version Manifest Implementation-Version 1.8.0 High Version central version 1.8.0 Highest Version file version 1.8.0 Highest Version pom version 1.8.0 Highest
Published Vulnerabilities CVE-2014-0114 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1. Vulnerable Software & Versions: (show all )
commons-cli-1.2.jarDescription:
Commons CLI provides a simple API for presenting, processing and validating a command line interface.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-cli-1.2.jar
MD5: bfdcae1ff93f0c07d733f03bdce28c9e
SHA1: 2bf96b7aa8b611c177d329452af1dc933e14501c
SHA256: e7cd8951956d349b568b7ccfd4f5b2529a8c113e67c32b028f52ffda371259d9
Evidence Type Source Name Value Confidence Vendor pom groupid commons-cli Highest Vendor manifest Bundle-Description Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Vendor file name commons-cli High Vendor pom artifactid commons-cli Low Vendor pom description Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom name Commons CLI High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.cli Medium Vendor pom url http://commons.apache.org/cli/ Highest Vendor Manifest bundle-docurl http://commons.apache.org/cli/ Low Product manifest Bundle-Description Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Product file name commons-cli High Product Manifest Bundle-Name Commons CLI Medium Product pom parent-artifactid commons-parent Medium Product pom description Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Product Manifest Implementation-Title Commons CLI High Product pom url http://commons.apache.org/cli/ Medium Product Manifest specification-title Commons CLI Medium Product pom name Commons CLI High Product pom parent-groupid org.apache.commons Low Product Manifest bundle-symbolicname org.apache.commons.cli Medium Product Manifest bundle-docurl http://commons.apache.org/cli/ Low Product pom artifactid commons-cli Highest Product pom groupid commons-cli Low Version Manifest Implementation-Version 1.2 High Version file version 1.2 Highest Version pom version 1.2 Highest
maven: commons-cli:commons-cli:1.2 Confidence :High commons-codec-1.7.jarDescription:
The codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-codec-1.7.jar
MD5: e47ef8e1a0c11e0e7e41704816cda890
SHA1: 9cd61d269c88f9fb0eb36cea1efcd596ab74772f
SHA256: db82a948bc070414fcfd3880ebd1205c94df5f5c61558ccbc653ec2f820bf7a4
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description The codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Vendor pom url http://commons.apache.org/codec/ Highest Vendor pom groupid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest bundle-docurl http://commons.apache.org/codec/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build tags/1.7-RC2@r1383368; 2012-09-11 08:05:03-0400 Low Vendor pom name Commons Codec High Vendor pom description The codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Vendor file name commons-codec High Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium Product Manifest Bundle-Name Commons Codec Medium Product manifest Bundle-Description The codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/codec/ Medium Product Manifest specification-title Commons Codec Medium Product Manifest Implementation-Title Commons Codec High Product Manifest bundle-docurl http://commons.apache.org/codec/ Low Product pom parent-groupid org.apache.commons Low Product Manifest implementation-build tags/1.7-RC2@r1383368; 2012-09-11 08:05:03-0400 Low Product pom artifactid commons-codec Highest Product pom name Commons Codec High Product pom groupid commons-codec Low Product pom description The codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Product file name commons-codec High Product Manifest bundle-symbolicname org.apache.commons.codec Medium Version Manifest Implementation-Version 1.7 High Version file version 1.7 Highest Version pom version 1.7 Highest
Related Dependencies commons-codec-1.7.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/commons-codec-1.7.jar MD5: e47ef8e1a0c11e0e7e41704816cda890 SHA1: 9cd61d269c88f9fb0eb36cea1efcd596ab74772f SHA256: db82a948bc070414fcfd3880ebd1205c94df5f5c61558ccbc653ec2f820bf7a4 commons-codec-1.7.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/commons-codec-1.7.jar MD5: e47ef8e1a0c11e0e7e41704816cda890 SHA1: 9cd61d269c88f9fb0eb36cea1efcd596ab74772f SHA256: db82a948bc070414fcfd3880ebd1205c94df5f5c61558ccbc653ec2f820bf7a4 maven: commons-codec:commons-codec:1.7 Confidence :High commons-collections-3.2.1.jarDescription:
Types that extend and augment the Java Collections Framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-collections-3.2.1.jar
MD5: 13bc641afd7fd95e09b260f69c1e4c91
SHA1: 761ea405b9b37ced573d2df0d1e3a4e0f9edc668
SHA256: 87363a4c94eaabeefd8b930cb059f66b64c9f7d632862f23de3012da7660047b
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium Vendor file name commons-collections High Vendor pom name Commons Collections High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/collections/ Highest Vendor pom parent-groupid org.apache.commons Medium Vendor pom groupid commons-collections Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium Vendor pom description Types that extend and augment the Java Collections Framework. Medium Vendor pom artifactid commons-collections Low Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low Product Manifest Implementation-Title Commons Collections High Product manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium Product pom artifactid commons-collections Highest Product file name commons-collections High Product pom parent-artifactid commons-parent Medium Product pom name Commons Collections High Product Manifest specification-title Commons Collections Medium Product pom url http://commons.apache.org/collections/ Medium Product pom parent-groupid org.apache.commons Low Product pom groupid commons-collections Low Product Manifest Bundle-Name Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.collections Medium Product pom description Types that extend and augment the Java Collections Framework. Medium Product Manifest bundle-docurl http://commons.apache.org/collections/ Low Version Manifest Implementation-Version 3.2.1 High Version file version 3.2.1 Highest Version pom version 3.2.1 Highest
Related Dependencies commons-collections-3.2.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/commons-collections-3.2.1.jar MD5: 13bc641afd7fd95e09b260f69c1e4c91 SHA1: 761ea405b9b37ced573d2df0d1e3a4e0f9edc668 SHA256: 87363a4c94eaabeefd8b930cb059f66b64c9f7d632862f23de3012da7660047b Published Vulnerabilities CVE-2015-6420 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. Vulnerable Software & Versions: (show all )
CVE-2017-15708 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version. Vulnerable Software & Versions: (show all )
commons-collections4-4.0.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-collections4-4.0.jar
MD5: a18f2d0153b5607dff8c5becbdd76dd1
SHA1: da217367fd25e88df52ba79e47658d4cf928b0d1
SHA256: 93f8dfcd20831a28d092427723f696bceb70b28e7fb89d7914f14d5ea492ce5a
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.collections4 Medium Vendor manifest Bundle-Description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-build tags/COLLECTIONS_4_0_RC5@r1543977; 2013-11-20 23:44:45+0100 Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom name Apache Commons Collections High Vendor file name commons-collections4 High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low Vendor pom url http://commons.apache.org/proper/commons-collections/ Highest Vendor pom groupid apache.commons Highest Vendor pom artifactid commons-collections4 Low Product Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-collections4 Highest Product Manifest bundle-symbolicname org.apache.commons.collections4 Medium Product manifest Bundle-Description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low Product Manifest implementation-build tags/COLLECTIONS_4_0_RC5@r1543977; 2013-11-20 23:44:45+0100 Low Product Manifest Bundle-Name Apache Commons Collections Medium Product pom name Apache Commons Collections High Product file name commons-collections4 High Product pom parent-groupid org.apache.commons Low Product Manifest specification-title Apache Commons Collections Medium Product pom url http://commons.apache.org/proper/commons-collections/ Medium Product Manifest Implementation-Title Apache Commons Collections High Product pom groupid apache.commons Low Product pom description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low Version Manifest Implementation-Version 4.0 High Version pom version 4.0 Highest Version file version 4.0 Highest
Published Vulnerabilities CVE-2015-6420 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. Vulnerable Software & Versions: (show all )
commons-compress-1.4.1.jarDescription:
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-compress-1.4.1.jar
MD5: 7f7ff9255a831325f38a170992b70073
SHA1: b02e84a993d88568417536240e970c4b809126fd
SHA256: 28a00d80716f073d644b9da76e94b5e8ff94de8e9323f06f558fba653fcf5f86
Evidence Type Source Name Value Confidence Vendor Manifest extension-name org.apache.commons.compress Medium Vendor pom name Commons Compress High Vendor Manifest bundle-symbolicname org.apache.commons.compress Medium Vendor Manifest bundle-docurl http://commons.apache.org/compress/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom artifactid commons-compress Low Vendor manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low Vendor pom url http://commons.apache.org/compress/ Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name commons-compress High Vendor Manifest implementation-build trunk@r1341303; 2012-05-22 06:55:03+0200 Low Vendor pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low Vendor pom groupid apache.commons Highest Product Manifest extension-name org.apache.commons.compress Medium Product pom artifactid commons-compress Highest Product pom parent-artifactid commons-parent Medium Product pom name Commons Compress High Product Manifest bundle-symbolicname org.apache.commons.compress Medium Product Manifest bundle-docurl http://commons.apache.org/compress/ Low Product Manifest Implementation-Title Commons Compress High Product manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low Product pom parent-groupid org.apache.commons Low Product Manifest specification-title Commons Compress Medium Product file name commons-compress High Product Manifest implementation-build trunk@r1341303; 2012-05-22 06:55:03+0200 Low Product pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low Product Manifest Bundle-Name Commons Compress Medium Product pom groupid apache.commons Low Product pom url http://commons.apache.org/compress/ Medium Version pom version 1.4.1 Highest Version Manifest Implementation-Version 1.4.1 High Version file version 1.4.1 Highest
cpe: cpe:/a:apache:commons-compress:1.4.1 Confidence :Low suppress maven: org.apache.commons:commons-compress:1.4.1 Confidence :High commons-configuration-1.6.jarDescription:
Tools to assist in the reading of configuration/preferences files in
various formats
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-configuration-1.6.jar
MD5: b099d9f9b4b99071cc52b259308df69a
SHA1: 32cadde23955d7681b0d94a2715846d20b425235
SHA256: 46b71b9656154f6a16ea4b1dc84026b52a9305f8eff046a2b4655fa1738e5eee
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-configuration Low Vendor pom name Commons Configuration High Vendor pom groupid commons-configuration Highest Vendor Manifest bundle-symbolicname org.apache.commons.configuration Medium Vendor Manifest bundle-docurl http://commons.apache.org/configuration/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor manifest Bundle-Description Tools to assist in the reading of configuration/preferences files in various formats Medium Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom description Tools to assist in the reading of configuration/preferences files in various formats Low Vendor file name commons-configuration High Vendor pom url http://commons.apache.org/configuration/ Highest Product pom name Commons Configuration High Product pom parent-artifactid commons-parent Medium Product Manifest bundle-symbolicname org.apache.commons.configuration Medium Product Manifest bundle-docurl http://commons.apache.org/configuration/ Low Product manifest Bundle-Description Tools to assist in the reading of configuration/preferences files in various formats Medium Product pom parent-groupid org.apache.commons Low Product pom artifactid commons-configuration Highest Product pom url http://commons.apache.org/configuration/ Medium Product Manifest Bundle-Name Commons Configuration Medium Product Manifest Implementation-Title Commons Configuration High Product pom description Tools to assist in the reading of configuration/preferences files in various formats Low Product file name commons-configuration High Product Manifest specification-title Commons Configuration Medium Product pom groupid commons-configuration Low Version file version 1.6 Highest Version pom version 1.6 Highest Version Manifest Implementation-Version 1.6 High
maven: commons-configuration:commons-configuration:1.6 Confidence :High commons-daemon-1.0.13.jarDescription:
Apache Commons Daemon software provides an alternative invocation mechanism for unix-daemon-like Java code.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-daemon-1.0.13.jar
MD5: 686f1a2cc85f8f4e939bd3cd28c9720b
SHA1: 750856a1fdb3ddf721ccf73c3518e4211cffc3a3
SHA256: fd63b583fd3e8baeae22efacbd5a4f91c1fd97f56248e62e2615efa7b81daeaa
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://commons.apache.org/daemon/ Low Vendor pom url http://commons.apache.org/daemon/ Highest Vendor pom groupid commons-daemon Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor file name commons-daemon High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2013-02-06 19:20:07+0100 Low Vendor pom description Apache Commons Daemon software provides an alternative invocation mechanism for unix-daemon-like Java code. Low Vendor manifest Bundle-Description Apache Commons Daemon software provides an alternative invocation mechanism for unix-daemon-like Java code. Low Vendor pom artifactid commons-daemon Low Vendor Manifest bundle-symbolicname org.apache.commons.daemon Medium Vendor pom name Commons Daemon High Product Manifest bundle-docurl http://commons.apache.org/daemon/ Low Product Manifest Bundle-Name Commons Daemon Medium Product pom groupid commons-daemon Low Product pom parent-artifactid commons-parent Medium Product file name commons-daemon High Product pom artifactid commons-daemon Highest Product pom parent-groupid org.apache.commons Low Product pom url http://commons.apache.org/daemon/ Medium Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2013-02-06 19:20:07+0100 Low Product pom description Apache Commons Daemon software provides an alternative invocation mechanism for unix-daemon-like Java code. Low Product manifest Bundle-Description Apache Commons Daemon software provides an alternative invocation mechanism for unix-daemon-like Java code. Low Product Manifest specification-title Commons Daemon Medium Product Manifest Implementation-Title Commons Daemon High Product Manifest bundle-symbolicname org.apache.commons.daemon Medium Product pom name Commons Daemon High Version pom version 1.0.13 Highest Version Manifest Implementation-Version 1.0.13 High Version file version 1.0.13 Highest
cpe: cpe:/a:apache:apache_commons_daemon:1.0.13 Confidence :Low suppress maven: commons-daemon:commons-daemon:1.0.13 Confidence :High commons-digester-1.8.jarDescription:
The Digester package lets you configure an XML->Java object mapping module
which triggers certain actions called rules whenever a particular
pattern of nested XML elements is recognized. License:
The Apache Software License, Version 2.0: /LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-digester-1.8.jar
MD5: cf89c593f0378e9509a06fce7030aeba
SHA1: dc6a73fdbd1fa3f0944e8497c6c872fa21dca37e
SHA256: 05662373044f3dff112567b7bb5dfa1174e91e074c0c727b4412788013f49d56
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor file name commons-digester High Vendor central groupid commons-digester Highest Vendor pom organization url http://jakarta.apache.org Medium Vendor pom description The Digester package lets you configure an XML->Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low Vendor Manifest extension-name commons-digester Medium Vendor jar package name digester Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom groupid commons-digester Highest Vendor pom name Digester High Vendor jar package name apache Low Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://jakarta.apache.org/commons/digester/ Highest Vendor pom artifactid commons-digester Low Product jar package name commons Low Product file name commons-digester High Product pom organization name The Apache Software Foundation Low Product pom artifactid commons-digester Highest Product Manifest Implementation-Title org.apache.commons.digester High Product Manifest specification-title Rule based XML->Java object mapping module Medium Product pom description The Digester package lets you configure an XML->Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low Product Manifest extension-name commons-digester Medium Product jar package name digester Low Product pom organization url http://jakarta.apache.org Low Product pom name Digester High Product pom url http://jakarta.apache.org/commons/digester/ Medium Product pom groupid commons-digester Low Product central artifactid commons-digester Highest Version file version 1.8 Highest Version central version 1.8 Highest Version Manifest Implementation-Version 1.8 High Version pom version 1.8 Highest
commons-el-1.0.jarDescription:
JSP 2.0 Expression Language Interpreter Implementation License:
The Apache Software License, Version 2.0: /LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-el-1.0.jar
MD5: 7c98594df7c126f33688fa6d93169639
SHA1: 1df2c042b3f2de0124750241ac6c886dbfa2cc2c
SHA256: 0d67550ec0022b653453c759f063a643c2fe64bc48faa8b25f95a220e2a282e2
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor pom artifactid commons-el Low Vendor pom organization url http://jakarta.apache.org Medium Vendor pom groupid commons-el Highest Vendor central groupid commons-el High Vendor jar package name apache Low Vendor central groupid tomcat High Vendor pom organization name The Apache Software Foundation High Vendor jar package name el Low Vendor Manifest specification-vendor Apache Software Foundation Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor file name commons-el High Vendor pom url http://jakarta.apache.org/commons/el/ Highest Vendor Manifest extension-name org.apache.commons.el Medium Vendor pom description JSP 2.0 Expression Language Interpreter Implementation Medium Vendor pom name EL High Product jar package name commons Low Product pom url http://jakarta.apache.org/commons/el/ Medium Product pom organization name The Apache Software Foundation Low Product pom organization url http://jakarta.apache.org Low Product jar package name el Low Product pom artifactid commons-el Highest Product Manifest Implementation-Title org.apache.commons.el High Product central artifactid commons-el High Product file name commons-el High Product pom groupid commons-el Low Product Manifest extension-name org.apache.commons.el Medium Product pom description JSP 2.0 Expression Language Interpreter Implementation Medium Product Manifest specification-title Jakarta Commons EL Medium Product pom name EL High Version pom version 1.0 Highest Version central version 5.5.23 High Version file version 1.0 Highest Version central version 1.0 High Version Manifest Implementation-Version 1.0 High
commons-fileupload-1.3.jarDescription:
The FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-fileupload-1.3.jar
MD5: fd24e83d8f62085f84c0622087872f36
SHA1: c89e540e4a12cb034fb973e12135839b5de9a87e
SHA256: bcea3f830ff3867c6700c1fc12282c219ecf77ae6b36cea445b8e9dc751449fe
Evidence Type Source Name Value Confidence Vendor file name commons-fileupload High Vendor pom groupid commons-fileupload Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom description The FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low Vendor pom name Commons FileUpload High Vendor Manifest implementation-build tags/FILEUPLOAD_1_3_RC2@r1460338; 2013-03-24 13:39:55+0100 Low Vendor pom artifactid commons-fileupload Low Vendor manifest Bundle-Description The FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest Product file name commons-fileupload High Product Manifest specification-title Commons FileUpload Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low Product pom parent-artifactid commons-parent Medium Product Manifest Bundle-Name Commons FileUpload Medium Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium Product pom artifactid commons-fileupload Highest Product pom groupid commons-fileupload Low Product pom parent-groupid org.apache.commons Low Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium Product pom description The FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low Product pom name Commons FileUpload High Product Manifest implementation-build tags/FILEUPLOAD_1_3_RC2@r1460338; 2013-03-24 13:39:55+0100 Low Product manifest Bundle-Description The FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low Product Manifest Implementation-Title Commons FileUpload High Version file version 1.3 Highest Version pom version 1.3 Highest Version Manifest Implementation-Version 1.3 High
Published Vulnerabilities CVE-2014-0050 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-264 Permissions, Privileges, and Access Controls
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions. Vulnerable Software & Versions: (show all )
CVE-2016-1000031 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-284 Improper Access Control
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution Vulnerable Software & Versions:
CVE-2016-3092 suppress
Severity:High CVSS Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C) CWE: CWE-20 Improper Input Validation
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. Vulnerable Software & Versions: (show all )
commons-httpclient-3.1.jarDescription:
The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. License:
Apache License: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-httpclient-3.1.jar
MD5: 8ad8c9229ef2d59ab9f59f7050e846a5
SHA1: 964cd74171f427720480efdec40a7c7f6e58426a
SHA256: dbd4953d013e10e7c1cc3701a3e6ccd8c950c892f08d804fabfac21705930443
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor file name commons-httpclient High Vendor central groupid commons-httpclient Highest Vendor pom artifactid commons-httpclient Low Vendor jar package name apache Low Vendor pom organization url http://jakarta.apache.org/ Medium Vendor manifest: org/apache/commons/httpclient Implementation-Vendor Apache Software Foundation Medium Vendor jar package name httpclient Low Vendor pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Highest Vendor pom name HttpClient High Vendor pom organization name Apache Software Foundation High Vendor pom groupid commons-httpclient Highest Vendor pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low Product jar package name commons Low Product file name commons-httpclient High Product pom organization name Apache Software Foundation Low Product pom artifactid commons-httpclient Highest Product pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Medium Product central artifactid commons-httpclient Highest Product manifest: org/apache/commons/httpclient Implementation-Title org.apache.commons.httpclient Medium Product pom groupid commons-httpclient Low Product jar package name httpclient Low Product pom name HttpClient High Product manifest: org/apache/commons/httpclient Specification-Title Jakarta Commons HttpClient Medium Product pom organization url http://jakarta.apache.org/ Low Product pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low Version file version 3.1 Highest Version pom version 3.1 Highest Version central version 3.1 Highest
commons-io-2.4.jarDescription:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
SHA256: cc6a41dc3eaacc9e440a6bd0d2890b20d36b4ee408fe2d67122f328bb6e01581
Evidence Type Source Name Value Confidence Vendor pom groupid commons-io Highest Vendor manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low Vendor pom name Commons IO High Vendor pom artifactid commons-io Low Vendor pom url http://commons.apache.org/io/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low Vendor file name commons-io High Product manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low Product pom name Commons IO High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/io/ Medium Product Manifest bundle-docurl http://commons.apache.org/io/ Low Product pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low Product Manifest Bundle-Name Commons IO Medium Product pom parent-groupid org.apache.commons Low Product Manifest specification-title Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.io Medium Product Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low Product file name commons-io High Product Manifest Implementation-Title Commons IO High Product pom groupid commons-io Low Product pom artifactid commons-io Highest Version pom version 2.4 Highest Version file version 2.4 Highest Version Manifest Implementation-Version 2.4 High
Related Dependencies commons-io-2.4.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-io-2.4.jar MD5: 7f97854dc04c119d461fed14f5d8bb96 SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad SHA256: cc6a41dc3eaacc9e440a6bd0d2890b20d36b4ee408fe2d67122f328bb6e01581 commons-io-2.4.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/commons-io-2.4.jar MD5: 7f97854dc04c119d461fed14f5d8bb96 SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad SHA256: cc6a41dc3eaacc9e440a6bd0d2890b20d36b4ee408fe2d67122f328bb6e01581 maven: commons-io:commons-io:2.4 Confidence :High commons-lang-2.6.jarDescription:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
SHA256: 50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/lang/ Highest Vendor pom groupid commons-lang Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Commons Lang High Vendor file name commons-lang High Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium Vendor pom artifactid commons-lang Low Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low Product Manifest Bundle-Name Commons Lang Medium Product pom groupid commons-lang Low Product pom parent-artifactid commons-parent Medium Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Product pom parent-groupid org.apache.commons Low Product pom name Commons Lang High Product pom url http://commons.apache.org/lang/ Medium Product pom artifactid commons-lang Highest Product file name commons-lang High Product Manifest specification-title Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang Medium Product Manifest Implementation-Title Commons Lang High Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Product Manifest bundle-docurl http://commons.apache.org/lang/ Low Version file version 2.6 Highest Version Manifest Implementation-Version 2.6 High Version pom version 2.6 Highest
Related Dependencies commons-lang-2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-lang-2.6.jar MD5: 4d5c1693079575b362edf41500630bbd SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2 SHA256: 50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c commons-lang-2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/commons-lang-2.6.jar MD5: 4d5c1693079575b362edf41500630bbd SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2 SHA256: 50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c maven: commons-lang:commons-lang:2.6 Confidence :High commons-lang3-3.1.jarDescription:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-lang3-3.1.jar
MD5: 71b48e6b3e1b1dc73fe705604b9c7584
SHA1: 905075e6c80f206bbe6cf1e809d2caa69f420c76
SHA256: 131f0519a8e4602e47cf024bfd7e0834bcf5592a7207f9a2fdb711d4f5afc166
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-lang3 Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/lang/ Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Commons Lang High Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor pom groupid apache.commons Highest Vendor file name commons-lang3 High Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2011-11-09 22:58:07-0800 Low Product Manifest Bundle-Name Commons Lang Medium Product pom parent-artifactid commons-parent Medium Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low Product pom parent-groupid org.apache.commons Low Product pom name Commons Lang High Product pom url http://commons.apache.org/lang/ Medium Product Manifest specification-title Commons Lang Medium Product pom groupid apache.commons Low Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Commons Lang High Product file name commons-lang3 High Product Manifest bundle-docurl http://commons.apache.org/lang/ Low Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2011-11-09 22:58:07-0800 Low Product pom artifactid commons-lang3 Highest Version Manifest Implementation-Version 3.1 High Version file version 3.1 Highest Version pom version 3.1 Highest
maven: org.apache.commons:commons-lang3:3.1 Confidence :High commons-logging-1.1.3.jarDescription:
Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-logging-1.1.3.jar
MD5: 92eb5aabc1b47287de53d45c086a435c
SHA1: f6f66e966c70a83ffbdb6f17a0919eaf7c8aca7f
SHA256: 70903f6fc82e9908c8da9f20443f61d90f0870a312642991fe8462a0b9391784
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor manifest Bundle-Description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor file name commons-logging High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid commons-logging Highest Vendor pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Vendor Manifest implementation-build tags/LOGGING_1_1_3_RC2@r1483540; 2013-05-16 22:04:41+0200 Low Vendor pom name Commons Logging High Vendor pom artifactid commons-logging Low Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Product Manifest Bundle-Name Commons Logging Medium Product manifest Bundle-Description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Product pom groupid commons-logging Low Product pom parent-artifactid commons-parent Medium Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product pom artifactid commons-logging Highest Product file name commons-logging High Product pom parent-groupid org.apache.commons Low Product pom url http://commons.apache.org/proper/commons-logging/ Medium Product Manifest Implementation-Title Commons Logging High Product pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Product Manifest specification-title Commons Logging Medium Product Manifest implementation-build tags/LOGGING_1_1_3_RC2@r1483540; 2013-05-16 22:04:41+0200 Low Product pom name Commons Logging High Version file version 1.1.3 Highest Version pom version 1.1.3 Highest Version Manifest Implementation-Version 1.1.3 High
Related Dependencies commons-logging-1.1.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-logging-1.1.3.jar MD5: 92eb5aabc1b47287de53d45c086a435c SHA1: f6f66e966c70a83ffbdb6f17a0919eaf7c8aca7f SHA256: 70903f6fc82e9908c8da9f20443f61d90f0870a312642991fe8462a0b9391784 maven: commons-logging:commons-logging:1.1.3 Confidence :High commons-math3-3.1.1.jarDescription:
The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-math3-3.1.1.jar
MD5: 505ece0d2261b037101e6c4bdf541ca7
SHA1: 6719d757a98ff24a83d9d727bef9cec83f59b6e1
SHA256: a07e39d31c46032879f0a48ae1bd0142b17dd67664c008b50216e9891f346c54
Evidence Type Source Name Value Confidence Vendor file name commons-math3 High Vendor Manifest bundle-docurl http://commons.apache.org/math/ Low Vendor pom name Commons Math High Vendor pom url http://commons.apache.org/math/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor manifest Bundle-Description The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.math3 Medium Vendor pom description The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. Low Vendor Manifest implementation-build tags/MATH_3_1_1_RC1@r1430928; 2013-01-09 17:13:33+0100 Low Vendor pom artifactid commons-math3 Low Vendor pom groupid apache.commons Highest Product file name commons-math3 High Product Manifest bundle-docurl http://commons.apache.org/math/ Low Product Manifest Implementation-Title Commons Math High Product pom name Commons Math High Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-math3 Highest Product Manifest specification-title Commons Math Medium Product manifest Bundle-Description The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. Low Product pom parent-groupid org.apache.commons Low Product pom url http://commons.apache.org/math/ Medium Product Manifest bundle-symbolicname org.apache.commons.math3 Medium Product Manifest Bundle-Name Commons Math Medium Product pom description The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. Low Product Manifest implementation-build tags/MATH_3_1_1_RC1@r1430928; 2013-01-09 17:13:33+0100 Low Product pom groupid apache.commons Low Version file version 3.1.1 Highest Version Manifest Implementation-Version 3.1.1 High Version pom version 3.1.1 Highest
maven: org.apache.commons:commons-math3:3.1.1 Confidence :High commons-net-3.1.jarDescription:
Apache Commons Net library contains a collection of network utilities and protocol implementations.
Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/commons-net-3.1.jar
MD5: 23c94d51e72f341fb412d6a015e16313
SHA1: 2298164a7c2484406f2aa5ac85b205d39019896f
SHA256: 34a58d6d80a50748307e674ec27b4411e6536fd12e78bec428eb2ee49a123007
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build tags/NET_3_1_RC2@r1244108; 2012-02-14 17:45:12+0000 Low Vendor Manifest bundle-symbolicname org.apache.commons.net Medium Vendor pom name Commons Net High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/net/ Highest Vendor file name commons-net High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid commons-net Highest Vendor pom description
Apache Commons Net library contains a collection of network utilities and protocol implementations.
Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois Low Vendor Manifest bundle-docurl http://commons.apache.org/net/ Low Vendor pom artifactid commons-net Low Vendor manifest Bundle-Description Apache Commons Net library contains a collection of network utilities and protocol implementations.Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois Low Product Manifest implementation-build tags/NET_3_1_RC2@r1244108; 2012-02-14 17:45:12+0000 Low Product pom groupid commons-net Low Product Manifest bundle-symbolicname org.apache.commons.net Medium Product pom name Commons Net High Product pom parent-artifactid commons-parent Medium Product Manifest Bundle-Name Commons Net Medium Product Manifest Implementation-Title Commons Net High Product Manifest specification-title Commons Net Medium Product file name commons-net High Product pom parent-groupid org.apache.commons Low Product pom description
Apache Commons Net library contains a collection of network utilities and protocol implementations.
Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois Low Product Manifest bundle-docurl http://commons.apache.org/net/ Low Product pom artifactid commons-net Highest Product pom url http://commons.apache.org/net/ Medium Product manifest Bundle-Description Apache Commons Net library contains a collection of network utilities and protocol implementations.Supported protocols include: Echo, Finger, FTP, NNTP, NTP, POP3(S), SMTP(S), Telnet, Whois Low Version Manifest Implementation-Version 3.1 High Version file version 3.1 Highest Version pom version 3.1 Highest
maven: commons-net:commons-net:3.1 Confidence :High crawler-commons-0.10.jarDescription:
crawler-commons is a set of reusable Java components that implement
functionality common to any web crawler.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/crawler-commons-0.10.jar
MD5: 9008c9876d7ad7e8a39a915120efe867
SHA1: 40a3cb267fd85959902fbbf4a652b6131bc06f8b
SHA256: 77dcdc049b1b9481e5a2e4adee0ce0bb70c806b8be03cad72a04df754178490c
Evidence Type Source Name Value Confidence Vendor pom artifactid crawler-commons Low Vendor pom organization name Crawler-Commons High Vendor pom description crawler-commons is a set of reusable Java components that implement functionality common to any web crawler. Low Vendor jar package name crawlercommons Low Vendor pom groupid github.crawler-commons Highest Vendor file name crawler-commons High Vendor pom organization url http://github.com/crawler-commons Medium Vendor pom url crawler-commons/crawler-commons Highest Vendor pom name Crawler-commons High Product pom groupid github.crawler-commons Low Product pom artifactid crawler-commons Highest Product pom description crawler-commons is a set of reusable Java components that implement functionality common to any web crawler. Low Product pom url crawler-commons/crawler-commons High Product file name crawler-commons High Product pom organization url http://github.com/crawler-commons Low Product pom name Crawler-commons High Product pom organization name Crawler-Commons Low Version file version 0.10 Highest Version pom version 0.10 Highest
maven: com.github.crawler-commons:crawler-commons:0.10 Confidence :High cxf-rt-core-2.5.2.jarDescription:
Apache CXF Runtime Core File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-rt-core-2.5.2.jarMD5: d1af5f0f841641cd336bcd570da3cbbfSHA1: c33b3671b7dd939d7dfabe22232afd7314b97479SHA256: 9e60be8bd47fb45e833c241b5f610a672b35f46dd3f07c983f584ca88b36f0ea
Evidence Type Source Name Value Confidence Vendor file name cxf-rt-core High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://cxf.apache.org Highest Vendor pom description Apache CXF Runtime Core Medium Vendor pom parent-artifactid cxf-parent Low Vendor pom artifactid cxf-rt-core Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom name Apache CXF Runtime Core High Vendor pom parent-groupid org.apache.cxf Medium Vendor pom groupid apache.cxf Highest Product pom groupid apache.cxf Low Product file name cxf-rt-core High Product Manifest Implementation-Title Apache CXF Runtime Core High Product Manifest specification-title Apache CXF Runtime Core Medium Product pom artifactid cxf-rt-core Highest Product pom description Apache CXF Runtime Core Medium Product pom parent-groupid org.apache.cxf Low Product pom url http://cxf.apache.org Medium Product pom name Apache CXF Runtime Core High Product pom parent-artifactid cxf-parent Medium Version file version 2.5.2 Highest Version pom version 2.5.2 Highest Version Manifest Implementation-Version 2.5.2 High
Related Dependencies cxf-api-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-api-2.5.2.jar MD5: 174f0f6ab864d227b795e166f02cd357 SHA1: 2252d3766ca74d316d9aff9b7a53d5cc2ae8097f SHA256: 67fcc56ac10bfd75796ee39c7a7c9a06acda09a45d0f23c8a0b212013435c53b cpe: cpe:/a:apache:cxf:2.5.2 cxf-rt-bindings-xml-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-rt-bindings-xml-2.5.2.jar MD5: 0ac67325a99091fd40220ff4d100cfeb SHA1: 66495011e37e4ef7875ed375bea46ae26aa30f27 SHA256: f1c86937119dabb8318bd22092baf3c38292625e664516f728ad3a180dfcfd88 cpe: cpe:/a:apache:cxf:2.5.2 cxf-rt-transports-common-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-rt-transports-common-2.5.2.jar MD5: e25975b9cc89e5ba517c4e782fe128ed SHA1: 7eeb2e19293c42b196884413ff0c033fa203d7bb SHA256: 1da53c1850a1f20b225423f7643582c6fd418da1e3402ca1471e5a36b39e98b7 cpe: cpe:/a:apache:cxf:2.5.2 cxf-rt-transports-http-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-rt-transports-http-2.5.2.jar MD5: a2162c30cf36836bb4fb630e6c1c327f SHA1: a8a496c67e7001d5d1df34508773e2c30ef88e8e SHA256: 4a804d62917e07f8d6eacda102c3725a39baabdb3f843eeb71bc5f6abea31ed3 cpe: cpe:/a:apache:cxf:2.5.2 cxf-common-utilities-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-common-utilities-2.5.2.jar MD5: 37dd79b27668056632c753438da814be SHA1: f0f0821cc2a99654b1a96aa77d1a8a1968ec5077 SHA256: 36aaca08d31792bf2fe1eb357fcc9a677bfa3bf588df2bc1dcc274c0146e341f cpe: cpe:/a:apache:cxf:2.5.2 cxf-rt-frontend-jaxrs-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/cxf-rt-frontend-jaxrs-2.5.2.jar MD5: ee9f67f9444830c8054e085907c87b18 SHA1: 77bb25fed731823d75b7aa40f9468cb9d474ccf5 SHA256: 822265f5541699619f559e239ba91b7da265d4bcec28afd47de48de0c27e73fb cpe: cpe:/a:apache:cxf:2.5.2 Published Vulnerabilities CVE-2012-2378 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-264 Permissions, Privileges, and Access Controls
Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies. Vulnerable Software & Versions: (show all )
CVE-2012-2379 suppress
Severity:High CVSS Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors. Vulnerable Software & Versions: (show all )
CVE-2012-3451 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-20 Improper Input Validation
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body. Vulnerable Software & Versions: (show all )
CVE-2012-5575 suppress
Severity:Medium CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N) CWE: CWE-310 Cryptographic Issues
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack." Vulnerable Software & Versions: (show all )
CVE-2012-5633 suppress
Severity:Medium CVSS Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N) CWE: CWE-287 Improper Authentication
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request. Vulnerable Software & Versions: (show all )
CVE-2012-5786 suppress
Severity:Medium CVSS Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N) CWE: CWE-20 Improper Input Validation
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. Vulnerable Software & Versions:
CVE-2013-0239 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-287 Improper Authentication
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element. Vulnerable Software & Versions: (show all )
CVE-2013-2160 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors. Vulnerable Software & Versions: (show all )
CVE-2014-0034 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-20 Improper Input Validation
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token. Vulnerable Software & Versions: (show all )
CVE-2014-0035 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-310 Cryptographic Issues
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. Vulnerable Software & Versions: (show all )
CVE-2014-0109 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error. Vulnerable Software & Versions: (show all )
CVE-2014-0110 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message. Vulnerable Software & Versions: (show all )
CVE-2014-3584 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service. Vulnerable Software & Versions: (show all )
CVE-2015-5253 suppress
Severity:Medium CVSS Score: 4.0 (AV:N/AC:L/Au:S/C:N/I:P/A:N) CWE: CWE-264 Permissions, Privileges, and Access Controls
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack." Vulnerable Software & Versions: (show all )
CVE-2016-6812 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client. Vulnerable Software & Versions: (show all )
CVE-2016-8739 suppress
Severity:High CVSS Score: 7.8 (AV:N/AC:L/Au:N/C:C/I:N/A:N) CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk. Vulnerable Software & Versions: (show all )
CVE-2017-3156 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-361 7PK - Time and State
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks. Vulnerable Software & Versions: (show all )
CVE-2017-5656 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-384 Session Fixation
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user. Vulnerable Software & Versions: (show all )
CVE-2018-8039 suppress
Severity:Medium CVSS Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) CWE: CWE-254 7PK - Security Features
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks. Vulnerable Software & Versions: (show all )
dom4j-1.6.1.jarDescription:
dom4j: the flexible XML framework for Java File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/dom4j-1.6.1.jarMD5: 4d8f51d3fe3900efc6e395be48030d6dSHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94SHA256: 593552ffea3c5823c6602478b5002a7c525fd904a3c44f1abe4065c22edfac73
Evidence Type Source Name Value Confidence Vendor Manifest extension-name dom4j Medium Vendor pom description dom4j: the flexible XML framework for Java Medium Vendor file name dom4j High Vendor pom url http://dom4j.org Highest Vendor pom artifactid dom4j Low Vendor pom groupid zenframework.z8.dependencies.commons Highest Vendor Manifest Implementation-Vendor MetaStuff Ltd. High Vendor Manifest specification-vendor MetaStuff Ltd. Low Vendor pom organization name MetaStuff Ltd. High Vendor pom organization url http://sourceforge.net/projects/dom4j Medium Vendor pom artifactid dom4j-1.6.1 Low Vendor pom name Zenframework Z8 Dependencies - Commons - dom4j-1.6.1 High Vendor pom name dom4j High Vendor jar package name dom4j Low Vendor pom parent-groupid org.zenframework.z8.dependencies Medium Vendor central groupid org.zenframework.z8.dependencies.commons High Vendor pom parent-artifactid z8-dependencies Low Vendor pom groupid dom4j Highest Vendor central groupid dom4j High Product Manifest extension-name dom4j Medium Product Manifest Implementation-Title org.dom4j High Product pom description dom4j: the flexible XML framework for Java Medium Product pom organization name MetaStuff Ltd. Low Product pom artifactid dom4j Highest Product file name dom4j High Product pom artifactid dom4j-1.6.1 Highest Product central artifactid dom4j-1.6.1 High Product pom organization url http://sourceforge.net/projects/dom4j Low Product pom url http://dom4j.org Medium Product pom groupid dom4j Low Product central artifactid dom4j High Product Manifest specification-title dom4j : XML framework for Java Medium Product pom groupid zenframework.z8.dependencies.commons Low Product pom parent-groupid org.zenframework.z8.dependencies Low Product pom parent-artifactid z8-dependencies Medium Product pom name Zenframework Z8 Dependencies - Commons - dom4j-1.6.1 High Product pom name dom4j High Version file version 1.6.1 Highest Version Manifest Implementation-Version 1.6.1 High
forbiddenapis-2.2.jarDescription:
Allows to parse Java byte code to find invocations of method/class/field signatures and fail build (Apache Ant, Apache Maven, Gradle, or CLI) License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/forbiddenapis-2.2.jar
MD5: 1728891f75c9139cad3968aa92d1e82e
SHA1: 8a689543e4d7267398d803be1ff87a77b5cbe60b
SHA256: 255f4193eb4a635cf07ea3c08a28a6d203e90a13fd2b95d3a0c90bf89184f207
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor de.thetaphi High Vendor pom url policeman-tools/forbidden-apis Highest Vendor jar package name de Low Vendor pom artifactid forbiddenapis Low Vendor jar package name thetaphi Low Vendor jar package name forbiddenapis Low Vendor pom name Policeman's Forbidden API Checker High Vendor file name forbiddenapis High Vendor pom groupid de.thetaphi Highest Vendor central groupid de.thetaphi Highest Vendor pom description Allows to parse Java byte code to find invocations of method/class/field signatures and fail build (Apache Ant, Apache Maven, Gradle, or CLI) Low Product pom artifactid forbiddenapis Highest Product pom url policeman-tools/forbidden-apis High Product jar package name thetaphi Low Product jar package name forbiddenapis Low Product pom name Policeman's Forbidden API Checker High Product file name forbiddenapis High Product Manifest Implementation-Title forbiddenapis High Product pom groupid de.thetaphi Low Product pom description Allows to parse Java byte code to find invocations of method/class/field signatures and fail build (Apache Ant, Apache Maven, Gradle, or CLI) Low Product central artifactid forbiddenapis Highest Version file version 2.2 Highest Version Manifest Implementation-Version 2.2 High Version pom version 2.2 Highest Version central version 2.2 Highest
geronimo-javamail_1.4_spec-1.7.1.jarDescription:
Javamail 1.4 Specification License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/geronimo-javamail_1.4_spec-1.7.1.jar
MD5: f3b9d8c9a79eefdc0ebe07c34612646d
SHA1: 43ad4090b1a07a11c82ac40c01fc4e2fbad20013
SHA256: 6f1e85d9c66135f5a9dbc9f78cbf8132e52f8a85884d618ccf0dbe9344c5a330
Evidence Type Source Name Value Confidence Vendor pom artifactid geronimo-javamail_1.4_spec Low Vendor pom groupid apache.geronimo.specs Highest Vendor pom parent-artifactid genesis-java5-flava Low Vendor pom parent-groupid org.apache.geronimo.genesis Medium Vendor pom description Javamail 1.4 Specification Medium Vendor pom name JavaMail 1.4 High Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-javamail_1.4_spec;singleton=true Medium Vendor Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-javamail_1.4_spec/1.7.1 Low Vendor file name geronimo-javamail_1.4_spec-1.7.1 High Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor manifest Bundle-Description Javamail 1.4 Specification Medium Vendor pom url http://geronimo.apache.org/maven/${siteId}/${version} Highest Product Manifest Bundle-Name JavaMail 1.4 Medium Product pom description Javamail 1.4 Specification Medium Product pom name JavaMail 1.4 High Product pom url http://geronimo.apache.org/maven/${siteId}/${version} Medium Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-javamail_1.4_spec;singleton=true Medium Product Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-javamail_1.4_spec/1.7.1 Low Product file name geronimo-javamail_1.4_spec-1.7.1 High Product Manifest specification-title JSR-919 Javamail API 1.4 Medium Product pom artifactid geronimo-javamail_1.4_spec Highest Product manifest Bundle-Description Javamail 1.4 Specification Medium Product Manifest Implementation-Title JavaMail 1.4 High Product pom groupid apache.geronimo.specs Low Product pom parent-groupid org.apache.geronimo.genesis Low Product pom parent-artifactid genesis-java5-flava Medium Version Manifest Implementation-Version 1.7.1 High Version pom version 1.7.1 Highest
maven: org.apache.geronimo.specs:geronimo-javamail_1.4_spec:1.7.1 Confidence :Highcpe: cpe:/a:sun:javamail:1.7.1 Confidence :Low suppress gora-core-0.8.jarDescription:
The Apache Gora open source framework provides an in-memory data model and
persistence for big data. Gora supports persisting to column stores, key value stores,
document stores and RDBMSs, and analyzing the data with extensive Apache Hadoop MapReduce
support. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/gora-core-0.8.jar
MD5: 236629a938c1bfbce53fad83bd61bf2e
SHA1: ed404506b8ea1e8e3fefbe47a82d9fc57cf8cd7a
SHA256: 6ef24871aeb1ce2d7c619b7950c9c8185b3361763cea0ff3840a535612d7b926
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.apache.gora Medium Vendor pom groupid apache.gora Highest Vendor pom url http://gora.apache.org Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid gora-core Low Vendor pom organization url http://www.apache.org/ Medium Vendor pom description The Apache Gora open source framework provides an in-memory data model and persistence for big data. Gora supports persisting to column stores, key value stores, document stores and RDBMSs, and analyzing the data with extensive Apache Hadoop MapReduce support. Low Vendor pom parent-groupid org.apache.gora Medium Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom name Apache Gora :: Core High Vendor pom parent-artifactid gora Low Vendor Manifest bundle-symbolicname gora-core Medium Vendor file name gora-core High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor manifest Bundle-Description The Apache Gora open source framework provides an in-memory data model and persistence for big data. Gora supports persisting to column stores, key value stores, document stores and RDBMSs, and analyzing the data with extensive Apache Hadoop MapReduce support. Low Product pom organization name The Apache Software Foundation Low Product pom organization url http://www.apache.org/ Low Product Manifest Bundle-Name Apache Gora :: Core Medium Product pom description The Apache Gora open source framework provides an in-memory data model and persistence for big data. Gora supports persisting to column stores, key value stores, document stores and RDBMSs, and analyzing the data with extensive Apache Hadoop MapReduce support. Low Product Manifest specification-title Apache Gora :: Core Medium Product Manifest Implementation-Title Apache Gora :: Core High Product pom parent-groupid org.apache.gora Low Product pom parent-artifactid gora Medium Product pom groupid apache.gora Low Product Manifest bundle-docurl http://www.apache.org/ Low Product pom name Apache Gora :: Core High Product Manifest bundle-symbolicname gora-core Medium Product pom artifactid gora-core Highest Product file name gora-core High Product pom url http://gora.apache.org Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product manifest Bundle-Description The Apache Gora open source framework provides an in-memory data model and persistence for big data. Gora supports persisting to column stores, key value stores, document stores and RDBMSs, and analyzing the data with extensive Apache Hadoop MapReduce support. Low Version Manifest Implementation-Version 0.8 High Version file version 0.8 Highest Version pom version 0.8 Highest
Related Dependencies gora-compiler-cli-0.8.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/gora-compiler-cli-0.8.jar MD5: fb7b70ce24144da16dbfa5f299510c8d SHA1: 3d49d7c75c42542a4972213fe9a8f31667b8065b SHA256: 233ae8274adcd17e1a5369c7bfcebf2cd146fa3095e737046f70bd796f69f01d gora-compiler-0.8.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/gora-compiler-0.8.jar MD5: b06411c78c43a0ea01a884723b96bd19 SHA1: 1a91642609f4d205633d4666c7ceb487f5f075b2 SHA256: 4f53cf4ed0bce53d3a5b3d572d31ac61da679ac3153c022f7a5195f2e9ac6f9f cpe: cpe:/a:apache:hadoop:0.8 Confidence :Low suppress maven: org.apache.gora:gora-core:0.8 Confidence :High Published Vulnerabilities CVE-2012-4449 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack. Vulnerable Software & Versions: (show all )
CVE-2016-5001 suppress
Severity:Low CVSS Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token. Vulnerable Software & Versions: (show all )
CVE-2017-3161 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. Vulnerable Software & Versions:
CVE-2017-3162 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0. Vulnerable Software & Versions:
guava-14.0.1.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has two code dependencies - javax.annotation
per the JSR-305 spec and javax.inject per the JSR-330 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/guava-14.0.1.jar
MD5: 58553f87d83b9f8ec74bd3529083ee2f
SHA1: 69e12f4c6aeac392555f1ea86fab82b5e5e31ad4
SHA256: d69df3331840605ef0e5fe4add60f2d28e870e3820937ea29f713d2035d9ab97
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has two code dependencies - javax.annotation per the JSR-305 spec and javax.inject per the JSR-330 spec. Low Vendor file name guava High Vendor pom artifactid guava Low Vendor pom parent-artifactid guava-parent Low Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has two code dependencies - javax.annotation per the JSR-305 spec and javax.inject per the JSR-330 spec. Low Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-groupid com.google.guava Medium Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom groupid google.guava Highest Product pom groupid google.guava Low Product manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has two code dependencies - javax.annotation per the JSR-305 spec and javax.inject per the JSR-330 spec. Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product file name guava High Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has two code dependencies - javax.annotation per the JSR-305 spec and javax.inject per the JSR-330 spec. Low Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Product pom parent-artifactid guava-parent Medium Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Low Version file version 14.0.1 Highest Version pom version 14.0.1 Highest
maven: com.google.guava:guava:14.0.1 Confidence :High guice-3.0.jarDescription:
Guice is a lightweight dependency injection framework for Java 5 and above License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/guice-3.0.jar
MD5: ca1c7ba366884cfcd2cfb48d2395c400
SHA1: 9d84f15fe35e2c716a02979fb62f50a29f38aefa
SHA256: 1a59d0421ffd355cc0b70b42df1c2e9af744c8a2d0c92da379f5fca2f07f1d22
Evidence Type Source Name Value Confidence Vendor central groupid com.google.inject Highest Vendor jar package name internal Low Vendor manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium Vendor file name guice High Vendor Manifest bundle-symbolicname com.google.inject Medium Vendor jar package name google Low Vendor jar package name inject Low Vendor pom parent-groupid com.google.inject Medium Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor pom name Google Guice - Core Library High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor pom groupid google.inject Highest Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Vendor pom artifactid guice Low Vendor pom parent-artifactid guice-parent Low Product jar package name internal Low Product pom groupid google.inject Low Product manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium Product file name guice High Product pom parent-groupid com.google.inject Low Product Manifest bundle-symbolicname com.google.inject Medium Product Manifest Bundle-Name guice Medium Product jar package name inject Low Product pom artifactid guice Highest Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product pom name Google Guice - Core Library High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product central artifactid guice Highest Product pom parent-artifactid guice-parent Medium Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Version file version 3.0 Highest Version pom version 3.0 Highest Version central version 3.0 Highest
guice-servlet-3.0.jarDescription:
Guice is a lightweight dependency injection framework for Java 5 and above License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/guice-servlet-3.0.jar
MD5: c9f66a5f6a0d840d9057b30853f25b85
SHA1: 610cde0e8da5a8b7d8efb8f0b8987466ffebaaf9
SHA256: 9e72a4b8582888d53c2f4297e93276a3c14c82880124490f2da7b16a9df1c618
Evidence Type Source Name Value Confidence Vendor pom name Google Guice - Extensions - Servlet High Vendor pom groupid google.inject.extensions Highest Vendor pom parent-artifactid extensions-parent Low Vendor manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium Vendor jar package name google Low Vendor file name guice-servlet High Vendor jar package name inject Low Vendor pom parent-groupid com.google.inject.extensions Medium Vendor Manifest bundle-symbolicname com.google.inject.servlet Medium Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor jar package name servlet Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor central groupid com.google.inject.extensions Highest Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Vendor pom artifactid guice-servlet Low Product pom name Google Guice - Extensions - Servlet High Product pom artifactid guice-servlet Highest Product central artifactid guice-servlet Highest Product pom parent-artifactid extensions-parent Medium Product manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium Product file name guice-servlet High Product Manifest Bundle-Name guice-servlet Medium Product jar package name inject Low Product Manifest bundle-symbolicname com.google.inject.servlet Medium Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product jar package name servlet Low Product pom groupid google.inject.extensions Low Product pom parent-groupid com.google.inject.extensions Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Version file version 3.0 Highest Version pom version 3.0 Highest Version central version 3.0 Highest
h2-1.4.180.jarDescription:
H2 Database Engine License:
MPL 2.0, and EPL 1.0: http://h2database.com/html/license.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/h2-1.4.180.jar
MD5: cfed4ec6ae8fced8e135fe87699ac45f
SHA1: 155fd1e4926093df7b97b09a6954ab9964f6a54b
SHA256: 16428fd1e6a3e5baa8067c1c2e777e1e99af68c6ef3ff7fbbf1938937a048a82
Evidence Type Source Name Value Confidence Vendor pom groupid h2database Highest Vendor Manifest implementation-url http://www.h2database.com Low Vendor pom description H2 Database Engine Medium Vendor Manifest bundle-symbolicname org.h2 Medium Vendor central groupid com.h2database Highest Vendor pom name H2 Database Engine High Vendor pom artifactid h2 Low Vendor pom url http://www.h2database.com Highest Vendor jar package name h2 Low Vendor file name h2 High Product Manifest implementation-url http://www.h2database.com Low Product pom description H2 Database Engine Medium Product Manifest Implementation-Title H2 Database Engine High Product pom groupid h2database Low Product Manifest bundle-symbolicname org.h2 Medium Product central artifactid h2 Highest Product pom url http://www.h2database.com Medium Product pom artifactid h2 Highest Product pom name H2 Database Engine High Product Manifest Bundle-Name H2 Database Engine Medium Product file name h2 High Version central version 1.4.180 Highest Version file version 1.4.180 Highest Version pom version 1.4.180 Highest Version Manifest Implementation-Version 1.4.180 High
hadoop-mapreduce-client-core-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-mapreduce-client-core-2.5.2.jarMD5: aa9b658b762eb27611b0181d0c42f752SHA1: a7168fb50e32ee16e926e28ba0459580c36b2548SHA256: 334d3dfddd47be4d5dfc177ca2d72e9289130980ddb0ca348edeaf6cde6eae09
Evidence Type Source Name Value Confidence Vendor jar package name hadoop Low Vendor file name hadoop-mapreduce-client-core High Vendor pom parent-groupid org.apache.hadoop Medium Vendor pom parent-artifactid hadoop-mapreduce-client Low Vendor pom name hadoop-mapreduce-client-core High Vendor pom groupid apache.hadoop Highest Vendor jar package name apache Low Vendor pom artifactid hadoop-mapreduce-client-core Low Vendor jar package name mapreduce Low Product jar package name hadoop Low Product file name hadoop-mapreduce-client-core High Product pom artifactid hadoop-mapreduce-client-core Highest Product pom parent-artifactid hadoop-mapreduce-client Medium Product pom parent-groupid org.apache.hadoop Low Product pom name hadoop-mapreduce-client-core High Product pom groupid apache.hadoop Low Product jar package name mapreduce Low Version file version 2.5.2 Highest Version pom version 2.5.2 Highest
Related Dependencies hadoop-yarn-server-nodemanager-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-yarn-server-nodemanager-2.5.2.jar MD5: 4feceee7759563511f386a76b781ee7d SHA1: 36f02e92a13ccfd489a0e24df8ad5aa7f14ebee4 SHA256: 39b934ee9b148797490300b53a38cf62d9a2c2f46e97dae8c3420f2dd14d75a4 hadoop-yarn-api-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-yarn-api-2.5.2.jar MD5: d30fee09a590f6ce3b6652e16fba4426 SHA1: ed56ef51f79bec95a258681d38a61dbc1713724e SHA256: e4d30b63fc03e5854814e44c4c35aece693b3b142ff55347654d93d7de0499ce hadoop-common-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-common-2.5.2.jar MD5: a673d993c01c194f40414dfa4543af71 SHA1: d4a60ca549b1f9064578a4ac0a2340624e2440bd SHA256: cb0735c98aaf1bfa5a2d925b4e1bdf9083cc21b8ee78267036ab61f608232566 hadoop-yarn-client-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-yarn-client-2.5.2.jar MD5: bca2de34b676e57402903dc1329a0a84 SHA1: f62818f180f489d18607474ddeb7f0072c00f87d SHA256: 564562295d8d82bb67b8f51403ae9749fcbb8322fac5ab6b479903137c87b56d hadoop-auth-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-auth-2.5.2.jar MD5: 9c6e4b8acdbdb9ed40d5f00b8083d571 SHA1: e637ea131afd368853034649c48b36d032aead52 SHA256: 2a6ddf4e0848f475046e4e09422b2062041d03480828454f6d344fa3cb7b5475 hadoop-annotations-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-annotations-2.5.2.jar MD5: 334e5c7e6cb1d7b01ee0a68bd18dfc3f SHA1: 7bf4cdb8c35cf4dd761726c02b7677a169162f0a SHA256: b2b30f660ba3a5419cf791ca4210497bc41a5af317cae7ce51f3a34201c8cc2a hadoop-mapreduce-client-shuffle-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-mapreduce-client-shuffle-2.5.2.jar MD5: bf0d94d6a79fceef8aac55e5d424aa2e SHA1: 01c2c8ada2300a9fca6967f1de0300e1b5d86a4a SHA256: b4cf481859504d18d0dd8cdd37c4000435c2faaefc2fd4b05553c0e84abca0fe hadoop-yarn-server-common-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-yarn-server-common-2.5.2.jar MD5: 1508e51b29dead2fb1d9a20185715ce9 SHA1: 0f2203b3e8afeb600b899bfd944e1554adf55902 SHA256: b50d21cab7efb5948f655f13920f3f3aef469930275d429671eb989deb4f312f hadoop-hdfs-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-hdfs-2.5.2.jar MD5: 17a21b4e46b0b9ec84859c6a903e200c SHA1: 7c555a887341e8abd95cec5815bb8d920db74969 SHA256: 7bf1f8c1fe5abe3938853025d76e13ca7ad7ae7a926174fdb08ed4d92ea1e8a4 hadoop-mapreduce-client-jobclient-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-mapreduce-client-jobclient-2.5.2.jar MD5: 1218d1f0a8fd13aa1141abd21141b147 SHA1: a4dc84d6dfab278f58d729073ae9d93ac1e7b2f9 SHA256: 822d6a5a32a60036cade971c718a7488b565975eb9e8f0b5b76c8925b37980c3 hadoop-mapreduce-client-common-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-mapreduce-client-common-2.5.2.jar MD5: e7e672f2ae91f884a20307ef5268a276 SHA1: 4c643ab26741daf6d570bab6008b95c8b2562a8f SHA256: 2944a9a1ba8e9017e8597dbe88fd98d32d6848f07584f4779f45133a55711dcf hadoop-yarn-common-2.5.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hadoop-yarn-common-2.5.2.jar MD5: dd52083665b3be448e26afa97c52fe27 SHA1: 8bc52cc38b68820e9fc4831e3942802f6034404e SHA256: b2fb425afa3d13e015fc242c3944e87d4f72c4b6396ec868b6cdb0851aa51879 maven: org.apache.hadoop:hadoop-mapreduce-client-core:2.5.2 Confidence :Highcpe: cpe:/a:apache:hadoop:2.5.2 Confidence :Low suppress Published Vulnerabilities CVE-2016-5001 suppress
Severity:Low CVSS Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token. Vulnerable Software & Versions: (show all )
CVE-2017-3161 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. Vulnerable Software & Versions:
CVE-2017-3162 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0. Vulnerable Software & Versions:
hamcrest-core-1.3.jarDescription:
This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hamcrest-core-1.3.jarMD5: 6393363b47ddcbba82321110c3e07519SHA1: 42a25dc3219429f0e5d060061f71acb49bf010a0SHA256: 66fdef91e9739348df7a096aa384a5685f4e875584cce89386a7a47251c4d8e9
Evidence Type Source Name Value Confidence Vendor file name hamcrest-core High Vendor jar package name hamcrest Low Vendor Manifest built-date 2012-07-09 19:49:34 Low Vendor Manifest Implementation-Vendor hamcrest.org High Vendor pom parent-groupid org.hamcrest Medium Vendor pom parent-artifactid hamcrest-parent Low Vendor pom groupid hamcrest Highest Vendor pom artifactid hamcrest-core Low Vendor pom description This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations. Low Vendor pom name Hamcrest Core High Vendor central groupid org.hamcrest Highest Product file name hamcrest-core High Product Manifest Implementation-Title hamcrest-core High Product Manifest built-date 2012-07-09 19:49:34 Low Product pom groupid hamcrest Low Product pom parent-artifactid hamcrest-parent Medium Product central artifactid hamcrest-core Highest Product pom parent-groupid org.hamcrest Low Product pom artifactid hamcrest-core Highest Product pom description This is the core API of hamcrest matcher framework to be used by third-party framework providers. This includes the a foundation set of matcher implementations for common operations. Low Product pom name Hamcrest Core High Version central version 1.3 Highest Version file version 1.3 Highest Version pom version 1.3 Highest Version Manifest Implementation-Version 1.3 High
Related Dependencies hamcrest-core-1.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/hamcrest-core-1.3.jar MD5: 6393363b47ddcbba82321110c3e07519 SHA1: 42a25dc3219429f0e5d060061f71acb49bf010a0 SHA256: 66fdef91e9739348df7a096aa384a5685f4e875584cce89386a7a47251c4d8e9 hsqldb-2.2.8.jarDescription:
HSQLDB - Lightweight 100% Java SQL Database Engine License:
HSQLDB License, a BSD open source license: http://hsqldb.org/web/hsqlLicense.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/hsqldb-2.2.8.jar
MD5: 92dfcd0b5d8b5d301c9350f69c3337fc
SHA1: 8231a3ff71ba5889f9e2d01ce13503cbdd4038e9
SHA256: 364649da28ee95a43f3168d6f211fc1ea5f76946655e80aed1584e4058597f3d
Evidence Type Source Name Value Confidence Vendor pom organization url http://hsqldb.org Medium Vendor Manifest build-vendor blaine Medium Vendor pom artifactid hsqldb Low Vendor central groupid org.hsqldb Highest Vendor pom url http://hsqldb.org Highest Vendor file name hsqldb High Vendor Manifest specification-vendor The HSQL Development Group Low Vendor pom organization name The HSQL Development Group High Vendor manifest Bundle-Description HyperSQL Lightweight 100% Java SQL Database Engine Medium Vendor Manifest Implementation-Vendor The HSQL Development Group High Vendor pom description HSQLDB - Lightweight 100% Java SQL Database Engine Medium Vendor pom groupid hsqldb Highest Vendor pom name HyperSQL Database High Vendor Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Vendor Manifest originally-created-by 1.6.0_30-b12 (Sun Microsystems Inc.) Low Vendor jar package name hsqldb Low Product pom organization url http://hsqldb.org Low Product pom organization name The HSQL Development Group Low Product file name hsqldb High Product central artifactid hsqldb Highest Product pom groupid hsqldb Low Product manifest Bundle-Description HyperSQL Lightweight 100% Java SQL Database Engine Medium Product pom url http://hsqldb.org Medium Product Manifest Bundle-Name HSQLDB Medium Product pom artifactid hsqldb Highest Product pom description HSQLDB - Lightweight 100% Java SQL Database Engine Medium Product pom name HyperSQL Database High Product Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Product Manifest originally-created-by 1.6.0_30-b12 (Sun Microsystems Inc.) Low Product Manifest Implementation-Title Standard runtime High Product Manifest specification-title HSQLDB Medium Version file version 2.2.8 Highest Version Manifest Implementation-Version 2.2.8 High Version pom version 2.2.8 Highest Version central version 2.2.8 Highest
httpclient-4.2.6.jarDescription:
HttpComponents Client
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/httpclient-4.2.6.jarMD5: 7bae53a30550dd3eb62db72ab08fcd94SHA1: e4ca30a6a3a075053a61c6fc850d2432dc012ba7SHA256: 362e9324ee7c697e21279e20077b52737ddef3f1b2c1a7abe5ad34b465145550
Evidence Type Source Name Value Confidence Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-artifactid httpcomponents-client Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor pom artifactid httpclient Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom description
HttpComponents Client
Medium Vendor file name httpclient High Vendor Manifest implementation-build tags/4.2.6-RC2/httpclient@r1520084; 2013-09-04 20:15:00+0200 Low Vendor pom name Apache HttpClient High Product Manifest Implementation-Title HttpComponents Apache HttpClient High Product pom url http://hc.apache.org/httpcomponents-client Medium Product pom artifactid httpclient Highest Product Manifest specification-title HttpComponents Apache HttpClient Medium Product pom parent-artifactid httpcomponents-client Medium Product pom groupid apache.httpcomponents Low Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom parent-groupid org.apache.httpcomponents Low Product pom description
HttpComponents Client
Medium Product file name httpclient High Product Manifest implementation-build tags/4.2.6-RC2/httpclient@r1520084; 2013-09-04 20:15:00+0200 Low Product pom name Apache HttpClient High Version file version 4.2.6 Highest Version Manifest Implementation-Version 4.2.6 High Version pom version 4.2.6 Highest
Related Dependencies httpclient-4.2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/httpclient-4.2.6.jar MD5: 7bae53a30550dd3eb62db72ab08fcd94 SHA1: e4ca30a6a3a075053a61c6fc850d2432dc012ba7 SHA256: 362e9324ee7c697e21279e20077b52737ddef3f1b2c1a7abe5ad34b465145550 httpclient-4.2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/httpclient-4.2.6.jar MD5: 7bae53a30550dd3eb62db72ab08fcd94 SHA1: e4ca30a6a3a075053a61c6fc850d2432dc012ba7 SHA256: 362e9324ee7c697e21279e20077b52737ddef3f1b2c1a7abe5ad34b465145550 cpe: cpe:/a:apache:httpclient:4.2.6 Confidence :Low suppress maven: org.apache.httpcomponents:httpclient:4.2.6 Confidence :High httpcore-4.2.5.jarDescription:
HttpComponents Core (blocking I/O)
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/httpcore-4.2.5.jarMD5: 7e23d35d533b24c1f385724e8b5ba623SHA1: 472f0f5f8dba5d1962cb9d7739feed739a31c30dSHA256: e5e82da4cc66c8d917bbf743e3c0752efe8522735e7fc9dbddb65bccea81cfe9
Evidence Type Source Name Value Confidence Vendor pom artifactid httpcore Low Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-artifactid httpcomponents-core Low Vendor file name httpcore High Vendor pom description
HttpComponents Core (blocking I/O)
Medium Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom name Apache HttpCore High Vendor Manifest implementation-build tags/4.2.5-RC2/httpcore@r1506585; 2013-07-29 17:13:49+0200 Low Product file name httpcore High Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product pom parent-artifactid httpcomponents-core Medium Product pom description
HttpComponents Core (blocking I/O)
Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product pom groupid apache.httpcomponents Low Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product pom parent-groupid org.apache.httpcomponents Low Product pom artifactid httpcore Highest Product pom name Apache HttpCore High Product Manifest implementation-build tags/4.2.5-RC2/httpcore@r1506585; 2013-07-29 17:13:49+0200 Low Version Manifest Implementation-Version 4.2.5 High Version file version 4.2.5 Highest Version pom version 4.2.5 Highest
Related Dependencies httpcore-4.2.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/httpcore-4.2.5.jar MD5: 7e23d35d533b24c1f385724e8b5ba623 SHA1: 472f0f5f8dba5d1962cb9d7739feed739a31c30d SHA256: e5e82da4cc66c8d917bbf743e3c0752efe8522735e7fc9dbddb65bccea81cfe9 httpcore-4.2.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/httpcore-4.2.5.jar MD5: 7e23d35d533b24c1f385724e8b5ba623 SHA1: 472f0f5f8dba5d1962cb9d7739feed739a31c30d SHA256: e5e82da4cc66c8d917bbf743e3c0752efe8522735e7fc9dbddb65bccea81cfe9 maven: org.apache.httpcomponents:httpcore:4.2.5 Confidence :High httpmime-4.2.6.jarDescription:
HttpComponents HttpClient - MIME coded entities
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/httpmime-4.2.6.jarMD5: 291ec6eac9dfb76f2b8c4f1b647b9a21SHA1: 270386011895bc6c7ee6496fd87511d6a98093c1SHA256: d2dd4857b05d2050073e265987d8a63726fd42b979bb1f757dfa50b6c2d78be8
Evidence Type Source Name Value Confidence Vendor pom groupid apache.httpcomponents Highest Vendor pom parent-artifactid httpcomponents-client Low Vendor Manifest implementation-build tags/4.2.6-RC2/httpmime@r1520084; 2013-09-04 20:15:00+0200 Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor file name httpmime High Vendor pom name Apache HttpClient Mime High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom artifactid httpmime Low Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom description
HttpComponents HttpClient - MIME coded entities
Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Product Manifest implementation-build tags/4.2.6-RC2/httpmime@r1520084; 2013-09-04 20:15:00+0200 Low Product pom parent-artifactid httpcomponents-client Medium Product Manifest Implementation-Title HttpComponents Apache HttpClient Mime High Product Manifest specification-title HttpComponents Apache HttpClient Mime Medium Product file name httpmime High Product pom artifactid httpmime Highest Product pom name Apache HttpClient Mime High Product pom groupid apache.httpcomponents Low Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom parent-groupid org.apache.httpcomponents Low Product pom description
HttpComponents HttpClient - MIME coded entities
Medium Version file version 4.2.6 Highest Version Manifest Implementation-Version 4.2.6 High Version pom version 4.2.6 Highest
Related Dependencies httpmime-4.2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/httpmime-4.2.6.jar MD5: 291ec6eac9dfb76f2b8c4f1b647b9a21 SHA1: 270386011895bc6c7ee6496fd87511d6a98093c1 SHA256: d2dd4857b05d2050073e265987d8a63726fd42b979bb1f757dfa50b6c2d78be8 httpmime-4.2.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/httpmime-4.2.6.jar MD5: 291ec6eac9dfb76f2b8c4f1b647b9a21 SHA1: 270386011895bc6c7ee6496fd87511d6a98093c1 SHA256: d2dd4857b05d2050073e265987d8a63726fd42b979bb1f757dfa50b6c2d78be8 maven: org.apache.httpcomponents:httpmime:4.2.6 Confidence :High icu4j-55.1.jarDescription:
International Component for Unicode for Java (ICU4J) is a mature, widely used Java library
providing Unicode and Globalization support
License:
ICU License: http://source.icu-project.org/repos/icu/icu/trunk/license.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/icu4j-55.1.jar
MD5: d2154c148fbd871c7ca1cf07d5d02f6f
SHA1: 670e165010677d0ae8ffaba6f3135895042b63b9
SHA256: 85c049f0b096d74d5b1b33aa4dcfde24b74a9a57ff69711b856198950989376f
Evidence Type Source Name Value Confidence Vendor file name icu4j High Vendor Manifest specification-vendor icu-project.org Low Vendor jar package name icu Low Vendor pom name ICU4J High Vendor pom groupid ibm.icu Highest Vendor manifest Bundle-Description International Components for Unicode for Java Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor central groupid com.ibm.icu Highest Vendor Manifest Implementation-Vendor-Id com.ibm Medium Vendor Manifest Implementation-Vendor IBM Corporation High Vendor jar package name ibm Low Vendor Manifest bundle-copyright Copyright 2000-2015, International Business Machines Corporation and others. All Rights Reserved. Low Vendor pom artifactid icu4j Low Vendor Manifest bundle-symbolicname com.ibm.icu Medium Vendor pom description International Component for Unicode for Java (ICU4J) is a mature, widely used Java library providing Unicode and Globalization support Low Vendor pom url http://icu-project.org/ Highest Product file name icu4j High Product Manifest Bundle-Name ICU4J Medium Product jar package name icu Low Product pom url http://icu-project.org/ Medium Product pom name ICU4J High Product manifest Bundle-Description International Components for Unicode for Java Medium Product pom artifactid icu4j Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest Implementation-Title International Components for Unicode for Java High Product pom groupid ibm.icu Low Product Manifest bundle-copyright Copyright 2000-2015, International Business Machines Corporation and others. All Rights Reserved. Low Product Manifest specification-title International Components for Unicode for Java Medium Product central artifactid icu4j Highest Product Manifest bundle-symbolicname com.ibm.icu Medium Product pom description International Component for Unicode for Java (ICU4J) is a mature, widely used Java library providing Unicode and Globalization support Low Version pom version 55.1 Highest Version central version 55.1 Highest Version Manifest Implementation-Version 55.1 High Version file version 55.1 Highest
jackson-core-2.3.0.jarDescription:
Core Jackson abstractions, basic JSON streaming API implementation
License:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.gnu.org/licenses/lgpl-2.1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-core-2.3.0.jar
MD5: 31cbd34f3afd5cac7bce4890130b4152
SHA1: 5e19d8381e01aa64c9dd47ff453e39abc441775c
SHA256: 61f84f93e3f901134d7498b50119ee01074f10d59560e45ccd3e1d48cfec493b
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.fasterxml Medium Vendor pom artifactid jackson-core Low Vendor Manifest specification-vendor FasterXML Low Vendor pom parent-artifactid oss-parent Low Vendor pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low Vendor Manifest implementation-build-date 2013-11-13 21:04:58-0800 Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium Vendor pom name Jackson-core High Vendor pom groupid fasterxml.jackson.core Highest Vendor file name jackson-core High Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest Product pom parent-groupid com.fasterxml Low Product Manifest Bundle-Name Jackson-core Medium Product pom url http://wiki.fasterxml.com/JacksonHome Medium Product pom parent-artifactid oss-parent Medium Product Manifest specification-title Jackson-core Medium Product pom groupid fasterxml.jackson.core Low Product Manifest Implementation-Title Jackson-core High Product pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low Product Manifest implementation-build-date 2013-11-13 21:04:58-0800 Low Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium Product pom name Jackson-core High Product file name jackson-core High Product pom artifactid jackson-core Highest Version pom version 2.3.0 Highest Version file version 2.3.0 Highest Version Manifest Implementation-Version 2.3.0 High
Related Dependencies jackson-annotations-2.3.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-annotations-2.3.0.jar MD5: c954fbca7d677f323d810d0fa8baead2 SHA1: f5e853a20b60758922453d56f9ae1e64af5cb3da SHA256: 0c8c3811322cc84c09a93f34436fe784a1259dd5376a90aec5a73493456f757d cpe: cpe:/a:fasterxml:jackson:2.3.0 Confidence :Low suppress maven: com.fasterxml.jackson.core:jackson-core:2.3.0 Confidence :High jackson-core-asl-1.9.13.jarDescription:
Jackson is a high-performance JSON processor (parser, generator)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-core-asl-1.9.13.jar
MD5: 319c49a4304e3fa9fe3cd8dcfc009d37
SHA1: 3c304d70f42f832e0a86d45bd437f692129299a4
SHA256: 440a9cb5ca95b215f953d3a20a6b1a10da1f09b529a9ddea5f8a4905ddab4f5a
Evidence Type Source Name Value Confidence Vendor file name jackson-core-asl High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor pom url http://jackson.codehaus.org Highest Vendor pom groupid codehaus.jackson Highest Vendor jar package name codehaus Low Vendor central groupid org.codehaus.jackson Highest Vendor pom organization url http://fasterxml.com Medium Vendor jar package name jackson Low Vendor pom organization name FasterXML High Vendor pom name Jackson High Vendor pom artifactid jackson-core-asl Low Vendor Manifest bundle-symbolicname jackson-core-asl Medium Vendor pom description Jackson is a high-performance JSON processor (parser, generator)
Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor Manifest specification-vendor http://www.ietf.org/rfc/rfc4627.txt Low Product file name jackson-core-asl High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product pom organization name FasterXML Low Product pom artifactid jackson-core-asl Highest Product Manifest Bundle-Name Jackson JSON processor Medium Product Manifest specification-title JSON - JavaScript Object Notation Medium Product pom groupid codehaus.jackson Low Product pom organization url http://fasterxml.com Low Product jar package name jackson Low Product pom name Jackson High Product pom url http://jackson.codehaus.org Medium Product Manifest bundle-symbolicname jackson-core-asl Medium Product Manifest Implementation-Title Jackson JSON processor High Product pom description Jackson is a high-performance JSON processor (parser, generator)
Medium Product central artifactid jackson-core-asl Highest Version file version 1.9.13 Highest Version central version 1.9.13 Highest Version Manifest Implementation-Version 1.9.13 High Version pom version 1.9.13 Highest
Related Dependencies jackson-xc-1.9.13.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-xc-1.9.13.jar MD5: 49f6a735bae30745dcf5ecec27090720 SHA1: e3480072bc95c202476ffa1de99ff7ee9149f29c SHA256: 2d2905fcec7d1c55b775995617685dbb03672350704d9e40b492eab5b54d0be7 maven: org.codehaus.jackson:jackson-xc:1.9.13 ✓ jackson-mapper-asl-1.9.13.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-mapper-asl-1.9.13.jar MD5: 1750f9c339352fc4b728d61b57171613 SHA1: 1ee2f2bed0e5dd29d1cb155a166e6f8d50bbddb7 SHA256: 74e7a07a76f2edbade29312a5a2ebccfa019128bc021ece3856d76197e9be0c2 maven: org.codehaus.jackson:jackson-mapper-asl:1.9.13 ✓ jackson-jaxrs-1.9.13.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-jaxrs-1.9.13.jar MD5: 8481e1904d9bfe974157a6af04b4445e SHA1: 534d72d2b9d6199dd531dfb27083dd4844082bba SHA256: 1770570a6ba5c87a4795c0aeb40ee7c5fe5e31df64ef1d4795a0d427796b84bb maven: org.codehaus.jackson:jackson-jaxrs:1.9.13 ✓ jackson-databind-2.3.0.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.gnu.org/licenses/lgpl-2.1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-databind-2.3.0.jar
MD5: 5b7a92b9d489c1d81d629d6a04ef77d8
SHA1: 76eb119e9f7769c5b124afbfa17ed0c63cab4920
SHA256: 9b789c2de23ff5a1ae1fc8193ea79e34f16d74c64c51491fbe76ca277349e694
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium Vendor pom parent-groupid com.fasterxml Medium Vendor file name jackson-databind High Vendor Manifest specification-vendor FasterXML Low Vendor pom parent-artifactid oss-parent Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low Vendor pom name jackson-databind High Vendor pom description General data-binding functionality for Jackson: works on core streaming API Medium Vendor pom artifactid jackson-databind Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest implementation-build-date 2013-11-13 21:23:47-0800 Low Vendor pom groupid fasterxml.jackson.core Highest Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest Product pom parent-groupid com.fasterxml Low Product pom artifactid jackson-databind Highest Product manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium Product Manifest Bundle-Name jackson-databind Medium Product pom url http://wiki.fasterxml.com/JacksonHome Medium Product file name jackson-databind High Product pom parent-artifactid oss-parent Medium Product pom groupid fasterxml.jackson.core Low Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low Product pom name jackson-databind High Product pom description General data-binding functionality for Jackson: works on core streaming API Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest implementation-build-date 2013-11-13 21:23:47-0800 Low Product Manifest specification-title jackson-databind Medium Version pom version 2.3.0 Highest Version file version 2.3.0 Highest Version Manifest Implementation-Version 2.3.0 High
cpe: cpe:/a:fasterxml:jackson:2.3.0 Confidence :Low suppress maven: com.fasterxml.jackson.core:jackson-databind:2.3.0 Confidence :Highcpe: cpe:/a:fasterxml:jackson-databind:2.3.0 Confidence :Highest suppress Published Vulnerabilities CVE-2017-15095 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously. Vulnerable Software & Versions: (show all )
CVE-2017-17485 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath. Vulnerable Software & Versions: (show all )
CVE-2017-7525 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. Vulnerable Software & Versions: (show all )
CVE-2018-5968 suppress
Severity:Medium CVSS Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P) CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist. Vulnerable Software & Versions: (show all )
CVE-2018-7489 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath. Vulnerable Software & Versions: (show all )
jackson-dataformat-csv-2.2.3.jarDescription:
Support for reading and writing CSV-encoded data via Jackson
abstractions.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-dataformat-csv-2.2.3.jarMD5: d22bb07e86066b2bf7880a9bba6c63f2SHA1: 33f39a39225bd6ad6ffda1ac62dee841469adfc4SHA256: 714565c3631476e6836d5d54f8b61acc2aacf498c5e880f7b4eb515d6f4163ee
Evidence Type Source Name Value Confidence Vendor pom description Support for reading and writing CSV-encoded data via Jackson
abstractions.
Medium Vendor pom groupid fasterxml.jackson.dataformat Highest Vendor jar package name jackson Low Vendor pom parent-groupid com.fasterxml Medium Vendor pom url http://wiki.fasterxml.com/JacksonExtensionCSV Highest Vendor jar package name dataformat Low Vendor pom artifactid jackson-dataformat-csv Low Vendor pom name Jackson-dataformat-CSV High Vendor file name jackson-dataformat-csv High Vendor pom parent-artifactid oss-parent Low Vendor jar package name fasterxml Low Product pom parent-groupid com.fasterxml Low Product pom description Support for reading and writing CSV-encoded data via Jackson
abstractions.
Medium Product jar package name jackson Low Product jar package name csv Low Product pom groupid fasterxml.jackson.dataformat Low Product pom parent-artifactid oss-parent Medium Product jar package name dataformat Low Product pom name Jackson-dataformat-CSV High Product file name jackson-dataformat-csv High Product pom artifactid jackson-dataformat-csv Highest Product pom url http://wiki.fasterxml.com/JacksonExtensionCSV Medium Version file version 2.2.3 Highest Version pom version 2.2.3 Highest
Related Dependencies jackson-module-jsonSchema-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-module-jsonSchema-2.2.3.jar MD5: ca27071abf8c5e3871bde94b24995016 SHA1: 239888727ae871206073952917a3e4b6b2c3f3f2 SHA256: 693db8cdc1c7148693f2098ab5a038184ee57204124fe827aea0d60760524bc6 jackson-module-jaxb-annotations-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-module-jaxb-annotations-2.2.3.jar MD5: dc38da2afab500152b23ebc6bad092e9 SHA1: 67dc02bc307443e3571c94dfba31c355c8668015 SHA256: df93db324332fa4ac3f97fca05448eef01106f5ebbb9123df73d8209f96ebbe0 jackson-dataformat-smile-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-dataformat-smile-2.2.3.jar MD5: 1bd32f0fcf7de857ff96217e64aaf325 SHA1: ec8428fa68e1db518243878a8662832c7e117d05 SHA256: 491cec696c4e7040fe8cff9b01b72b1dd213c6c6fc35fbef685c82938db945b6 jackson-dataformat-yaml-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-dataformat-yaml-2.2.3.jar MD5: 375874d17b3225e2c52679d0cb5161d3 SHA1: 0abd7b08d1df08e34d8c86fcd5a6ec08d8e5b0e7 SHA256: d6a37b0027633a8bd16b5cce616e7a8fd59c54221de74bd0cd918a43b6995085 maven: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.2.3 ✓ cpe: cpe:/a:fasterxml:jackson:2.2.3 Confidence :Low suppress maven: com.fasterxml.jackson.dataformat:jackson-dataformat-csv:2.2.3 Confidence :High jackson-dataformat-xml-2.2.3.jarDescription:
Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types like JsonGenerator, JsonParser and JsonFactory.
Some data-binding types overridden as well (ObjectMapper sub-classed as XmlMapper).
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-dataformat-xml-2.2.3.jarMD5: cc188e1f2d979160acf5eb4bbd65a1e0SHA1: 7e3bc1b0ce8074cee1e0a2c2403baee2b1034215SHA256: e1ec43c2774631cd841535dc6fc9c4ca1d4a2c9abc5684cb200fac4c388b32ac
Evidence Type Source Name Value Confidence Vendor pom groupid fasterxml.jackson.dataformat Highest Vendor jar package name jackson Low Vendor pom parent-groupid com.fasterxml Medium Vendor pom description Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low Vendor file name jackson-dataformat-xml High Vendor pom url http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Highest Vendor jar package name dataformat Low Vendor pom artifactid jackson-dataformat-xml Low Vendor pom name Jackson-dataformat-XML High Vendor pom parent-artifactid oss-parent Low Vendor jar package name fasterxml Low Product pom parent-groupid com.fasterxml Low Product pom url http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Medium Product jar package name jackson Low Product pom description Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low Product file name jackson-dataformat-xml High Product pom groupid fasterxml.jackson.dataformat Low Product pom artifactid jackson-dataformat-xml Highest Product pom parent-artifactid oss-parent Medium Product jar package name dataformat Low Product jar package name xml Low Product pom name Jackson-dataformat-XML High Version file version 2.2.3 Highest Version pom version 2.2.3 Highest
cpe: cpe:/a:fasterxml:jackson-databind:2.2.3 Confidence :Highest suppress cpe: cpe:/a:fasterxml:jackson:2.2.3 Confidence :Low suppress maven: com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.2.3 Confidence :High Published Vulnerabilities CVE-2016-3720 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors. Vulnerable Software & Versions:
CVE-2016-7051 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-918 Server-Side Request Forgery (SSRF)
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. Vulnerable Software & Versions: (show all )
CVE-2017-15095 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously. Vulnerable Software & Versions: (show all )
CVE-2017-17485 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath. Vulnerable Software & Versions: (show all )
CVE-2017-7525 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. Vulnerable Software & Versions: (show all )
jasper-runtime-5.5.23.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jasper-runtime-5.5.23.jarMD5: 00e6f385adab8441f27e75d6038ea2aeSHA1: 96ca5528a93ab47b001476b74320c644beb89ddeSHA256: 3564c35fa738e2e683af8b7ae28c4345a32e2bd97ff88498f17423f329975890
Evidence Type Source Name Value Confidence Vendor central groupid tomcat Highest Vendor pom parent-artifactid tomcat-parent Low Vendor pom artifactid jasper-runtime Low Vendor pom groupid tomcat Highest Vendor jar package name apache Low Vendor jar package name runtime Low Vendor jar package name jasper Low Vendor file name jasper-runtime High Product pom parent-artifactid tomcat-parent Medium Product central artifactid jasper-runtime Highest Product pom groupid tomcat Low Product pom artifactid jasper-runtime Highest Product jar package name runtime Low Product jar package name jasper Low Product file name jasper-runtime High Version pom version 5.5.23 Highest Version central version 5.5.23 Highest Version file version 5.5.23 Highest
Related Dependencies jasper-compiler-5.5.23.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jasper-compiler-5.5.23.jar MD5: 118a663a65385184b50cf3795f9c5318 SHA1: 6d35bd7fb8c4fbc1f5401fb3678aa976d2e4c241 SHA256: e493e53f7231f6c715341c661b95157aef3fb44bc44f82b4b1ec6d9380dc6c93 maven: tomcat:jasper-compiler:5.5.23 ✓ java-xmlbuilder-0.4.jarDescription:
XML Builder is a utility that creates simple XML documents using relatively sparse Java code License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/java-xmlbuilder-0.4.jar
MD5: 0fa474213a6a0282cd9264f6e0dd3658
SHA1: ac5962e48cdee3a0a6e1f8e00fcb594747ac5aaf
SHA256: 681e53c4ffd59fa12068803b259e3a83d43f07a47c112e748a187dee179eb31f
Evidence Type Source Name Value Confidence Vendor file name java-xmlbuilder High Vendor pom groupid jamesmurty.utils Highest Vendor pom description XML Builder is a utility that creates simple XML documents using relatively sparse Java code Medium Vendor pom name java-xmlbuilder High Vendor jar package name base64 Low Vendor pom artifactid java-xmlbuilder Low Vendor jar package name iharder Low Vendor jar package name net Low Vendor pom url http://code.google.com/p/java-xmlbuilder/ Highest Product file name java-xmlbuilder High Product pom url http://code.google.com/p/java-xmlbuilder/ Medium Product pom description XML Builder is a utility that creates simple XML documents using relatively sparse Java code Medium Product pom name java-xmlbuilder High Product jar package name base64 Low Product pom artifactid java-xmlbuilder Highest Product jar package name iharder Low Product pom groupid jamesmurty.utils Low Version file version 0.4 Highest Version pom version 0.4 Highest
maven: com.jamesmurty.utils:java-xmlbuilder:0.4 Confidence :High javassist-3.12.1.GA.jarDescription:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/javassist-3.12.1.GA.jar
MD5: 30d9d95456d43005da78d7281accccd1
SHA1: 526633327faa61aee448a519e8a4d53ec3057885
SHA256: 3f5780dacb4b28ad147100f74361bb338a45069d8034b24735bb8292d2856614
Evidence Type Source Name Value Confidence Vendor pom name Javassist High Vendor pom artifactid javassist Low Vendor pom groupid javassist Highest Vendor Manifest specification-vendor Shigeru Chiba, Tokyo Institute of Technology Low Vendor pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low Vendor pom url http://www.javassist.org/ Highest Vendor file name javassist High Product pom name Javassist High Product pom url http://www.javassist.org/ Medium Product pom groupid javassist Low Product pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low Product pom artifactid javassist Highest Product Manifest specification-title Javassist Medium Product file name javassist High Version file version 3.12.1 Highest Version pom version 3.12.1.GA Highest
maven: javassist:javassist:3.12.1.GA Confidence :High javax.inject-1.jarDescription:
The javax.inject API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Evidence Type Source Name Value Confidence Vendor jar package name javax Low Vendor central groupid javax.inject Highest Vendor pom description The javax.inject API Medium Vendor file name javax.inject-1 High Vendor pom url http://code.google.com/p/atinject/ Highest Vendor pom artifactid javax.inject Low Vendor pom name javax.inject High Vendor pom groupid javax.inject Highest Vendor jar package name inject Low Product pom description The javax.inject API Medium Product file name javax.inject-1 High Product pom groupid javax.inject Low Product pom name javax.inject High Product central artifactid javax.inject Highest Product pom artifactid javax.inject Highest Product pom url http://code.google.com/p/atinject/ Medium Product jar package name inject Low Version pom version 1 Highest Version file version 1 Medium Version central version 1 Highest
javax.persistence-2.0.0.jarDescription:
EclipseLink subversion revision 5939 License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/javax.persistence-2.0.0.jar
MD5: db6ff1c72a5babef16b604df6791b678
SHA1: bff9b1d9de629095001f1a4e77f450b2d6487b07
SHA256: 4e2e0187251332c4bed1e206b4701837dacd9ca927076bca027ea427447a94e2
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor Eclipse.org - EclipseLink Project High Vendor pom url http://www.eclipse.org/eclipselink Highest Vendor Manifest bundle-symbolicname javax.persistence Medium Vendor jar package name persistence Low Vendor Manifest tstamp 1155 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor jar package name javax Low Vendor pom artifactid javax.persistence Low Vendor pom groupid eclipse.persistence Highest Vendor Manifest today November 27 2009 Low Vendor central groupid org.eclipse.persistence Highest Vendor file name javax.persistence High Vendor Manifest specification-vendor Sun Microsystems Inc. Low Vendor Manifest dstamp 20091127 Low Vendor pom name Javax Persistence API 2.0 High Vendor pom description EclipseLink subversion revision 5939 Medium Product Manifest bundle-symbolicname javax.persistence Medium Product pom artifactid javax.persistence Highest Product jar package name persistence Low Product pom url http://www.eclipse.org/eclipselink Medium Product Manifest tstamp 1155 Low Product central artifactid javax.persistence Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest today November 27 2009 Low Product file name javax.persistence High Product Manifest Bundle-Name Java Persistence API 2.0 Medium Product Manifest dstamp 20091127 Low Product pom name Javax Persistence API 2.0 High Product pom groupid eclipse.persistence Low Product pom description EclipseLink subversion revision 5939 Medium Version central version 2.0.0 Highest Version file version 2.0.0 Highest Version pom version 2.0.0 Highest Version Manifest Implementation-Version 2.0.0 High
javax.servlet-api-3.0.1.jarDescription:
Java.net - The Source for Java Technology Collaboration License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/javax.servlet-api-3.0.1.jar
MD5: 3ef236ac4c24850cd54abff60be25f35
SHA1: 6bf0ebb7efd993e222fc1112377b5e92a13b38dd
SHA256: 377d8bde87ac6bc7f83f27df8e02456d5870bb78c832dac656ceacc28b016e56
Evidence Type Source Name Value Confidence Vendor pom url http://servlet-spec.java.net Highest Vendor manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium Vendor Manifest extension-name javax.servlet Medium Vendor pom name Java Servlet API High Vendor Manifest specification-vendor Oracle Low Vendor pom artifactid javax.servlet-api Low Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest bundle-symbolicname javax.servlet-api Medium Vendor pom organization name GlassFish Community High Vendor Manifest (hint) specification-vendor sun Low Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor pom organization url https://glassfish.dev.java.net Medium Vendor file name javax.servlet-api High Vendor pom parent-artifactid jvnet-parent Low Vendor pom groupid javax.servlet Highest Vendor pom parent-groupid net.java Medium Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low Product pom organization name GlassFish Community Low Product manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium Product Manifest extension-name javax.servlet Medium Product pom groupid javax.servlet Low Product pom url http://servlet-spec.java.net Medium Product pom name Java Servlet API High Product Manifest Bundle-Name Java Servlet API Medium Product Manifest bundle-symbolicname javax.servlet-api Medium Product pom artifactid javax.servlet-api Highest Product Manifest specification-title Java(TM) Servlet API Design Specification Medium Product pom parent-artifactid jvnet-parent Medium Product file name javax.servlet-api High Product pom organization url https://glassfish.dev.java.net Low Product Manifest bundle-docurl https://glassfish.dev.java.net Low Product pom parent-groupid net.java Low Version pom version 3.0.1 Highest Version Manifest Implementation-Version 3.0.1 High Version file version 3.0.1 Highest
maven: javax.servlet:javax.servlet-api:3.0.1 Confidence :High jaxb-api-2.2.11.jarDescription:
JAXB (JSR 222) API License:
CDDL 1.1: https://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jaxb-api-2.2.11.jar
MD5: 5983d1e2ec1a9b0604575cd9e9582591
SHA1: 32274d4244967ff43e7a5d967743d94ed3d2aea7
SHA256: 273d82f8653b53ad9d00ce2b2febaef357e79a273560e796ff3fcfec765f8910
Evidence Type Source Name Value Confidence Vendor pom organization url http://www.oracle.com/ Medium Vendor Manifest implementation-build-id tags/jaxb-api-2.2.11-1631, 2013-09-06T10:10:58+0000 Low Vendor file name jaxb-api High Vendor pom artifactid jaxb-api Low Vendor pom description JAXB (JSR 222) API Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom organization name Oracle Corporation High Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor Manifest extension-name javax.xml.bind Medium Vendor manifest Bundle-Description JAXB (JSR 222) API Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom name Java Architecture for XML Binding High Vendor pom groupid javax.xml.bind Highest Vendor pom parent-groupid net.java Medium Vendor pom url http://jaxb.java.net/ Highest Product Manifest implementation-build-id tags/jaxb-api-2.2.11-1631, 2013-09-06T10:10:58+0000 Low Product pom url http://jaxb.java.net/ Medium Product file name jaxb-api High Product Manifest specification-title Java Architecture for XML Binding Medium Product pom description JAXB (JSR 222) API Medium Product pom groupid javax.xml.bind Low Product pom artifactid jaxb-api Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest bundle-symbolicname jaxb-api Medium Product Manifest extension-name javax.xml.bind Medium Product pom parent-artifactid jvnet-parent Medium Product manifest Bundle-Description JAXB (JSR 222) API Medium Product Manifest Bundle-Name jaxb-api Medium Product pom name Java Architecture for XML Binding High Product pom organization name Oracle Corporation Low Product pom organization url http://www.oracle.com/ Low Product pom parent-groupid net.java Low Version pom version 2.2.11 Highest Version file version 2.2.11 Highest
maven: javax.xml.bind:jaxb-api:2.2.11 Confidence :High jaxb-impl-2.2.3-1.jarDescription:
JAXB (JSR 222) reference implementation License:
CDDL 1.1: https://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jaxb-impl-2.2.3-1.jar
MD5: 1b689e7f87caf2615c0f6a47831d0342
SHA1: 56baae106392040a45a06d4a41099173425da1e6
SHA256: fa3e1499b192c310312bf02881274b68394aaea4c9563e6c554cc406ae644ff8
Evidence Type Source Name Value Confidence Vendor pom organization url http://www.oracle.com/ Medium Vendor central groupid com.sun.xml.bind High Vendor jar package name bind Low Vendor pom groupid sun.xml.bind Highest Vendor Manifest extension-name com.sun.xml.bind Medium Vendor jar package name xml Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom organization name Oracle Corporation High Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor pom artifactid jaxb-impl Low Vendor file name jaxb-impl High Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor pom description JAXB (JSR 222) reference implementation Medium Vendor pom url http://jaxb.java.net/ Highest Vendor pom name JAXB RI High Product pom url http://jaxb.java.net/ Medium Product central artifactid jaxb-impl High Product Manifest specification-title Java Architecture for XML Binding Medium Product jar package name bind Low Product Manifest extension-name com.sun.xml.bind Medium Product jar package name xml Low Product jar package name v2 Low Product file name jaxb-impl High Product pom groupid sun.xml.bind Low Product Manifest Implementation-Title JAXB Reference Implementation High Product pom artifactid jaxb-impl Highest Product pom organization name Oracle Corporation Low Product pom organization url http://www.oracle.com/ Low Product pom description JAXB (JSR 222) reference implementation Medium Product pom name JAXB RI High Version Manifest build-id hudson-jaxb-ri-2.2.3-3 Medium Version Manifest Implementation-Version 2.2.3 High Version pom version 2.2.3-1 Highest Version manifest: com.sun.xml.bind.v2.runtime Implementation-Version 2.2.3-hudson-jaxb-ri-2.2.3-3- Medium Version file version 2.2.3.1 Highest Version central version 2.2.3-1 High Version file name jaxb-impl Medium Version central version 2.2.3U1 High Version pom version 2.2.3U1 Highest
jdom-1.1.jarDescription:
JDOM is, quite simply, a Java representation of an XML document. JDOM provides a way to represent that document for
easy and efficient reading, manipulation, and writing. It has a straightforward API, is a lightweight and fast, and
is optimized for the Java programmer. It's an alternative to DOM and SAX, although it integrates well with both DOM
and SAX.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jdom-1.1.jarMD5: adf67fc5dcf48e1593640ad7e02f6ad4SHA1: 1d04c0f321ea337f3661cf7ede8f4c6f653a8fddSHA256: 3c167654499436ee9c19674b519d04e7364085533f6facada1bf90b16ad34897
Evidence Type Source Name Value Confidence Vendor manifest: org/jdom/output/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/transform/ Implementation-Vendor jdom.org Medium Vendor jar package name jdom Low Vendor pom url http://www.jdom.org/ Highest Vendor pom name JDOM High Vendor pom description JDOM is, quite simply, a Java representation of an XML document. JDOM provides a way to represent that document for easy and efficient reading, manipulation, and writing. It has a straightforward API, is a lightweight and fast, and is optimized for the Java programmer. It's an alternative to DOM and SAX, although it integrates well with both DOM and SAX. Low Vendor manifest: org/jdom/xpath/ Implementation-Vendor jdom.org Medium Vendor central groupid org.jdom Highest Vendor pom groupid jdom Highest Vendor manifest: org/jdom/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/filter/ Implementation-Vendor jdom.org Medium Vendor file name jdom High Vendor manifest: org/jdom/input/ Implementation-Vendor jdom.org Medium Vendor pom artifactid jdom Low Vendor manifest: org/jdom/ Implementation-Vendor jdom.org Medium Product manifest: org/jdom/transform/ Specification-Title JDOM Transformation Classes Medium Product manifest: org/jdom/ Implementation-Title org.jdom Medium Product pom groupid jdom Low Product manifest: org/jdom/ Specification-Title JDOM Classes Medium Product manifest: org/jdom/adapters/ Specification-Title JDOM Adapter Classes Medium Product manifest: org/jdom/adapters/ Implementation-Title org.jdom.adapters Medium Product pom name JDOM High Product pom description JDOM is, quite simply, a Java representation of an XML document. JDOM provides a way to represent that document for easy and efficient reading, manipulation, and writing. It has a straightforward API, is a lightweight and fast, and is optimized for the Java programmer. It's an alternative to DOM and SAX, although it integrates well with both DOM and SAX. Low Product manifest: org/jdom/filter/ Implementation-Title org.jdom.filter Medium Product manifest: org/jdom/transform/ Implementation-Title org.jdom.transform Medium Product manifest: org/jdom/output/ Specification-Title JDOM Output Classes Medium Product pom artifactid jdom Highest Product manifest: org/jdom/xpath/ Implementation-Title org.jdom.xpath Medium Product file name jdom High Product manifest: org/jdom/xpath/ Specification-Title JDOM XPath Classes Medium Product central artifactid jdom Highest Product manifest: org/jdom/filter/ Specification-Title JDOM Filter Classes Medium Product manifest: org/jdom/input/ Specification-Title JDOM Input Classes Medium Product manifest: org/jdom/input/ Implementation-Title org.jdom.input Medium Product manifest: org/jdom/output/ Implementation-Title org.jdom.output Medium Product pom url http://www.jdom.org/ Medium Version file version 1.1 Highest Version central version 1.1 Highest Version pom version 1.1 Highest
Related Dependencies jdom-1.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-xml/jdom-1.1.jar MD5: adf67fc5dcf48e1593640ad7e02f6ad4 SHA1: 1d04c0f321ea337f3661cf7ede8f4c6f653a8fdd SHA256: 3c167654499436ee9c19674b519d04e7364085533f6facada1bf90b16ad34897 jersey-client-1.9.jarDescription:
Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html, http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jersey-client-1.9.jar
MD5: cdbba85f9cb7ce5e0ca51d610f0228e9
SHA1: d3c4b2b5f89db32c96ceddcb863684821910a7bb
SHA256: 8ae03af0d06c46a51b65d123ec40f245da690991aa3669cef4767db8f36fbe68
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jersey-project Low Vendor file name jersey-client High Vendor manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor pom parent-groupid com.sun.jersey Medium Vendor pom artifactid jersey-client Low Vendor pom groupid sun.jersey Highest Vendor Manifest bundle-symbolicname com.sun.jersey.jersey-client Medium Vendor Manifest Implementation-Vendor-Id com.sun.jersey Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor pom name jersey-client High Product file name jersey-client High Product Manifest Implementation-Title jersey-client High Product manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom parent-groupid com.sun.jersey Low Product pom artifactid jersey-client Highest Product Manifest bundle-symbolicname com.sun.jersey.jersey-client Medium Product Manifest Bundle-Name jersey-client Medium Product pom groupid sun.jersey Low Product pom parent-artifactid jersey-project Medium Product pom name jersey-client High Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: com.sun.jersey:jersey-client:1.9 Confidence :High jersey-core-1.9.jarDescription:
Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html, http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jersey-core-1.9.jar
MD5: 73d196595f5e410a37c0a4337350ceb7
SHA1: 8341846f18187013bb9e27e46b7ee00a6395daf4
SHA256: 2c6d0ec88fc8c36cb41637d9c00d0698c22cb6b6a137fa526ef782e00d2265bc
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jersey-project Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Vendor pom artifactid jersey-core Low Vendor pom parent-groupid com.sun.jersey Medium Vendor file name jersey-core High Vendor Manifest bundle-symbolicname com.sun.jersey.jersey-core Medium Vendor pom groupid sun.jersey Highest Vendor Manifest Implementation-Vendor-Id com.sun.jersey Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor pom name jersey-core High Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name jersey-core Medium Product manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Product pom artifactid jersey-core Highest Product pom parent-groupid com.sun.jersey Low Product file name jersey-core High Product Manifest bundle-symbolicname com.sun.jersey.jersey-core Medium Product Manifest Implementation-Title jersey-core High Product pom groupid sun.jersey Low Product pom name jersey-core High Product pom parent-artifactid jersey-project Medium Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: com.sun.jersey:jersey-core:1.9 Confidence :High jersey-guice-1.9.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jersey-guice-1.9.jarMD5: a81140d246f420c1e2eabe649417c5b1SHA1: 5963c28c47df7e5d6ad34cec80c071c368777f7bSHA256: 544fc92d2625332a9a8eeaa7a7274cf1af6703936a50afa80d92a78200a7de34
Evidence Type Source Name Value Confidence Vendor pom artifactid jersey-guice Low Vendor pom name jersey-guice High Vendor Manifest Implementation-Vendor-Id com.sun.jersey.contribs Medium Vendor pom parent-groupid com.sun.jersey.contribs Medium Vendor pom groupid sun.jersey.contribs Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor file name jersey-guice High Vendor pom parent-artifactid jersey-contribs Low Product pom name jersey-guice High Product pom parent-groupid com.sun.jersey.contribs Low Product pom groupid sun.jersey.contribs Low Product Manifest Implementation-Title jersey-guice High Product pom artifactid jersey-guice Highest Product pom parent-artifactid jersey-contribs Medium Product file name jersey-guice High Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: com.sun.jersey.contribs:jersey-guice:1.9 Confidence :High jersey-json-1.9.jarDescription:
Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html, http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jersey-json-1.9.jar
MD5: 17ca6b0d49ed8db159b7827b6defa6b6
SHA1: 1aa73e1896bcc7013fed247157d7f676226eb432
SHA256: cc5d535f43cef0d1c467240961aae35801a837ab010319e741b2c7a6658f3fd6
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jersey-project Low Vendor manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname com.sun.jersey.jersey-json Medium Vendor file name jersey-json High Vendor pom parent-groupid com.sun.jersey Medium Vendor pom groupid sun.jersey Highest Vendor pom artifactid jersey-json Low Vendor pom name jersey-json High Vendor Manifest Implementation-Vendor-Id com.sun.jersey Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Product manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Implementation-Title jersey-json High Product Manifest bundle-symbolicname com.sun.jersey.jersey-json Medium Product pom parent-groupid com.sun.jersey Low Product file name jersey-json High Product pom artifactid jersey-json Highest Product pom groupid sun.jersey Low Product pom name jersey-json High Product Manifest Bundle-Name jersey-json Medium Product pom parent-artifactid jersey-project Medium Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: com.sun.jersey:jersey-json:1.9 Confidence :High jersey-server-1.9.jarDescription:
Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html, http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jersey-server-1.9.jar
MD5: 0c98f6cca5df8197b310a0d1d89bb34a
SHA1: 3a6ea7cc5e15c824953f9f3ece2201b634d90d18
SHA256: 3ded91b198077561bd51f6c0442c9cd70b754d8b31b61afaf448bda9d01848f0
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jersey-project Low Vendor manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Vendor Manifest bundle-symbolicname com.sun.jersey.jersey-server Medium Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor file name jersey-server High Vendor pom parent-groupid com.sun.jersey Medium Vendor pom groupid sun.jersey Highest Vendor pom name jersey-server High Vendor Manifest Implementation-Vendor-Id com.sun.jersey Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor pom artifactid jersey-server Low Product Manifest Bundle-Name jersey-server Medium Product manifest Bundle-Description Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. Low Product Manifest bundle-symbolicname com.sun.jersey.jersey-server Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product file name jersey-server High Product Manifest Implementation-Title jersey-server High Product pom parent-groupid com.sun.jersey Low Product pom artifactid jersey-server Highest Product pom name jersey-server High Product pom groupid sun.jersey Low Product pom parent-artifactid jersey-project Medium Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: com.sun.jersey:jersey-server:1.9 Confidence :High jettison-1.3.1.jarDescription:
A StAX implementation for JSON. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jettison-1.3.1.jarMD5: ff4330f064a5eddcdc24a29d344a21ccSHA1: 056dcc8480ecd2c03ec004aa76278d1f2d621561SHA256: e69372aa9d5fdf002c48d2e8490cf7515f6dcf6903282c935ac91cafb6a843cc
Evidence Type Source Name Value Confidence Vendor pom groupid codehaus.jettison Highest Vendor manifest Bundle-Description A StAX implementation for JSON. Medium Vendor pom parent-artifactid codehaus-parent Low Vendor pom description A StAX implementation for JSON. Medium Vendor pom parent-groupid org.codehaus Medium Vendor pom artifactid jettison Low Vendor pom name Jettison High Vendor file name jettison High Vendor Manifest bundle-symbolicname org.codehaus.jettison.jettison Medium Product Manifest Bundle-Name jettison Medium Product pom parent-groupid org.codehaus Low Product pom parent-artifactid codehaus-parent Medium Product pom groupid codehaus.jettison Low Product manifest Bundle-Description A StAX implementation for JSON. Medium Product pom description A StAX implementation for JSON. Medium Product pom name Jettison High Product file name jettison High Product Manifest Implementation-Title Jettison High Product pom artifactid jettison Highest Product Manifest bundle-symbolicname org.codehaus.jettison.jettison Medium Version file version 1.3.1 Highest Version Manifest Implementation-Version 1.3.1 High Version pom version 1.3.1 Highest
maven: org.codehaus.jettison:jettison:1.3.1 Confidence :High jetty-6.1.26.jarDescription:
Jetty server core License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jetty-6.1.26.jar
MD5: 12b65438bbaf225102d0396c21236052
SHA1: 2f546e289fddd5b1fab1d4199fbb6e9ef43ee4b0
SHA256: 21091d3a9c1349f640fdc421504a604c040ed89087ecc12afbe32353326ed4e5
Evidence Type Source Name Value Confidence Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor Manifest bundle-symbolicname org.mortbay.jetty.server Medium Vendor pom description Jetty server core Medium Vendor pom name Jetty Server High Vendor pom parent-groupid org.mortbay.jetty Medium Vendor pom artifactid jetty Low Vendor Manifest url http://www.eclipse.org/jetty/jetty-parent/project/modules/jetty Low Vendor Manifest originally-created-by 1.6.0_22 (Sun Microsystems Inc.) Low Vendor manifest Bundle-Description Jetty server core Medium Vendor file name jetty High Vendor pom parent-artifactid project Low Vendor Manifest bundle-docurl http://jetty.mortbay.org Low Vendor pom groupid mortbay.jetty Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product pom groupid mortbay.jetty Low Product Manifest bundle-symbolicname org.mortbay.jetty.server Medium Product Manifest Bundle-Name Jetty Server Medium Product pom description Jetty server core Medium Product pom name Jetty Server High Product pom parent-groupid org.mortbay.jetty Low Product Manifest url http://www.eclipse.org/jetty/jetty-parent/project/modules/jetty Low Product Manifest originally-created-by 1.6.0_22 (Sun Microsystems Inc.) Low Product pom parent-artifactid project Medium Product manifest Bundle-Description Jetty server core Medium Product file name jetty High Product pom artifactid jetty Highest Product Manifest bundle-docurl http://jetty.mortbay.org Low Version pom version 6.1.26 Highest Version file version 6.1.26 Highest
Related Dependencies jetty-util5-6.1.26.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jetty-util5-6.1.26.jar MD5: bc2db69472f041af56d31ba98a51d08d SHA1: 6e8a0158fb11ba7cb3ec906fd2ff36c60f2eafdb SHA256: 18bf25fcc12efcfe7858b83cd6cd9aa3f34de7bc7267aa1ae279555400cbae27 jetty-util-6.1.26.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jetty-util-6.1.26.jar MD5: 450fedce4f7f8ad3761577b10a664200 SHA1: e5642fe0399814e1687d55a3862aa5a3417226a9 SHA256: 9b974ce2b99f48254b76126337dc45b21226f383aaed616f59780adaf167c047 jetty-sslengine-6.1.26.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jetty-sslengine-6.1.26.jar MD5: d3bea45d6939e57fccf450a914fe4e1a SHA1: 60367999cee49a3b09fa86bdcb52310b6c896014 SHA256: 9c5f6bb168ba01b95d250b57f061c8094e1ce9c89ae4e773492bacb17192ea87 jetty-client-6.1.26.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jetty-client-6.1.26.jar MD5: 11694dcf0e460956990605bc9bf29ab2 SHA1: 74bbbab933175d04c8c31a8bbe29fa6cee82314c SHA256: b4eaea26c6026c7f28fa9c3087051ca487379f68d8a40794867467fc0ba9722a jetty-util-6.1.26.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/jetty-util-6.1.26.jar MD5: 450fedce4f7f8ad3761577b10a664200 SHA1: e5642fe0399814e1687d55a3862aa5a3417226a9 SHA256: 9b974ce2b99f48254b76126337dc45b21226f383aaed616f59780adaf167c047 cpe: cpe:/a:mortbay_jetty:jetty:6.1.26 Confidence :Low suppress maven: org.mortbay.jetty:jetty:6.1.26 Confidence :Highcpe: cpe:/a:mortbay:jetty:6.1.26 Confidence :Low suppress cpe: cpe:/a:jetty:jetty:6.1.26 Confidence :Low suppress Published Vulnerabilities CVE-2011-4461 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-310 Cryptographic Issues
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Vulnerable Software & Versions: (show all )
joda-time-2.7.jarDescription:
Date and time library to replace JDK date handling License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/joda-time-2.7.jar
MD5: 4f29e832878694d7096249c5c32f8fe9
SHA1: 5599707a3eaad13e889f691b3af78c8c03842195
SHA256: f0f5720b333cd62b2b4f6164b1a0cde0a582f497798e8eea033f5d25f9d6f590
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor Joda.org Low Vendor Manifest bundle-docurl http://www.joda.org/joda-time/ Low Vendor pom name Joda-Time High Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor pom groupid joda-time Highest Vendor pom description Date and time library to replace JDK date handling Medium Vendor Manifest extension-name joda-time Medium Vendor pom url http://www.joda.org/joda-time/ Highest Vendor file name joda-time High Vendor pom organization url http://www.joda.org Medium Vendor Manifest bundle-symbolicname joda-time Medium Vendor pom artifactid joda-time Low Vendor Manifest Implementation-Vendor Joda.org High Vendor pom organization name Joda.org High Product pom groupid joda-time Low Product Manifest specification-title Joda-Time Medium Product Manifest bundle-docurl http://www.joda.org/joda-time/ Low Product pom name Joda-Time High Product pom description Date and time library to replace JDK date handling Medium Product Manifest Bundle-Name Joda-Time Medium Product pom organization name Joda.org Low Product Manifest extension-name joda-time Medium Product pom organization url http://www.joda.org Low Product pom artifactid joda-time Highest Product file name joda-time High Product Manifest bundle-symbolicname joda-time Medium Product pom url http://www.joda.org/joda-time/ Medium Product Manifest Implementation-Title org.joda.time High Version Manifest Implementation-Version 2.7 High Version file version 2.7 Highest Version pom version 2.7 Highest
maven: joda-time:joda-time:2.7 Confidence :High jquery-2.0.3-1.jarDescription:
WebJar for jQuery License:
MIT License: https://github.com/jquery/jquery/blob/master/MIT-LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jquery-2.0.3-1.jar
MD5: 732cfed87e366dd90b2a975ad74366bb
SHA1: 9be7beefd7c17933d68640da261e3e05d46f3b45
SHA256: a43d569f4ec10a9383719bec2185d10959623345688b5be28ca8ea3856a82d17
Evidence Type Source Name Value Confidence Vendor pom groupid webjars Highest Vendor pom name jquery High Vendor pom description WebJar for jQuery Medium Vendor file name jquery High Vendor pom artifactid jquery Low Vendor pom url http://webjars.org Highest Product pom groupid webjars Low Product pom artifactid jquery Highest Product pom name jquery High Product pom description WebJar for jQuery Medium Product pom url http://webjars.org Medium Product file name jquery High Version file version 2.0.3.1 Highest Version pom version 2.0.3-1 Highest
maven: org.webjars:jquery:2.0.3-1 Confidence :High jquery-selectors-0.0.3.jarLicense:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jquery-selectors-0.0.3.jar
MD5: a2f60c4f980351d48d9415fb01fdf1b7
SHA1: 00b658478b70ef120c434054d7a07790e2aff3bb
SHA256: 7191f3a436b2302841d927ef5b95a1aaac4df514836174ff7f7963384b95978f
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid maven-parent-pom Low Vendor Manifest implementation-build 37738a9d719a5f2b1ca24ccf117e07b2eb5ee01f Low Vendor Manifest Implementation-Vendor-Id de.agilecoders.wicket Medium Vendor file name jquery-selectors High Vendor Manifest Implementation-Vendor AgileCoders High Vendor pom parent-groupid de.agilecoders.maven Medium Vendor pom groupid de.agilecoders.wicket Highest Vendor pom artifactid jquery-selectors Low Product pom artifactid jquery-selectors Highest Product pom parent-groupid de.agilecoders.maven Low Product Manifest implementation-build 37738a9d719a5f2b1ca24ccf117e07b2eb5ee01f Low Product file name jquery-selectors High Product Manifest Implementation-Title jquery-selectors High Product pom groupid de.agilecoders.wicket Low Product pom parent-artifactid maven-parent-pom Medium Version pom version 0.0.3 Highest Version Manifest Implementation-Version 0.0.3 High Version file version 0.0.3 Highest
maven: de.agilecoders.wicket:jquery-selectors:0.0.3 Confidence :High jquery-ui-1.10.2-1.jarDescription:
WebJar for jQuery UI License:
MIT License: https://github.com/jquery/jquery-ui/blob/master/MIT-LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jquery-ui-1.10.2-1.jar
MD5: 8514b666fa516423c426cb4857c94745
SHA1: 4767035496f7b4ecf2cfb9aea39003dc2eeecd59
SHA256: 277d7a47ba2cd0912eae32aeb662896264e2e3b4d0d10815c4d1433fc6e435b5
Evidence Type Source Name Value Confidence Vendor pom groupid webjars Highest Vendor file name jquery-ui High Vendor pom artifactid jquery-ui Low Vendor pom description WebJar for jQuery UI Medium Vendor pom url http://webjars.org Highest Vendor pom name jQuery UI High Product pom groupid webjars Low Product pom artifactid jquery-ui Highest Product file name jquery-ui High Product pom url http://webjars.org Medium Product pom description WebJar for jQuery UI Medium Product pom name jQuery UI High Version file version 1.10.2.1 Highest Version pom version 1.10.2-1 Highest
maven: org.webjars:jquery-ui:1.10.2-1 Confidence :High jquerypp-1.0.1.jarDescription:
WebJar for jQuery++ License:
MIT License: https://github.com/jupiterjs/jquerypp/blob/master/license.md File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jquerypp-1.0.1.jar
MD5: 653b09bd62701f3544f1a8e9a28d4625
SHA1: 8ad527112c0d70fc140475d0f04802c3567c77fe
SHA256: 834febdee3ae60e13178ed1f945c0fb5141b1534c4799584bf25939c0730f828
Evidence Type Source Name Value Confidence Vendor file name jquerypp High Vendor pom groupid webjars Highest Vendor pom description WebJar for jQuery++ Medium Vendor pom name jQuery++ High Vendor pom artifactid jquerypp Low Vendor pom url http://webjars.org Highest Product pom groupid webjars Low Product file name jquerypp High Product pom artifactid jquerypp Highest Product pom description WebJar for jQuery++ Medium Product pom url http://webjars.org Medium Product pom name jQuery++ High Version file version 1.0.1 Highest Version pom version 1.0.1 Highest
maven: org.webjars:jquerypp:1.0.1 Confidence :High jsch-0.1.42.jarDescription:
JSch is a pure Java implementation of SSH2 License:
BSD: http://www.jcraft.com/jsch/LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jsch-0.1.42.jar
MD5: 74ea920580077b4c0b51101a8292a529
SHA1: a86104b0f2e0c0bab5b0df836065823a99b5e334
SHA256: 74297550aecc3b566ee19e49befb9cd49e2326c9d8d71ad5071bacc655b760dc
Evidence Type Source Name Value Confidence Vendor file name jsch High Vendor jar package name jcraft Low Vendor pom url http://www.jcraft.com/jsch/ Highest Vendor pom groupid jcraft Highest Vendor central groupid com.jcraft Highest Vendor jar package name jsch Low Vendor pom artifactid jsch Low Vendor pom name JSch High Vendor pom description JSch is a pure Java implementation of SSH2 Medium Vendor pom organization name jcraft High Vendor pom organization url http://www.jcraft.com/jsch Medium Product file name jsch High Product jar package name jsch Low Product pom artifactid jsch Highest Product pom url http://www.jcraft.com/jsch/ Medium Product pom name JSch High Product pom description JSch is a pure Java implementation of SSH2 Medium Product central artifactid jsch Highest Product pom organization name jcraft Low Product pom organization url http://www.jcraft.com/jsch Low Product pom groupid jcraft Low Version file version 0.1.42 Highest Version central version 0.1.42 Highest Version pom version 0.1.42 Highest
Published Vulnerabilities CVE-2016-5725 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command. Vulnerable Software & Versions:
json-20090211.jarDescription:
JSON (JavaScript Object Notation) is a lightweight data-interchange format.
It is easy for humans to read and write. It is easy for machines to parse and generate.
It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition
- December 1999. JSON is a text format that is completely language independent but uses
conventions that are familiar to programmers of the C-family of languages, including C, C++, C#,
Java, JavaScript, Perl, Python, and many others.
These properties make JSON an ideal data-interchange language.
License:
provided without support or warranty: http://www.json.org/license.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/json-20090211.jar
MD5: 333139fffc6c9d4bc3d2495d9613f092
SHA1: c183aa3a2a6250293808bba12262c8920ce5a51c
SHA256: 055be110a570f9cda3eba8d70a006ff46c77a048bc67868524879211c48b330a
Evidence Type Source Name Value Confidence Vendor pom name JSON (JavaScript Object Notation) High Vendor pom url http://www.json.org/java/index.html Highest Vendor jar package name json Low Vendor pom artifactid json Low Vendor file name json-20090211 High Vendor pom organization name JSON High Vendor pom groupid json Highest Vendor central groupid org.json Highest Vendor pom organization url http://json.org/ Medium Vendor pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but... Low Product pom groupid json Low Product pom organization url http://json.org/ Low Product pom name JSON (JavaScript Object Notation) High Product pom artifactid json Highest Product file name json-20090211 High Product pom organization name JSON Low Product pom url http://www.json.org/java/index.html Medium Product central artifactid json Highest Product pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but... Low Version central version 20090211 Highest Version file version 20090211 Medium Version pom version 20090211 Highest
jsp-api-2.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jsp-api-2.1.jarMD5: b8a34113a3a1ce29c8c60d7141f5a704SHA1: 63f943103f250ef1f3a4d5e94d145a0f961f5316SHA256: 545f4e7dc678ffb4cf8bd0fd40b4a4470a409a787c0ea7d0ad2f08d56112987b
Evidence Type Source Name Value Confidence Vendor jar package name javax Low Vendor pom groupid javax.servlet.jsp Highest Vendor jar package name servlet Low Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor central groupid javax.servlet.jsp Highest Vendor pom artifactid jsp-api Low Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor jar package name jsp Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor file name jsp-api High Vendor Manifest extension-name javax.servlet.jsp Medium Product pom artifactid jsp-api Highest Product jar package name el Low Product jar package name servlet Low Product pom groupid javax.servlet.jsp Low Product jar package name jsp Low Product file name jsp-api High Product central artifactid jsp-api Highest Product Manifest extension-name javax.servlet.jsp Medium Product Manifest specification-title JavaServer Pages(TM) Specification Medium Version file version 2.1 Highest Version Manifest Implementation-Version 2.1 High Version pom version 2.1 Highest Version central version 2.1 Highest
jsr305-1.3.9.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jsr305-1.3.9.jar
MD5: 1d5a772e400b04bb67a7ef4a0e0996d8
SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf
SHA256: 905721a0eea90a81534abb7ee6ef4ea2e5e645fa1def0a5cd88402df1b46c9ed
Evidence Type Source Name Value Confidence Vendor jar package name javax Low Vendor jar package name annotation Low Vendor pom groupid google.code.findbugs Highest Vendor pom url http://findbugs.sourceforge.net/ Highest Vendor pom description JSR305 Annotations for Findbugs Medium Vendor pom artifactid jsr305 Low Vendor file name jsr305 High Vendor pom name FindBugs-jsr305 High Vendor central groupid com.google.code.findbugs Highest Product jar package name annotation Low Product pom groupid google.code.findbugs Low Product pom description JSR305 Annotations for Findbugs Medium Product central artifactid jsr305 Highest Product pom artifactid jsr305 Highest Product pom url http://findbugs.sourceforge.net/ Medium Product file name jsr305 High Product pom name FindBugs-jsr305 High Version file version 1.3.9 Highest Version central version 1.3.9 Highest Version pom version 1.3.9 Highest
Related Dependencies jsr305-1.3.9.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jsr305-1.3.9.jar MD5: 1d5a772e400b04bb67a7ef4a0e0996d8 SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf SHA256: 905721a0eea90a81534abb7ee6ef4ea2e5e645fa1def0a5cd88402df1b46c9ed jsr305-1.3.9.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/jsr305-1.3.9.jar MD5: 1d5a772e400b04bb67a7ef4a0e0996d8 SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf SHA256: 905721a0eea90a81534abb7ee6ef4ea2e5e645fa1def0a5cd88402df1b46c9ed jsr311-api-1.1.1.jarLicense:
CDDL License
: http://www.opensource.org/licenses/cddl1.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
SHA256: ab1534b73b5fa055808e6598a5e73b599ccda28c3159c3c0908977809422ee4a
Evidence Type Source Name Value Confidence Vendor Manifest extension-name javax.ws.rs Medium Vendor file name jsr311-api High Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium Vendor pom organization name Sun Microsystems, Inc High Vendor pom name jsr311-api High Vendor Manifest bundle-docurl http://www.sun.com/ Low Vendor pom url https://jsr311.dev.java.net Highest Vendor pom artifactid jsr311-api Low Vendor pom organization url http://www.sun.com/ Medium Vendor pom groupid javax.ws.rs Highest Product Manifest extension-name javax.ws.rs Medium Product file name jsr311-api High Product pom name jsr311-api High Product Manifest bundle-docurl http://www.sun.com/ Low Product Manifest Bundle-Name jsr311-api Medium Product pom artifactid jsr311-api Highest Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium Product pom url https://jsr311.dev.java.net Medium Product pom organization url http://www.sun.com/ Low Product pom groupid javax.ws.rs Low Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium Product pom organization name Sun Microsystems, Inc Low Version pom version 1.1.1 Highest Version file version 1.1.1 Highest
maven: javax.ws.rs:jsr311-api:1.1.1 Confidence :High junit-4.11.jarDescription:
JUnit is a regression testing framework written by Erich Gamma and Kent Beck.
It is used by the developer who implements unit tests in Java.
License:
Common Public License Version 1.0: http://www.opensource.org/licenses/cpl1.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/junit-4.11.jar
MD5: 3c42be5ea7cbf3635716abbb429cb90d
SHA1: 4e031bb61df09069aeb2bffb4019e7a5034a4ee0
SHA256: 90a8e1603eeca48e7e879f3afbc9560715322985f39a274f6f6070b43f9d06fe
Evidence Type Source Name Value Confidence Vendor pom artifactid junit Low Vendor pom organization url http://www.junit.org Medium Vendor pom name JUnit High Vendor jar package name junit Low Vendor pom url http://junit.org Highest Vendor pom groupid junit Highest Vendor central groupid junit Highest Vendor pom description JUnit is a regression testing framework written by Erich Gamma and Kent Beck. It is used by the developer who implements unit tests in Java. Low Vendor file name junit High Vendor pom organization name JUnit High Product pom name JUnit High Product central artifactid junit Highest Product pom organization url http://www.junit.org Low Product pom description JUnit is a regression testing framework written by Erich Gamma and Kent Beck. It is used by the developer who implements unit tests in Java. Low Product file name junit High Product pom url http://junit.org Medium Product pom organization name JUnit Low Product pom artifactid junit Highest Product pom groupid junit Low Version file version 4.11 Highest Version central version 4.11 Highest Version pom version 4.11 Highest
Related Dependencies junit-4.11.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/junit-4.11.jar MD5: 3c42be5ea7cbf3635716abbb429cb90d SHA1: 4e031bb61df09069aeb2bffb4019e7a5034a4ee0 SHA256: 90a8e1603eeca48e7e879f3afbc9560715322985f39a274f6f6070b43f9d06fe juniversalchardet-1.0.3.jarDescription:
Java port of universalchardet License:
Mozilla Public License 1.1 (MPL 1.1): http://www.mozilla.org/MPL/MPL-1.1.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/juniversalchardet-1.0.3.jar
MD5: d9ea0a9a275336c175b343f2e4cd8f27
SHA1: cd49678784c46aa8789c060538e0154013bb421b
SHA256: 757bfe906193b8b651e79dc26cd67d6b55d0770a2cdfb0381591504f779d4a76
Evidence Type Source Name Value Confidence Vendor jar package name prober Low Vendor jar package name mozilla Low Vendor jar package name universalchardet Low Vendor pom url http://juniversalchardet.googlecode.com/ Highest Vendor pom artifactid juniversalchardet Low Vendor pom name juniversalchardet High Vendor pom description Java port of universalchardet Medium Vendor file name juniversalchardet High Vendor pom groupid googlecode.juniversalchardet Highest Product jar package name prober Low Product pom groupid googlecode.juniversalchardet Low Product jar package name universalchardet Low Product pom name juniversalchardet High Product pom description Java port of universalchardet Medium Product file name juniversalchardet High Product pom artifactid juniversalchardet Highest Product pom url http://juniversalchardet.googlecode.com/ Medium Version pom version 1.0.3 Highest Version file version 1.0.3 Highest
Related Dependencies juniversalchardet-1.0.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/juniversalchardet-1.0.3.jar MD5: d9ea0a9a275336c175b343f2e4cd8f27 SHA1: cd49678784c46aa8789c060538e0154013bb421b SHA256: 757bfe906193b8b651e79dc26cd67d6b55d0770a2cdfb0381591504f779d4a76 maven: com.googlecode.juniversalchardet:juniversalchardet:1.0.3 Confidence :High leveldbjni-all-1.8.jarDescription:
An uber jar which contains all the leveldbjni platform libraries and dependencies License:
http://www.opensource.org/licenses/BSD-3-Clause File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/leveldbjni-all-1.8.jar
MD5: 6944e9bc03c7938868e53c96726ae914
SHA1: 707350a2eeb1fa2ed77a32ddb3893ed308e941db
SHA256: c297213b0e6f9392305952753f3099a4c02e70b3656266fe01867e7b6c160ffe
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.fusesource.leveldbjni Medium Vendor pom artifactid leveldbjni-all Low Vendor pom name ${project.artifactId} High Vendor pom parent-artifactid leveldbjni-project Low Vendor pom groupid fusesource.leveldbjni Highest Vendor file name leveldbjni-all High Vendor Manifest bundle-docurl http://fusesource.com/ Low Vendor pom description An uber jar which contains all the leveldbjni platform libraries and dependencies Medium Vendor manifest Bundle-Description An uber jar which contains all the leveldbjni platform libraries and dependencies Medium Vendor Manifest bundle-symbolicname org.fusesource.leveldbjni.leveldbjni-all Medium Vendor Manifest bundle-nativecode META-INF/native/windows32/leveldbjni.dll;osname=Win32;processor=x86,META-INF/native/windows64/leveldbjni.dll;osname=Win32;processor=x86-64,META-INF/native/osx/libleveldbjni.jnilib;osname=macosx;processor=x86,META-INF/native/osx/libleveldbjni.jnilib;osname=macosx;processor=x86-64,META-INF/native/linux32/libleveldbjni.so;osname=Linux;processor=x86,META-INF/native/linux64/libleveldbjni.so;osname=Linux;processor=x86-64 Low Product pom name ${project.artifactId} High Product pom parent-groupid org.fusesource.leveldbjni Low Product file name leveldbjni-all High Product pom description An uber jar which contains all the leveldbjni platform libraries and dependencies Medium Product Manifest bundle-symbolicname org.fusesource.leveldbjni.leveldbjni-all Medium Product Manifest Bundle-Name leveldbjni-all Medium Product pom groupid fusesource.leveldbjni Low Product Manifest Implementation-Title LevelDB JNI High Product pom artifactid leveldbjni-all Highest Product Manifest bundle-docurl http://fusesource.com/ Low Product manifest Bundle-Description An uber jar which contains all the leveldbjni platform libraries and dependencies Medium Product Manifest bundle-nativecode META-INF/native/windows32/leveldbjni.dll;osname=Win32;processor=x86,META-INF/native/windows64/leveldbjni.dll;osname=Win32;processor=x86-64,META-INF/native/osx/libleveldbjni.jnilib;osname=macosx;processor=x86,META-INF/native/osx/libleveldbjni.jnilib;osname=macosx;processor=x86-64,META-INF/native/linux32/libleveldbjni.so;osname=Linux;processor=x86,META-INF/native/linux64/libleveldbjni.so;osname=Linux;processor=x86-64 Low Product pom parent-artifactid leveldbjni-project Medium Version file version 1.8 Highest Version Manifest Implementation-Version 1.8 High Version pom version 1.8 Highest
maven: org.fusesource.leveldbjni:leveldbjni-all:1.8 Confidence :Highcpe: cpe:/a:id:id-software:1.8 Confidence :Low suppress log4j-1.2.17.jarDescription:
Apache Log4j 1.2 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/log4j-1.2.17.jar
MD5: 04a41f0a068986f0f73485cf507c0f40
SHA1: 5af35056b4d257e4b64b9e8069c0746e8b08629f
SHA256: 1d31696445697720527091754369082a6651bd49781b6005deb94e56753406f9
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low Vendor pom description Apache Log4j 1.2 Medium Vendor pom artifactid log4j Low Vendor pom name Apache Log4j High Vendor Manifest bundle-symbolicname log4j Medium Vendor manifest Bundle-Description Apache Log4j 1.2 Medium Vendor manifest: org.apache.log4j Implementation-Vendor "Apache Software Foundation" Medium Vendor pom organization name Apache Software Foundation High Vendor file name log4j High Vendor pom organization url http://www.apache.org Medium Vendor pom groupid log4j Highest Vendor pom url http://logging.apache.org/log4j/1.2/ Highest Product Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low Product pom organization name Apache Software Foundation Low Product pom description Apache Log4j 1.2 Medium Product pom name Apache Log4j High Product pom url http://logging.apache.org/log4j/1.2/ Medium Product pom groupid log4j Low Product Manifest bundle-symbolicname log4j Medium Product pom artifactid log4j Highest Product manifest Bundle-Description Apache Log4j 1.2 Medium Product pom organization url http://www.apache.org Low Product manifest: org.apache.log4j Implementation-Title log4j Medium Product file name log4j High Product Manifest Bundle-Name Apache Log4j Medium Version file version 1.2.17 Highest Version pom version 1.2.17 Highest
Related Dependencies log4j-1.2.17.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/log4j-1.2.17.jar MD5: 04a41f0a068986f0f73485cf507c0f40 SHA1: 5af35056b4d257e4b64b9e8069c0746e8b08629f SHA256: 1d31696445697720527091754369082a6651bd49781b6005deb94e56753406f9 cpe: cpe:/a:apache:log4j:1.2.17 Confidence :Low suppress maven: log4j:log4j:1.2.17 Confidence :High mail-1.4.2.jarDescription:
JavaMail API License:
http://www.sun.com/cddl, https://glassfish.dev.java.net/public/CDDL+GPL.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/mail-1.4.2.jar
MD5: 81e2cd97e84fb814dfd0018bb8782c81
SHA1: 6a1d836b6a4c77ec11ac46d2ea8557ca574cd428
SHA256: be03dd1caa2f93d7f75d06637ea11e4c1b1ea322a7afd057cbf8b08f87932987
Evidence Type Source Name Value Confidence Vendor pom groupid javax.mail Highest Vendor pom parent-artifactid all Low Vendor Manifest bundle-symbolicname javax.mail.mail Medium Vendor Manifest extension-name javax.mail Medium Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor pom name JavaMail API High Vendor pom artifactid mail Low Vendor Manifest bundle-docurl http://www.sun.com Low Vendor pom parent-groupid com.sun.mail Medium Vendor file name mail High Vendor manifest Bundle-Description JavaMail API Medium Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest hk2-bundle-name javax.mail:mail Medium Product Manifest bundle-symbolicname javax.mail.mail Medium Product Manifest extension-name javax.mail Medium Product Manifest Bundle-Name JavaMail API Medium Product Manifest Implementation-Title javax.mail High Product Manifest specification-title JavaMail(TM) API Design Specification Medium Product pom name JavaMail API High Product Manifest bundle-docurl http://www.sun.com Low Product file name mail High Product manifest Bundle-Description JavaMail API Medium Product pom parent-groupid com.sun.mail Low Product Manifest hk2-bundle-name javax.mail:mail Medium Product pom groupid javax.mail Low Product pom artifactid mail Highest Product pom parent-artifactid all Medium Version Manifest Implementation-Version 1.4.2 High Version pom version 1.4.2 Highest Version file version 1.4.2 Highest
maven-parent-config-0.3.4.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/maven-parent-config-0.3.4.jarMD5: aaf25e6f75341a109323d00ed823c596SHA1: b2ac776e18fda81b7e1487d32e13a5618281c4d8SHA256: 9a087f524b7d8f049b49c88e9b097b3101eea624ad04a93c638de63701fa81e4
Evidence Type Source Name Value Confidence Vendor file name maven-parent-config High Vendor pom parent-artifactid maven-parent Low Vendor pom artifactid maven-parent-config Low Vendor pom groupid de.agilecoders.maven Highest Product file name maven-parent-config High Product pom parent-artifactid maven-parent Medium Product pom groupid de.agilecoders.maven Low Product pom artifactid maven-parent-config Highest Version file version 0.3.4 Highest Version pom version 0.3.4 Highest
maven: de.agilecoders.maven:maven-parent-config:0.3.4 Confidence :High mockito-all-1.9.5.jarDescription:
Mock objects library for java License:
The MIT License: http://code.google.com/p/mockito/wiki/License File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/mockito-all-1.9.5.jar
MD5: 50faa79d126d0213ab14ccb112a8b76d
SHA1: 79a8984096fc6591c1e3690e07d41be506356fa5
SHA256: b2a63307d1dce3aa1623fdaacb2327a4cd7795b0066f31bf542b1e8f2683239e
Evidence Type Source Name Value Confidence Vendor pom groupid mockito Highest Vendor pom artifactid mockito-all Low Vendor pom description Mock objects library for java Medium Vendor pom name Mockito High Vendor file name mockito-all High Vendor Manifest bundle-symbolicname org.mockito.mockito-all Medium Vendor central groupid org.mockito Highest Vendor pom url http://www.mockito.org Highest Vendor jar package name mockito Low Product Manifest Bundle-Name Mockito Mock Library for Java. Hamcrest-core & Objenesis included in the bundle. Medium Product central artifactid mockito-all Highest Product pom groupid mockito Low Product pom description Mock objects library for java Medium Product pom name Mockito High Product file name mockito-all High Product Manifest bundle-symbolicname org.mockito.mockito-all Medium Product pom url http://www.mockito.org Medium Product pom artifactid mockito-all Highest Version file version 1.9.5 Highest Version central version 1.9.5 Highest Version pom version 1.9.5 Highest
modernizr-2.6.2-1.jarDescription:
WebJar for Modernizr License:
MIT License: http://en.wikipedia.org/wiki/MIT_License File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/modernizr-2.6.2-1.jar
MD5: 6fb51714f12c1cc66763fd5467abfdb4
SHA1: 86cc31cc6a32f81be5074f9fa27cf53d5e210198
SHA256: 7076ac7d1e598173386608a207bde0ac0a9bc51f86c4e92583281a69d0abfb63
Evidence Type Source Name Value Confidence Vendor pom description WebJar for Modernizr Medium Vendor pom groupid webjars Highest Vendor pom artifactid modernizr Low Vendor file name modernizr High Vendor pom name Modernizr High Vendor pom url http://webjars.org Highest Product pom groupid webjars Low Product pom artifactid modernizr Highest Product pom description WebJar for Modernizr Medium Product file name modernizr High Product pom url http://webjars.org Medium Product pom name Modernizr High Version file version 2.6.2.1 Highest Version pom version 2.6.2-1 Highest
maven: org.webjars:modernizr:2.6.2-1 Confidence :High neethi-3.0.1.jarDescription:
Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/neethi-3.0.1.jar
MD5: bf9e9783665575a7465f112e1a5594ca
SHA1: 9e4a9d3ebab53720bccbafacc7495e801a6256c6
SHA256: cad5f8a6327679a90552597dc4f65e6c472ffcf268223212c13626dc9d7e1a43
Evidence Type Source Name Value Confidence Vendor pom groupid apache.neethi Highest Vendor pom name Apache Neethi High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor manifest Bundle-Description Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities. Low Vendor pom organization url http://www.apache.org/ Medium Vendor pom organization name The Apache Software Foundation High Vendor file name neethi High Vendor pom url http://ws.apache.org/neethi/ Highest Vendor Manifest bundle-symbolicname org.apache.neethi Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom artifactid neethi Low Vendor pom description Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities. Low Product Manifest Implementation-Title Apache Neethi High Product pom organization name The Apache Software Foundation Low Product pom organization url http://www.apache.org/ Low Product Manifest specification-title Apache Neethi Medium Product pom parent-groupid org.apache Low Product pom name Apache Neethi High Product manifest Bundle-Description Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities. Low Product pom artifactid neethi Highest Product file name neethi High Product Manifest bundle-symbolicname org.apache.neethi Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product Manifest Bundle-Name Apache Neethi Medium Product pom groupid apache.neethi Low Product pom url http://ws.apache.org/neethi/ Medium Product pom parent-artifactid apache Medium Product pom description Apache Neethi provides general framework for the programmers to use WS Policy. It is compliant with latest WS Policy specification which was published in March 2006. This framework is specifically written to enable the Apache Web services stack to use WS Policy as a way of expressing it's requirements and capabilities. Low Version pom version 3.0.1 Highest Version Manifest Implementation-Version 3.0.1 High Version file version 3.0.1 Highest
maven: org.apache.neethi:neethi:3.0.1 Confidence :Highcpe: cpe:/a:apache:apache_test:3.0.1 Confidence :Low suppress netty-3.6.2.Final.jarDescription:
The Netty project is an effort to provide an asynchronous event-driven
network application framework and tools for rapid development of
maintainable high performance and high scalability protocol servers and
clients. In other words, Netty is a NIO client server framework which
enables quick and easy development of network applications such as protocol
servers and clients. It greatly simplifies and streamlines network
programming such as TCP and UDP socket server.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/netty-3.6.2.Final.jar
MD5: 65546c0885e83ba36f1f4d9ff9f8c776
SHA1: 69be11c61427f0604a30539755add84ad9e37e5e
SHA256: d4ff9f0a2959633e062edd0e678d8187bbe95ad19195384ac524fd41f00f5a44
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://netty.io/ Low Vendor pom groupid io.netty Highest Vendor pom organization name The Netty Project High Vendor pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Vendor Manifest bundle-symbolicname org.jboss.netty Medium Vendor pom name The Netty Project High Vendor pom organization url http://netty.io/ Medium Vendor pom artifactid netty Low Vendor file name netty High Vendor pom url http://netty.io/ Highest Vendor manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product pom url http://netty.io/ Medium Product pom organization url http://netty.io/ Low Product pom organization name The Netty Project Low Product pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product pom name The Netty Project High Product pom artifactid netty Highest Product file name netty High Product pom groupid io.netty Low Product Manifest bundle-docurl http://netty.io/ Low Product Manifest Bundle-Name The Netty Project Medium Product Manifest bundle-symbolicname org.jboss.netty Medium Product manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Version pom version 3.6.2.Final Highest Version file version 3.6.2 Highest
Published Vulnerabilities CVE-2014-0193 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames. Vulnerable Software & Versions: (show all )
CVE-2014-3488 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message. Vulnerable Software & Versions: (show all )
CVE-2015-2156 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-20 Improper Input Validation
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters. Vulnerable Software & Versions: (show all )
noggit-0.5.jarDescription:
Fast streaming JSON parser for Java License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/noggit-0.5.jar
MD5: c999a28fd0788cca79fb64460a36b0af
SHA1: 8e6e65624d2e09a30190c6434abe23b7d4e5413c
SHA256: 3ded7e6cff8702e3bcde8bf34d359c9c576cfe3d7a90dd38fa743d582b566ab6
Evidence Type Source Name Value Confidence Vendor pom url http://noggit.org Highest Vendor pom groupid noggit Highest Vendor pom artifactid noggit Low Vendor pom name Noggit High Vendor pom description Fast streaming JSON parser for Java Medium Vendor file name noggit High Vendor jar package name noggit Low Product pom url http://noggit.org Medium Product pom name Noggit High Product pom description Fast streaming JSON parser for Java Medium Product file name noggit High Product pom groupid noggit Low Product pom artifactid noggit Highest Version pom version 0.5 Highest Version file version 0.5 Highest
Related Dependencies noggit-0.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/noggit-0.5.jar MD5: c999a28fd0788cca79fb64460a36b0af SHA1: 8e6e65624d2e09a30190c6434abe23b7d4e5413c SHA256: 3ded7e6cff8702e3bcde8bf34d359c9c576cfe3d7a90dd38fa743d582b566ab6 maven: org.noggit:noggit:0.5 Confidence :High org.restlet-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/org.restlet-2.2.3.jarMD5: 0ca74b39e833efc4bc67dd494b4cfa88SHA1: b5743deba825f3b4bf54c87b9cfa4fc952e0ff74SHA256: a1bcc6ec92955721f4df65c649a0b67e218cdd876f3694b8104b54f085684ae6
Evidence Type Source Name Value Confidence Vendor jar package name engine Low Vendor jar package name restlet Low Vendor file name org.restlet High Product jar package name engine Low Product file name org.restlet High Version file version 2.2.3 Highest Version file name org.restlet Medium
Related Dependencies org.restlet.ext.crypto-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/org.restlet.ext.crypto-2.2.3.jar MD5: 2c4bf7cb31e3d09c962fab8042194db3 SHA1: 4fc84b3103632e2d4e4885a5e41f9580bceacced SHA256: 23b2928bc5db98357c49238b98d9930f6e5956912584240bf188c69243da3e3d org.restlet.ext.jaxrs-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/org.restlet.ext.jaxrs-2.2.3.jar MD5: e1de5b0c0b683c39ba7ecc1e1e5d8d49 SHA1: 83987e4f064595679eb0609a9eedaa7eac648980 SHA256: 04c6135abe20bd7f8c6d86fcc2a7d8124bd118d1de1a414f3dbc4db504bf078b org.restlet.ext.jackson-2.2.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/org.restlet.ext.jackson-2.2.3.jar MD5: 4202d222aaac56ad2ce9316edc0750aa SHA1: d4c65076876cb1900c8d9e4a2f0a799f540c67e9 SHA256: e6b170cc7b7337c5647da780ed157722b8a638504136615fc3d891a4c6d93962 cpe: cpe:/a:restlet:restlet_framework:2.2.3 Confidence :Low suppress cpe: cpe:/a:restlet:restlet:2.2.3 Confidence :Low suppress org.restlet.lib.org.json-2.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/org.restlet.lib.org.json-2.0.jarMD5: c8f97873c021adc0771e2348eb2c50f2SHA1: aa0e3bef5e0c3660a3e69529a3d8b71b4ecd291aSHA256: 2beae160ea6c32e0cb9a4e2fdc14b0ec7c5d0013107c516e111d978b5c3487cf
Evidence Type Source Name Value Confidence Vendor jar package name json Low Vendor file name org.restlet.lib.org.json High Product file name org.restlet.lib.org.json High Version file version 2.0 Highest Version file name org.restlet.lib.org.json Medium
cpe: cpe:/a:restlet:restlet:2.0 Confidence :Low suppress cpe: cpe:/a:restlet:restlet_framework:2.0 Confidence :Low suppress Published Vulnerabilities CVE-2013-4221 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-16 Configuration
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML. Vulnerable Software & Versions: (show all )
CVE-2013-4271 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221. Vulnerable Software & Versions: (show all )
CVE-2014-1868 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack. Vulnerable Software & Versions: (show all )
ormlite-core-4.48.jarDescription:
Lightweight Object Relational Model (ORM) for persisting objects to SQL databases. License:
ISC License: http://ormlite.com/docs/license File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/ormlite-core-4.48.jar
MD5: 74d1b09c4d0e3e216b0584485208c515
SHA1: e579bd2905d0399af5029aaaf9817d5fa0ca88a5
SHA256: 2beb9bd890a705fe25f6d74c7b1fdb5667da09f7063ba8e8eb501cb899dd5002
Evidence Type Source Name Value Confidence Vendor pom groupid j256.ormlite Highest Vendor pom artifactid ormlite-core Low Vendor pom name ORMLite Core High Vendor file name ormlite-core High Vendor pom description Lightweight Object Relational Model (ORM) for persisting objects to SQL databases. Medium Vendor pom url http://ormlite.sourceforge.net/ Highest Product pom groupid j256.ormlite Low Product pom artifactid ormlite-core Highest Product pom name ORMLite Core High Product file name ormlite-core High Product pom description Lightweight Object Relational Model (ORM) for persisting objects to SQL databases. Medium Product pom url http://ormlite.sourceforge.net/ Medium Version pom version 4.48 Highest Version file version 4.48 Highest
maven: com.j256.ormlite:ormlite-core:4.48 Confidence :High ormlite-jdbc-4.48.jarDescription:
Lightweight Object Relational Model (ORM) JDBC classes License:
ISC License: http://ormlite.com/docs/license File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/ormlite-jdbc-4.48.jar
MD5: aa6e8074f3cfc64a417fc6efa7004b56
SHA1: b915ebd2c4b901eec32e4df44e5503752e92ce38
SHA256: be89e2433f2b3528666d2845177237545d75d5183ce45709885f6edac9c53f58
Evidence Type Source Name Value Confidence Vendor file name ormlite-jdbc High Vendor pom groupid j256.ormlite Highest Vendor pom name ORMLite JDBC High Vendor pom description Lightweight Object Relational Model (ORM) JDBC classes Medium Vendor pom url http://ormlite.sourceforge.net/ Highest Vendor pom artifactid ormlite-jdbc Low Product file name ormlite-jdbc High Product pom groupid j256.ormlite Low Product pom name ORMLite JDBC High Product pom description Lightweight Object Relational Model (ORM) JDBC classes Medium Product pom artifactid ormlite-jdbc Highest Product pom url http://ormlite.sourceforge.net/ Medium Version pom version 4.48 Highest Version file version 4.48 Highest
maven: com.j256.ormlite:ormlite-jdbc:4.48 Confidence :High paranamer-2.7.jarDescription:
Paranamer allows runtime access to constructor and method parameter names for Java classes License:
LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/paranamer-2.7.jar
MD5: 5707a297363249fffe38e8189cd6f9cb
SHA1: 3ed64c69e882a324a75e890024c32a28aff0ade8
SHA256: 63e3f53f8f70784b65c25b2ee475813979d6d0e7f7b2510b364c4e1f4a803ccc
Evidence Type Source Name Value Confidence Vendor pom groupid thoughtworks.paranamer Highest Vendor pom name ParaNamer Core High Vendor manifest Bundle-Description Paranamer allows runtime access to constructor and method parameter names for Java classes Medium Vendor file name paranamer High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor pom parent-groupid com.thoughtworks.paranamer Medium Vendor Manifest bundle-symbolicname com.thoughtworks.paranamer Medium Vendor pom artifactid paranamer Low Vendor pom parent-artifactid paranamer-parent Low Product pom name ParaNamer Core High Product manifest Bundle-Description Paranamer allows runtime access to constructor and method parameter names for Java classes Medium Product file name paranamer High Product pom groupid thoughtworks.paranamer Low Product Manifest Bundle-Name ParaNamer Core Medium Product pom parent-groupid com.thoughtworks.paranamer Low Product pom parent-artifactid paranamer-parent Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product pom artifactid paranamer Highest Product Manifest bundle-symbolicname com.thoughtworks.paranamer Medium Version file version 2.7 Highest Version pom version 2.7 Highest
maven: com.thoughtworks.paranamer:paranamer:2.7 Confidence :High protobuf-java-2.5.0.jarDescription:
Protocol Buffers are a way of encoding structured data in an efficient yet
extensible format.
License:
New BSD license: http://www.opensource.org/licenses/bsd-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/protobuf-java-2.5.0.jar
MD5: a44473b98947e2a54c54e0db1387d137
SHA1: a10732c76bfacdbd633a7eb0f7968b1059a65dfa
SHA256: e0c1c64575c005601725e7c6a02cebf9e1285e888f756b2a1d73ffa8d725cc74
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname com.google.protobuf Medium Vendor pom parent-groupid com.google Medium Vendor pom url http://code.google.com/p/protobuf Highest Vendor pom artifactid protobuf-java Low Vendor pom name Protocol Buffer Java API High Vendor pom parent-artifactid google Low Vendor Manifest bundle-docurl http://code.google.com/p/protobuf Low Vendor manifest Bundle-Description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Medium Vendor pom groupid google.protobuf Highest Vendor file name protobuf-java High Vendor pom description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low Product pom parent-groupid com.google Low Product pom groupid google.protobuf Low Product pom parent-artifactid google Medium Product Manifest Bundle-Name Protocol Buffer Java API Medium Product pom name Protocol Buffer Java API High Product manifest Bundle-Description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Medium Product pom artifactid protobuf-java Highest Product file name protobuf-java High Product pom description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low Product Manifest bundle-symbolicname com.google.protobuf Medium Product pom url http://code.google.com/p/protobuf Medium Product Manifest bundle-docurl http://code.google.com/p/protobuf Low Version pom version 2.5.0 Highest Version file version 2.5.0 Highest
Related Dependencies protobuf-java-2.5.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/protobuf-java-2.5.0.jar MD5: a44473b98947e2a54c54e0db1387d137 SHA1: a10732c76bfacdbd633a7eb0f7968b1059a65dfa SHA256: e0c1c64575c005601725e7c6a02cebf9e1285e888f756b2a1d73ffa8d725cc74 protobuf-java-2.5.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/protobuf-java-2.5.0.jar MD5: a44473b98947e2a54c54e0db1387d137 SHA1: a10732c76bfacdbd633a7eb0f7968b1059a65dfa SHA256: e0c1c64575c005601725e7c6a02cebf9e1285e888f756b2a1d73ffa8d725cc74 Published Vulnerabilities CVE-2015-5237 suppress
Severity:Medium CVSS Score: 6.5 (AV:N/AC:L/Au:S/C:P/I:P/A:P) CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow. Vulnerable Software & Versions: (show all )
reflections-0.9.8.jarDescription:
Reflections - a Java runtime metadata analysis File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/reflections-0.9.8.jarMD5: 46192a2539fbe9e1fb69f8e5764e3aaaSHA1: f723abb59bf512952bfc503838f70f81487a6993SHA256: 790492c3d177c4121d7ed84edad57c591569d124a58a5c503420004e7a95f9d6
Evidence Type Source Name Value Confidence Vendor file name reflections High Vendor pom description Reflections - a Java runtime metadata analysis Medium Vendor pom url http://code.google.com/p/reflections/ Highest Vendor pom groupid reflections Highest Vendor pom artifactid reflections Low Vendor pom parent-groupid org.reflections Medium Vendor jar package name reflections Low Vendor pom parent-artifactid reflections-parent Low Vendor pom name Reflections High Product file name reflections High Product pom groupid reflections Low Product pom description Reflections - a Java runtime metadata analysis Medium Product pom parent-groupid org.reflections Low Product pom parent-artifactid reflections-parent Medium Product pom url http://code.google.com/p/reflections/ Medium Product pom artifactid reflections Highest Product pom name Reflections High Version pom version 0.9.8 Highest Version file version 0.9.8 Highest
maven: org.reflections:reflections:0.9.8 Confidence :High serializer-2.7.1.jarDescription:
Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input
SAX events.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/serializer-2.7.1.jarMD5: a6b64dfe58229bdd810263fa0cc54cffSHA1: 4b4b18df434451249bb65a63f2fb69e215a6a020SHA256: a15078d243d4a20b6b4e8ae2f61ed4655e352054e121aada6f7441f1ed445a3c
Evidence Type Source Name Value Confidence Vendor manifest: org/apache/xml/serializer/utils/ Implementation-Vendor Apache Software Foundation Medium Vendor pom name Xalan Java Serializer High Vendor pom artifactid serializer Low Vendor jar package name xml Low Vendor jar package name serializer Low Vendor manifest: org/apache/xml/serializer/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name apache Low Vendor pom url http://xml.apache.org/xalan-j/ Highest Vendor file name serializer High Vendor pom parent-artifactid apache Low Vendor central groupid xalan Highest Vendor pom parent-groupid org.apache Medium Vendor pom description Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input SAX events. Low Vendor pom groupid xalan Highest Product pom groupid xalan Low Product pom name Xalan Java Serializer High Product pom parent-groupid org.apache Low Product pom url http://xml.apache.org/xalan-j/ Medium Product manifest: org/apache/xml/serializer/utils/ Implementation-Title org.apache.xml.serializer.utils Medium Product manifest: org/apache/xml/serializer/ Implementation-Title org.apache.xml.serializer Medium Product jar package name xml Low Product jar package name serializer Low Product file name serializer High Product pom parent-artifactid apache Medium Product central artifactid serializer Highest Product pom artifactid serializer Highest Product pom description Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input SAX events. Low Product manifest: org/apache/xml/serializer/ Specification-Title XSL Transformations (XSLT), at http://www.w3.org/TR/xslt Medium Version central version 2.7.1 Highest Version pom version 2.7.1 Highest Version file version 2.7.1 Highest
Published Vulnerabilities CVE-2014-0107 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-264 Permissions, Privileges, and Access Controls
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function. Vulnerable Software & Versions: (show all )
servlet-api-2.5-20081211.jarDescription:
Servlet Specification API License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/servlet-api-2.5-20081211.jar
MD5: 083898d794cc261853922ca941aee390
SHA1: 22bff70037e1e6fa7e6413149489552ee2064702
SHA256: 068756096996fe00f604ac3b6672d6f663dc777ea4a83056e240d0456e77e472
Evidence Type Source Name Value Confidence Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor pom name Servlet Specification API High Vendor manifest Bundle-Description Servlet Specification API Medium Vendor Manifest bundle-symbolicname org.mortbay.jetty.servlet-api Medium Vendor Manifest Implementation-Vendor JCP High Vendor pom artifactid servlet-api Low Vendor file name servlet-api High Vendor pom parent-artifactid jetty-parent Low Vendor pom parent-groupid org.mortbay.jetty Medium Vendor Manifest originally-created-by 1.5.0_13 (Sun Microsystems Inc.) Low Vendor pom description Servlet Specification API Medium Vendor Manifest bundle-docurl http://www.mortbay.com Low Vendor pom groupid mortbay.jetty Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product pom groupid mortbay.jetty Low Product pom name Servlet Specification API High Product manifest Bundle-Description Servlet Specification API Medium Product Manifest bundle-symbolicname org.mortbay.jetty.servlet-api Medium Product Manifest Bundle-Name Servlet Specification API Medium Product file name servlet-api High Product pom parent-groupid org.mortbay.jetty Low Product Manifest originally-created-by 1.5.0_13 (Sun Microsystems Inc.) Low Product pom description Servlet Specification API Medium Product Manifest bundle-docurl http://www.mortbay.com Low Product pom parent-artifactid jetty-parent Medium Product pom artifactid servlet-api Highest Version file version 2.5.20081211 Highest Version pom version 2.5-20081211 Highest
cpe: cpe:/a:mortbay:jetty:2.5.200812 Confidence :Low suppress maven: org.mortbay.jetty:servlet-api:2.5-20081211 Confidence :Highcpe: cpe:/a:mortbay_jetty:jetty:2.5.200812 Confidence :Low suppress cpe: cpe:/a:jetty:jetty:2.5.200812 Confidence :Low suppress Published Vulnerabilities CVE-2005-3747 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758. Vulnerable Software & Versions: (show all )
CVE-2007-5615 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')
CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. Vulnerable Software & Versions:
CVE-2009-1523 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI. Vulnerable Software & Versions: (show all )
CVE-2009-1524 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character. Vulnerable Software & Versions: (show all )
CVE-2011-4461 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-310 Cryptographic Issues
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Vulnerable Software & Versions: (show all )
servlet-api-2.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/servlet-api-2.5.jarMD5: 69ca51af4e9a67a1027a7f95b52c3e8fSHA1: 5959582d97d8b61f4d154ca9e495aafd16726e34SHA256: c658ea360a70faeeadb66fb3c90a702e4142a0ab7768f9ae9828678e0d9ad4dc
Evidence Type Source Name Value Confidence Vendor pom artifactid servlet-api-2.5 Low Vendor pom artifactid servlet-api Low Vendor Manifest specification-vendor Sun Microsystems Inc Low Vendor Manifest Implementation-Vendor Sun Microsystems Inc High Vendor pom groupid zenframework.z8.dependencies.servlet Highest Vendor pom name Zenframework Z8 Dependencies - Servlet - servlet-api-2.5 High Vendor file name servlet-api High Vendor jar package name javax Low Vendor Manifest extension-name servlet-api Medium Vendor jar package name servlet Low Vendor pom parent-groupid org.zenframework.z8.dependencies Medium Vendor central groupid javax.servlet High Vendor pom parent-artifactid z8-dependencies Low Vendor pom groupid javax.servlet Highest Vendor central groupid org.zenframework.z8.dependencies.servlet High Product Manifest specification-title A component of the Glassfish Application Server Medium Product pom groupid javax.servlet Low Product Manifest Implementation-Title High Product pom artifactid servlet-api-2.5 Highest Product pom name Zenframework Z8 Dependencies - Servlet - servlet-api-2.5 High Product file name servlet-api High Product central artifactid servlet-api-2.5 High Product Manifest extension-name servlet-api Medium Product jar package name servlet Low Product pom parent-groupid org.zenframework.z8.dependencies Low Product pom groupid zenframework.z8.dependencies.servlet Low Product pom parent-artifactid z8-dependencies Medium Product central artifactid servlet-api High Product pom artifactid servlet-api Highest Version file version 2.5 Highest Version Manifest Implementation-Version 2.5 High Version pom version 2.0 Highest Version central version 2.0 High Version central version 2.5 High Version pom version 2.5 Highest
slf4j-api-1.7.7.jarDescription:
The slf4j API File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/slf4j-api-1.7.7.jarMD5: ca4280bf93d64367723ae5c8d42dd0b9SHA1: 2b8019b6249bb05d81d3a3094e468753e2b21311SHA256: 69980c038ca1b131926561591617d9c25fabfc7b29828af91597ca8570cf35fe
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor pom artifactid slf4j-api Low Vendor pom description The slf4j API Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Vendor pom url http://www.slf4j.org Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor manifest Bundle-Description The slf4j API Medium Vendor pom name SLF4J API Module High Vendor pom groupid slf4j Highest Vendor pom parent-groupid org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Product pom groupid slf4j Low Product pom description The slf4j API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Product pom parent-groupid org.slf4j Low Product pom artifactid slf4j-api Highest Product manifest Bundle-Description The slf4j API Medium Product pom name SLF4J API Module High Product pom url http://www.slf4j.org Medium Product file name slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Bundle-Name slf4j-api Medium Product Manifest Implementation-Title slf4j-api High Product pom parent-artifactid slf4j-parent Medium Version Manifest Implementation-Version 1.7.7 High Version file version 1.7.7 Highest Version pom version 1.7.7 Highest
cpe: cpe:/a:slf4j:slf4j:1.7.7 Confidence :Low suppress maven: org.slf4j:slf4j-api:1.7.7 Confidence :High slf4j-log4j12-1.7.5.jarDescription:
SLF4J LOG4J-12 Binding File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/slf4j-log4j12-1.7.5.jarMD5: 371e35747d6bd35e3800034bdac4150eSHA1: 6edffc576ce104ec769d954618764f39f0f0f10dSHA256: e3393b87604eeab24d72d71d0bfceb3436658ab0593f48f16523ad90f270c88f
Evidence Type Source Name Value Confidence Vendor pom name SLF4J LOG4J-12 Binding High Vendor Manifest bundle-symbolicname slf4j.log4j12 Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Vendor pom url http://www.slf4j.org Highest Vendor manifest Bundle-Description SLF4J LOG4J-12 Binding Medium Vendor pom artifactid slf4j-log4j12 Low Vendor pom description SLF4J LOG4J-12 Binding Medium Vendor file name slf4j-log4j12 High Vendor pom groupid slf4j Highest Vendor pom parent-groupid org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Product Manifest Implementation-Title slf4j-log4j12 High Product pom groupid slf4j Low Product pom name SLF4J LOG4J-12 Binding High Product Manifest bundle-symbolicname slf4j.log4j12 Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Product pom parent-groupid org.slf4j Low Product pom description SLF4J LOG4J-12 Binding Medium Product pom url http://www.slf4j.org Medium Product Manifest Bundle-Name slf4j-log4j12 Medium Product manifest Bundle-Description SLF4J LOG4J-12 Binding Medium Product pom artifactid slf4j-log4j12 Highest Product file name slf4j-log4j12 High Product pom parent-artifactid slf4j-parent Medium Version pom version 1.7.5 Highest Version file version 1.7.5 Highest Version Manifest Implementation-Version 1.7.5 High
maven: org.slf4j:slf4j-log4j12:1.7.5 Confidence :Highcpe: cpe:/a:slf4j:slf4j:1.7.5 Confidence :Low suppress snakeyaml-1.13.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License Version 2.0: LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/snakeyaml-1.13.jar
MD5: 88e239ab48632e2eab576ee86f56c47e
SHA1: 73cbb494a912866c4c831a178c3a2a9169f4eaad
SHA256: eebdfdc186a16cc52301d05e63730d3cf60b4eca62d9259e945025580dc274a9
Evidence Type Source Name Value Confidence Vendor pom description YAML 1.1 parser and emitter for Java Medium Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor pom groupid yaml Highest Vendor pom artifactid snakeyaml Low Vendor pom url http://www.snakeyaml.org Highest Vendor manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium Vendor pom name SnakeYAML High Vendor file name snakeyaml High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom description YAML 1.1 parser and emitter for Java Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium Product pom name SnakeYAML High Product pom groupid yaml Low Product pom artifactid snakeyaml Highest Product file name snakeyaml High Product pom url http://www.snakeyaml.org Medium Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Version file version 1.13 Highest Version pom version 1.13 Highest
maven: org.yaml:snakeyaml:1.13 Confidence :High snappy-java-1.1.1.3.jarDescription:
snappy-java: A fast compression/decompression library License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/snappy-java-1.1.1.3.jar
MD5: a73387268491e264935ea46e49011ed0
SHA1: fbd7b0b8400ebd0d6a2c61493f39530a93d9c4b6
SHA256: 4882736281544083b7d140d03b7346b9ecda834df886561ad3eae25375034592
Evidence Type Source Name Value Confidence Vendor jar package name snappy Low Vendor pom organization name xerial.org High Vendor Manifest bundle-docurl http://www.xerial.org/ Low Vendor pom groupid xerial.snappy Highest Vendor jar package name xerial Low Vendor file name snappy-java High Vendor central groupid org.xerial.snappy Highest Vendor pom url https://github.comm/xerial/snappy-java Highest Vendor Manifest bundle-symbolicname org.xerial.snappy.snappy-java Medium Vendor pom artifactid snappy-java Low Vendor Manifest bundle-nativecode org/xerial/snappy/native/Windows/x86_64/snappyjava.dll;osname=win32;processor=x86-64,org/xerial/snappy/native/Windows/x86/snappyjava.dll;osname=win32;processor=x86,org/xerial/snappy/native/Mac/x86/libsnappyjava.jnilib;osname=macosx;processor=x86,org/xerial/snappy/native/Mac/x86_64/libsnappyjava.jnilib;osname=macosx;processor=x86-64,org/xerial/snappy/native/Linux/x86_64/libsnappyjava.so;osname=linux;processor=x86-64,org/xerial/snappy/native/Linux/x86/libsnappyjava.so;osname=linux;processor=x86,org/xerial/snappy/native/Linux/arm/libsnappyjava.so;osname=linux;processor=arm,org/xerial/snappy/native/Linux/ppc64/libsnappyjava.so;osname=linux;processor=ppc64,org/xerial/snappy/native/Linux/ppc64le/libsnappyjava.so;osname=linux;processor=ppc64le,org/xerial/snappy/native/AIX/ppc64/libsnappyjava.a;osname=aix;processor=ppc64,org/xerial/snappy/native/SunOS/x86/libsnappyjava.so;osname=sunos;processor=x86,org/xerial/snappy/native/SunOS/x86_64/libsnappyjava.so;osname=sunos;processor=x86-64,org/xerial/snappy/native/SunOS/sparc/libsnappyjava.so;osname=sunos;processor=sparc Low Vendor pom description snappy-java: A fast compression/decompression library Medium Vendor pom name snappy-java High Product jar package name snappy Low Product Manifest bundle-docurl http://www.xerial.org/ Low Product pom artifactid snappy-java Highest Product pom url https://github.comm/xerial/snappy-java Medium Product file name snappy-java High Product central artifactid snappy-java Highest Product pom groupid xerial.snappy Low Product pom organization name xerial.org Low Product Manifest bundle-symbolicname org.xerial.snappy.snappy-java Medium Product Manifest Bundle-Name snappy-java: A fast compression/decompression library Medium Product Manifest bundle-nativecode org/xerial/snappy/native/Windows/x86_64/snappyjava.dll;osname=win32;processor=x86-64,org/xerial/snappy/native/Windows/x86/snappyjava.dll;osname=win32;processor=x86,org/xerial/snappy/native/Mac/x86/libsnappyjava.jnilib;osname=macosx;processor=x86,org/xerial/snappy/native/Mac/x86_64/libsnappyjava.jnilib;osname=macosx;processor=x86-64,org/xerial/snappy/native/Linux/x86_64/libsnappyjava.so;osname=linux;processor=x86-64,org/xerial/snappy/native/Linux/x86/libsnappyjava.so;osname=linux;processor=x86,org/xerial/snappy/native/Linux/arm/libsnappyjava.so;osname=linux;processor=arm,org/xerial/snappy/native/Linux/ppc64/libsnappyjava.so;osname=linux;processor=ppc64,org/xerial/snappy/native/Linux/ppc64le/libsnappyjava.so;osname=linux;processor=ppc64le,org/xerial/snappy/native/AIX/ppc64/libsnappyjava.a;osname=aix;processor=ppc64,org/xerial/snappy/native/SunOS/x86/libsnappyjava.so;osname=sunos;processor=x86,org/xerial/snappy/native/SunOS/x86_64/libsnappyjava.so;osname=sunos;processor=x86-64,org/xerial/snappy/native/SunOS/sparc/libsnappyjava.so;osname=sunos;processor=sparc Low Product pom description snappy-java: A fast compression/decompression library Medium Product pom name snappy-java High Version central version 1.1.1.3 Highest Version pom version 1.1.1.3 Highest Version file version 1.1.1.3 Highest
solr-solrj-4.6.0.jarDescription:
Apache Solr Solrj File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/solr-solrj-4.6.0.jarMD5: 675a97ea155a073aa83708dcb6b06d14SHA1: 708abed2f1403b4e320ba060d1d9b3377dc4b9baSHA256: 78da47e5e0de71f4111348bc20941c0cd27a1667bae265344623c3c6d99f41c1
Evidence Type Source Name Value Confidence Vendor pom name Apache Solr Solrj High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name solr Low Vendor jar package name apache Low Vendor pom artifactid solr-solrj Low Vendor pom parent-artifactid solr-parent Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.solr Medium Vendor pom groupid apache.solr Highest Vendor pom description Apache Solr Solrj Medium Vendor central groupid org.apache.solr Highest Vendor file name solr-solrj High Vendor jar package name client Low Vendor pom parent-groupid org.apache.solr Medium Product pom artifactid solr-solrj Highest Product pom parent-groupid org.apache.solr Low Product Manifest Implementation-Title org.apache.solr High Product pom name Apache Solr Solrj High Product pom groupid apache.solr Low Product jar package name solr Low Product pom parent-artifactid solr-parent Medium Product central artifactid solr-solrj Highest Product Manifest extension-name org.apache.solr Medium Product pom description Apache Solr Solrj Medium Product jar package name solrj Low Product file name solr-solrj High Product Manifest specification-title Apache Solr Search Server: solr-solrj Medium Product jar package name client Low Version central version 4.6.0 Highest Version pom version 4.6.0 Highest Version file version 4.6.0 Highest
Related Dependencies solr-solrj-4.6.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/solr-solrj-4.6.0.jar MD5: 675a97ea155a073aa83708dcb6b06d14 SHA1: 708abed2f1403b4e320ba060d1d9b3377dc4b9ba SHA256: 78da47e5e0de71f4111348bc20941c0cd27a1667bae265344623c3c6d99f41c1 Published Vulnerabilities CVE-2014-3628 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object. Vulnerable Software & Versions: (show all )
CVE-2015-8795 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js. Vulnerable Software & Versions:
CVE-2015-8796 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL. Vulnerable Software & Versions:
CVE-2015-8797 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI. Vulnerable Software & Versions:
CVE-2017-3163 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access. Vulnerable Software & Versions: (show all )
CVE-2018-1308 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Vulnerable Software & Versions: (show all )
spring-core-4.0.4.RELEASE.jarDescription:
Spring Core License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-core-4.0.4.RELEASE.jar
MD5: 6a3fe08a36ecfc491b87a48906111bd2
SHA1: 1e49cd206349aa6d1ee272acd67cb56c05452b95
SHA256: 2625daf3e22aa03fcc7a5229036041e1b54ae6b7145ca56865caa2a5bf2333f5
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor vmware High Vendor pom name Spring Core High Vendor pom url spring-projects/spring-framework Highest Vendor hint analyzer vendor SpringSource High Vendor hint analyzer vendor pivotal software Highest Vendor pom groupid springframework Highest Vendor jar package name springframework Low Vendor pom artifactid spring-core Low Vendor pom organization name Spring IO High Vendor pom description Spring Core Medium Vendor central groupid org.springframework Highest Vendor pom organization url http://projects.spring.io/spring-framework Medium Vendor hint analyzer vendor pivotal software High Vendor file name spring-core High Product Manifest Implementation-Title spring-core High Product pom name Spring Core High Product pom description Spring Core Medium Product central artifactid spring-core Highest Product pom organization url http://projects.spring.io/spring-framework Low Product pom organization name Spring IO Low Product file name spring-core High Product pom groupid springframework Low Product pom artifactid spring-core Highest Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework High Version pom version 4.0.4.RELEASE Highest Version Manifest Implementation-Version 4.0.4.RELEASE High Version central version 4.0.4.RELEASE Highest
Related Dependencies spring-expression-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-expression-4.0.4.RELEASE.jar MD5: 08694ae63bd5eeb8006bafaaccac6985 SHA1: 92b0c050662d57f6295c261862fef45e24b3505c SHA256: 5175506f1dc73935596a114b7b2d34b261aa630ce2b6e54bc29b0769790a497e maven: org.springframework:spring-expression:4.0.4.RELEASE ✓ cpe: cpe:/a:pivotal:spring_framework:4.0.4 cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 spring-context-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-context-4.0.4.RELEASE.jar MD5: b60990a9737275dc937d697b602575f9 SHA1: 253dfb1972f446d6f7b29711ac3ea5b61b5d7b52 SHA256: cab888aaa3a9a676852f148c647dc72264175212107b2d66fca9dd2e11a5522f maven: org.springframework:spring-context:4.0.4.RELEASE ✓ cpe: cpe:/a:pivotal:spring_framework:4.0.4 cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 spring-aop-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-aop-4.0.4.RELEASE.jar MD5: 7f081c86f95582a35c735e276b1d87bc SHA1: 2c5e0985de0355b6a15021c6b1057146a4635d1d SHA256: cc806f95731a272305d1719c5bee21d31ed2dbb3b60d07447ebd0ac39b1d9fc7 cpe: cpe:/a:pivotal:spring_framework:4.0.4 cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 maven: org.springframework:spring-aop:4.0.4.RELEASE ✓ spring-test-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-test-4.0.4.RELEASE.jar MD5: 4e5664f371fbd2dda91d9f7d8b9b4c1e SHA1: 747fea2e1aa0ea9f157c398cefbb38f4e00425c1 SHA256: 050e51717641f9d23c3ed32462ef4cfbe949ecba9d3ccadbbad817e900e3929a cpe: cpe:/a:pivotal:spring_framework:4.0.4 maven: org.springframework:spring-test:4.0.4.RELEASE ✓ cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 spring-beans-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-beans-4.0.4.RELEASE.jar MD5: e95385546c768184668d1ca8d9ebc246 SHA1: b44916d83324181be533beb471203b65ed3e8887 SHA256: bbe70bf71016a47418797ed40969a836a2090af8e56375dff7e209e00b4aea2d cpe: cpe:/a:pivotal:spring_framework:4.0.4 cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 maven: org.springframework:spring-beans:4.0.4.RELEASE ✓ spring-web-4.0.4.RELEASE.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/spring-web-4.0.4.RELEASE.jar MD5: ae8af90011e9313fd90ff4b338c228e2 SHA1: f49b50a8e95ec17ca571a4e85355a6fa8e8b5de9 SHA256: dad1485f9b6352751bf2538942a9120037ad6957a254331a71a5cf456411a664 maven: org.springframework:spring-web:4.0.4.RELEASE ✓ cpe: cpe:/a:pivotal:spring_framework:4.0.4 cpe: cpe:/a:pivotal_software:spring_framework:4.0.4 Published Vulnerabilities CVE-2014-0225 suppress
Severity:Medium CVSS Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack. Vulnerable Software & Versions: (show all )
CVE-2014-3578 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. Vulnerable Software & Versions: (show all )
CVE-2014-3625 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling. Vulnerable Software & Versions: (show all )
CVE-2015-5211 suppress
Severity:High CVSS Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) CWE: CWE-20 Improper Input Validation
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response. Vulnerable Software & Versions: (show all )
CVE-2016-5007 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-264 Permissions, Privileges, and Access Controls
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected. The problem is compounded by the fact that the Spring Framework provides richer features with regards to pattern matching as well as by the fact that pattern matching in each Spring Security and the Spring Framework can easily be customized creating additional differences. Vulnerable Software & Versions: (show all )
CVE-2018-1270 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-358 Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. Vulnerable Software & Versions: (show all )
CVE-2018-1271 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack. Vulnerable Software & Versions: (show all )
CVE-2018-1272 suppress
Severity:Medium CVSS Score: 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P) CWE: CWE-264 Permissions, Privileges, and Access Controls
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles. Vulnerable Software & Versions: (show all )
stax-api-1.0-2.jarDescription:
StAX is a standard XML processing API that allows you to stream XML data from and to your application.
License:
GNU General Public Library: http://www.gnu.org/licenses/gpl.txt
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: http://www.sun.com/cddl/cddl.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/stax-api-1.0-2.jar
MD5: 7d18b63063580284c3f5734081fdc99f
SHA1: d6337b0de8b25e53e81b922352fbea9f9f57ba0b
SHA256: e8c70ebd76f982c9582a82ef82cf6ce14a7d58a4a4dca5cb7b7fc988c80089b7
Evidence Type Source Name Value Confidence Vendor file name stax-api High Vendor jar package name javax Low Vendor pom groupid javax.xml.stream Highest Vendor pom artifactid stax-api Low Vendor jar package name xml Low Vendor pom name Streaming API for XML High Vendor jar package name stream Low Vendor central groupid javax.xml.stream Highest Vendor pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low Product file name stax-api High Product pom groupid javax.xml.stream Low Product central artifactid stax-api Highest Product pom artifactid stax-api Highest Product jar package name xml Low Product pom name Streaming API for XML High Product jar package name stream Low Product pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low Version pom version 1.0-2 Highest Version central version 1.0-2 Highest Version file version 1.0.2 Highest
stax2-api-3.1.3.jarDescription:
tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API.
License:
The BSD License: http://www.opensource.org/licenses/bsd-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/stax2-api-3.1.3.jar
MD5: f1e0b1c8e10ddfc32e48c86ede69a991
SHA1: 7b6af25588e281dd7ffe3750ea121b28add8800e
SHA256: 67d77c5afa51415a76a96dead24a5af32138181494ec0368045728c8498961b1
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://fasterxml.com Low Vendor pom organization name fasterxml.com High Vendor pom name Stax2 API High Vendor file name stax2-api High Vendor pom groupid codehaus.woodstox Highest Vendor manifest Bundle-Description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low Vendor pom description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low Vendor Manifest bundle-symbolicname stax2-api Medium Vendor pom url http://wiki.fasterxml.com/WoodstoxStax2 Highest Vendor pom artifactid stax2-api Low Vendor pom organization url http://fasterxml.com Medium Product pom url http://wiki.fasterxml.com/WoodstoxStax2 Medium Product Manifest bundle-docurl http://fasterxml.com Low Product pom name Stax2 API High Product pom organization name fasterxml.com Low Product Manifest bundle-symbolicname stax2-api Medium Product file name stax2-api High Product pom organization url http://fasterxml.com Low Product manifest Bundle-Description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low Product pom description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low Product pom artifactid stax2-api Highest Product pom groupid codehaus.woodstox Low Product Manifest Bundle-Name Stax2 API Medium Version file version 3.1.3 Highest Version pom version 3.1.3 Highest
maven: org.codehaus.woodstox:stax2-api:3.1.3 Confidence :High tika-core-1.10.jarDescription:
This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also
includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/tika-core-1.10.jar
MD5: 9fccc95cc1ef109c339a89215a26cbf9
SHA1: feeac0d2758775b721b5c3e700ce8e4f5c0d9eb2
SHA256: 9687d0b0c40bb3b9374ac386fad001558ebadf1b2f73321b4ac5db3f33484d74
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://tika.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.tika.core Medium Vendor pom parent-artifactid tika-parent Low Vendor pom parent-groupid org.apache.tika Medium Vendor pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name tika-core High Vendor Manifest Implementation-Vendor-Id org.apache.tika Medium Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Apache Tika core High Vendor pom groupid apache.tika Highest Vendor manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Vendor pom organization url http://www.apache.org Medium Vendor pom url http://tika.apache.org/ Highest Vendor pom artifactid tika-core Low Product Manifest bundle-docurl http://tika.apache.org/ Low Product Manifest bundle-symbolicname org.apache.tika.core Medium Product pom organization name The Apache Software Foundation Low Product pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Product pom groupid apache.tika Low Product file name tika-core High Product pom artifactid tika-core Highest Product pom parent-groupid org.apache.tika Low Product pom url http://tika.apache.org/ Medium Product pom name Apache Tika core High Product pom organization url http://www.apache.org Low Product Manifest Implementation-Title Apache Tika core High Product manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Product Manifest specification-title Apache Tika core Medium Product pom parent-artifactid tika-parent Medium Product Manifest Bundle-Name Apache Tika core Medium Version Manifest Implementation-Version 1.10 High Version pom version 1.10 Highest Version file version 1.10 Highest
Published Vulnerabilities CVE-2016-6809 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization. Vulnerable Software & Versions:
CVE-2018-1338 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
typeaheadjs-0.9.3.jarDescription:
WebJar for typeahead.js License:
MIT: https://github.com/twitter/typeahead.js/blob/master/LICENSE File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/typeaheadjs-0.9.3.jar
MD5: ed3081f15195e21c9b0a76f9bef9e405
SHA1: f7c38c931dcdb7bff0e309f9dcdd6f4281200440
SHA256: 36f4ee8f639bf7ed8f155d4c24a1d5d10c9f13104909be7486825c7555ba6974
Evidence Type Source Name Value Confidence Vendor file name typeaheadjs High Vendor pom groupid webjars Highest Vendor pom artifactid typeaheadjs Low Vendor pom name typeahead.js High Vendor pom description WebJar for typeahead.js Medium Vendor pom url http://webjars.org Highest Product pom groupid webjars Low Product file name typeaheadjs High Product pom url http://webjars.org Medium Product pom artifactid typeaheadjs Highest Product pom name typeahead.js High Product pom description WebJar for typeahead.js Medium Version pom version 0.9.3 Highest Version file version 0.9.3 Highest
maven: org.webjars:typeaheadjs:0.9.3 Confidence :High velocity-1.7.jarDescription:
Apache Velocity is a general purpose template engine. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/velocity-1.7.jarMD5: 3692dd72f8367cb35fb6280dc2916725SHA1: 2ceb567b8f3f21118ecdec129fe1271dbc09aa7aSHA256: ec92dae810034f4b46dbb16ef4364a4013b0efb24a8c5dd67435cae46a290d8e
Evidence Type Source Name Value Confidence Vendor pom name Apache Velocity High Vendor jar package name velocity Low Vendor pom description Apache Velocity is a general purpose template engine. Medium Vendor Manifest bundle-symbolicname org.apache.velocity Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name apache Low Vendor Manifest extension-name velocity Medium Vendor file name velocity High Vendor central groupid org.apache.velocity Highest Vendor Manifest specification-vendor Apache Software Foundation Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom groupid apache.velocity Highest Vendor pom parent-artifactid apache Low Vendor pom url http://velocity.apache.org/engine/devel/ Highest Vendor pom parent-groupid org.apache Medium Vendor pom artifactid velocity Low Vendor jar package name runtime Low Product pom groupid apache.velocity Low Product pom name Apache Velocity High Product jar package name velocity Low Product pom description Apache Velocity is a general purpose template engine. Medium Product Manifest Implementation-Title org.apache.velocity High Product pom parent-groupid org.apache Low Product Manifest bundle-symbolicname org.apache.velocity Medium Product pom url http://velocity.apache.org/engine/devel/ Medium Product Manifest extension-name velocity Medium Product file name velocity High Product Manifest specification-title Velocity is a Java-based template engine Medium Product pom artifactid velocity Highest Product pom parent-artifactid apache Medium Product central artifactid velocity Highest Product Manifest Bundle-Name Apache Velocity Medium Product jar package name runtime Low Version Manifest Implementation-Version 1.7 High Version central version 1.7 Highest Version file version 1.7 Highest Version pom version 1.7 Highest
wicket-bootstrap-core-0.9.2.jarDescription:
wicket with twitter bootstrap integration License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-bootstrap-core-0.9.2.jar
MD5: 526b085ebd563375c9b920f80734f149
SHA1: 9860c6da4ee063cf64b83d9678bfe17bae7a4d5c
SHA256: 2591413c23e927bd17f87892d44de6d8341c9d02791087866ea002ac698b2e00
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid bootstrap-parent Low Vendor file name wicket-bootstrap-core High Vendor manifest Bundle-Description wicket with twitter bootstrap integration Medium Vendor Manifest bundle-symbolicname wicket-bootstrap-core Medium Vendor pom artifactid wicket-bootstrap-core Low Vendor Manifest Implementation-Vendor-Id de.agilecoders.wicket Medium Vendor Manifest Implementation-Vendor AgileCoders High Vendor pom name bootstrap-core High Vendor Manifest implementation-build ${buildNumber} Low Vendor pom groupid de.agilecoders.wicket Highest Vendor Manifest bundle-docurl https://agile-coders.github.com/ Low Product file name wicket-bootstrap-core High Product manifest Bundle-Description wicket with twitter bootstrap integration Medium Product Manifest bundle-symbolicname wicket-bootstrap-core Medium Product Manifest Implementation-Title bootstrap-core High Product pom name bootstrap-core High Product pom groupid de.agilecoders.wicket Low Product Manifest implementation-build ${buildNumber} Low Product pom artifactid wicket-bootstrap-core Highest Product pom parent-artifactid bootstrap-parent Medium Product Manifest bundle-docurl https://agile-coders.github.com/ Low Product Manifest Bundle-Name bootstrap-core Medium Version pom version 0.9.2 Highest Version Manifest Implementation-Version 0.9.2 High Version file version 0.9.2 Highest
maven: de.agilecoders.wicket:wicket-bootstrap-core:0.9.2 Confidence :High wicket-bootstrap-extensions-0.9.2.jarDescription:
wicket with twitter bootstrap integration License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-bootstrap-extensions-0.9.2.jar
MD5: 848c862ad76f24f425718a999ae7ff2f
SHA1: 7dadadc64d2f8db8b4dd4fc2df910f693cfb9006
SHA256: 04d308a2694ab8bfe1915e3a8855e05de0240c88f8ae1e41c3395a071774574d
Evidence Type Source Name Value Confidence Vendor file name wicket-bootstrap-extensions High Vendor pom parent-artifactid bootstrap-parent Low Vendor pom name bootstrap-extensions High Vendor manifest Bundle-Description wicket with twitter bootstrap integration Medium Vendor Manifest Implementation-Vendor-Id de.agilecoders.wicket Medium Vendor Manifest bundle-symbolicname wicket-bootstrap-extensions Medium Vendor Manifest Implementation-Vendor AgileCoders High Vendor Manifest implementation-build ${buildNumber} Low Vendor pom artifactid wicket-bootstrap-extensions Low Vendor pom groupid de.agilecoders.wicket Highest Vendor Manifest bundle-docurl https://agile-coders.github.com/ Low Product file name wicket-bootstrap-extensions High Product pom name bootstrap-extensions High Product manifest Bundle-Description wicket with twitter bootstrap integration Medium Product Manifest Bundle-Name bootstrap-extensions Medium Product Manifest Implementation-Title bootstrap-extensions High Product Manifest bundle-symbolicname wicket-bootstrap-extensions Medium Product pom groupid de.agilecoders.wicket Low Product pom artifactid wicket-bootstrap-extensions Highest Product Manifest implementation-build ${buildNumber} Low Product pom parent-artifactid bootstrap-parent Medium Product Manifest bundle-docurl https://agile-coders.github.com/ Low Version pom version 0.9.2 Highest Version Manifest Implementation-Version 0.9.2 High Version file version 0.9.2 Highest
maven: de.agilecoders.wicket:wicket-bootstrap-extensions:0.9.2 Confidence :High wicket-core-6.16.0.jarDescription:
Wicket is a Java web application framework that takes simplicity,
separation of concerns and ease of development to a whole new level.
Wicket pages can be mocked up, previewed and later revised using
standard WYSIWYG HTML design tools. Dynamic content processing and
form handling is all handled in Java code using a first-class
component model backed by POJO data beans that can easily be
persisted using your favorite technology.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-core-6.16.0.jar
MD5: 4515a635b3e984515a09cc8737e3e617
SHA1: 85dd5611907b269f6a25569d9df45513bd0b1b5a
SHA256: 375040a1ed7faaa62e5533706db6495bff2d7bee1bdce621c163a5ea77dbafd4
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.apache.wicket Medium Vendor manifest Bundle-Description Wicket is a Java web application framework that takes simplicity, separation of concerns and ease of development to a whole new level. Wicket pages can be mocked up, previewed and later revised using standard WYSIWYG HTML design tools. Dynamic content processing and form handling is all handled in Java code using a first-class component model backed by POJO data beans that can easily be persisted using your favorite technology. Low Vendor pom description Wicket is a Java web application framework that takes simplicity, separation of concerns and ease of development to a whole new level. Wicket pages can be mocked up, previewed and later revised using standard WYSIWYG HTML design tools. Dynamic content processing and form handling is all handled in Java code using a first-class component model backed by POJO data beans that can easily be persisted using your favorite technology. Low Vendor Manifest bundle-docurl http://apache.org Low Vendor pom name Wicket Core High Vendor pom parent-artifactid wicket-parent Low Vendor pom groupid apache.wicket Highest Vendor pom parent-groupid org.apache.wicket Medium Vendor Manifest specification-vendor Apache Software Foundation Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom artifactid wicket-core Low Vendor Manifest bundle-symbolicname org.apache.wicket.core Medium Vendor file name wicket-core High Product manifest Bundle-Description Wicket is a Java web application framework that takes simplicity, separation of concerns and ease of development to a whole new level. Wicket pages can be mocked up, previewed and later revised using standard WYSIWYG HTML design tools. Dynamic content processing and form handling is all handled in Java code using a first-class component model backed by POJO data beans that can easily be persisted using your favorite technology. Low Product pom description Wicket is a Java web application framework that takes simplicity, separation of concerns and ease of development to a whole new level. Wicket pages can be mocked up, previewed and later revised using standard WYSIWYG HTML design tools. Dynamic content processing and form handling is all handled in Java code using a first-class component model backed by POJO data beans that can easily be persisted using your favorite technology. Low Product Manifest bundle-docurl http://apache.org Low Product pom name Wicket Core High Product Manifest Bundle-Name Wicket Core Medium Product pom parent-artifactid wicket-parent Medium Product pom parent-groupid org.apache.wicket Low Product Manifest Implementation-Title Wicket Core High Product Manifest specification-title Wicket Core Medium Product Manifest bundle-symbolicname org.apache.wicket.core Medium Product file name wicket-core High Product pom groupid apache.wicket Low Product pom artifactid wicket-core Highest Version Manifest Implementation-Version 6.16.0 High Version file version 6.16.0 Highest Version pom version 6.16.0 Highest
Related Dependencies wicket-ioc-6.16.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-ioc-6.16.0.jar MD5: ad37eea9ffc814baa2a070b58bae6c17 SHA1: 5e4b2f2ec265e2cac91e21714cb15b681d3be03d SHA256: a59717062027e935814463eb6a9a80bedbdb8e177ed91146369d68f1514205db cpe: cpe:/a:apache:wicket:6.16.0 wicket-request-6.16.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-request-6.16.0.jar MD5: ec41c0b211a44f0e179df626e2ce45fe SHA1: 60236a274760769c85cf2e416c099704f8f30368 SHA256: 0d1a9f022ef7d6563f3a37b084cd65da76e3db1cb0ffa20435d424400e541a8a cpe: cpe:/a:apache:wicket:6.16.0 wicket-auth-roles-6.16.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-auth-roles-6.16.0.jar MD5: 32d315dd8a4dbc8deff4e55c0dccc265 SHA1: 0360e7605c01f5856bb706de39b5e5f4e5e4ff2f SHA256: 3b83e35b79d8b57596051bd843613b381548422951b261aaecbc26320445271f cpe: cpe:/a:apache:wicket:6.16.0 wicket-util-6.16.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-util-6.16.0.jar MD5: 11f684c71f2df914a05bc6e07a5f9abd SHA1: 918a13a43683388fe1b5df6820dbe45b3c8d6cfe SHA256: 4d4e53d7e164f332d550c78ea04852e4761fdacfb710438cbce1818348e80b6c cpe: cpe:/a:apache:wicket:6.16.0 wicket-spring-6.16.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-spring-6.16.0.jar MD5: 7e525d21cc614b4dc6819d545ace8f02 SHA1: c26e2f1a55a2ba655dfb5e0dc9c90e6480056bff SHA256: 238b9bf07053b4fbe6cf530d9eaa3328caaa980490b56f5075b8562f38e0aeb3 cpe: cpe:/a:apache:wicket:6.16.0 Published Vulnerabilities CVE-2014-3526 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions. Vulnerable Software & Versions: (show all )
CVE-2014-7808 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-310 Cryptographic Issues
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider. Vulnerable Software & Versions: (show all )
CVE-2015-5347 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title. Vulnerable Software & Versions: (show all )
CVE-2015-7520 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element. Vulnerable Software & Versions: (show all )
CVE-2016-6793 suppress
Severity:Medium CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:N/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.7 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object. Vulnerable Software & Versions: (show all )
wicket-extensions-6.13.0.jarDescription:
Wicket Extensions is a rich component library for the Wicket framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-extensions-6.13.0.jar
MD5: bb473c8a26b60b9229b55b7bb8f2af81
SHA1: 6541b82ae1ef81cbe78bbd16de0bf94d65eeb79e
SHA256: 31b3a630c20fe4b115aafc294c3f705319f54ba52b3f0470cb37188852459062
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.apache.wicket Medium Vendor pom name Wicket Extensions High Vendor manifest Bundle-Description Wicket Extensions is a rich component library for the Wicket framework. Medium Vendor Manifest bundle-docurl http://apache.org Low Vendor pom parent-artifactid wicket-parent Low Vendor file name wicket-extensions High Vendor pom groupid apache.wicket Highest Vendor pom parent-groupid org.apache.wicket Medium Vendor pom description Wicket Extensions is a rich component library for the Wicket framework. Medium Vendor Manifest specification-vendor Apache Software Foundation Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom artifactid wicket-extensions Low Vendor Manifest bundle-symbolicname org.apache.wicket.extensions Medium Product pom name Wicket Extensions High Product manifest Bundle-Description Wicket Extensions is a rich component library for the Wicket framework. Medium Product Manifest Bundle-Name Wicket Extensions Medium Product Manifest Implementation-Title Wicket Extensions High Product Manifest bundle-docurl http://apache.org Low Product pom parent-artifactid wicket-parent Medium Product Manifest specification-title Wicket Extensions Medium Product pom parent-groupid org.apache.wicket Low Product file name wicket-extensions High Product pom description Wicket Extensions is a rich component library for the Wicket framework. Medium Product Manifest bundle-symbolicname org.apache.wicket.extensions Medium Product pom artifactid wicket-extensions Highest Product pom groupid apache.wicket Low Version pom version 6.13.0 Highest Version file version 6.13.0 Highest Version Manifest Implementation-Version 6.13.0 High
Published Vulnerabilities CVE-2014-0043 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use. Vulnerable Software & Versions: (show all )
CVE-2014-3526 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-200 Information Exposure
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions. Vulnerable Software & Versions: (show all )
CVE-2014-7808 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-310 Cryptographic Issues
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider. Vulnerable Software & Versions: (show all )
CVE-2015-5347 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title. Vulnerable Software & Versions: (show all )
CVE-2015-7520 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element. Vulnerable Software & Versions: (show all )
CVE-2016-6793 suppress
Severity:Medium CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:N/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.7 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object. Vulnerable Software & Versions: (show all )
wicket-webjars-0.4.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wicket-webjars-0.4.0.jarMD5: f06ad74c487b7743bee5e447d30ed85fSHA1: 962c559b498fbc7617ba40658a60d156473db146SHA256: 5e695e6d8ac8eb75512da86146dbd0145e8525ddaa7334c97043d98ff91bf0c5
Evidence Type Source Name Value Confidence Vendor pom name library High Vendor jar package name de Low Vendor jar package name wicket Low Vendor file name wicket-webjars High Vendor pom parent-artifactid wicket-webjars-parent Low Vendor jar package name agilecoders Low Vendor pom groupid de.agilecoders.wicket.webjars Highest Vendor pom artifactid wicket-webjars Low Product pom artifactid wicket-webjars Highest Product pom name library High Product pom parent-artifactid wicket-webjars-parent Medium Product pom groupid de.agilecoders.wicket.webjars Low Product jar package name wicket Low Product jar package name webjars Low Product file name wicket-webjars High Product jar package name agilecoders Low Version file version 0.4.0 Highest Version pom version 0.4.0 Highest
maven: de.agilecoders.wicket.webjars:wicket-webjars:0.4.0 Confidence :High woodstox-core-asl-4.2.0.jarDescription:
Woodstox is a high-performance XML processor that
implements Stax (JSR-173) and SAX2 APIs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/woodstox-core-asl-4.2.0.jar
MD5: ac7e73fcf52654c0642afdfccc7d9f57
SHA1: 7a3784c65cfa5c0553f31d000b43346feb1f4ee3
SHA256: 5ccb662b21ed218aaf06fc0a46f8b78338bc4992a236b62b471fa3f2671ed0ae
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname woodstox-core-asl Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor jar package name wstx Low Vendor pom groupid codehaus.woodstox Highest Vendor pom description Woodstox is a high-performance XML processor that
implements Stax (JSR-173) and SAX2 APIs Medium Vendor Manifest Implementation-Vendor http://woodstox.codehaus.org High Vendor pom organization name Codehaus High Vendor file name woodstox-core-asl High Vendor central groupid org.codehaus.woodstox Highest Vendor Manifest specification-vendor http://jcp.org/en/jsr/detail?id=173 Low Vendor pom organization url http://www.codehaus.org/ Medium Vendor jar package name ctc Low Vendor pom url http://woodstox.codehaus.org Highest Vendor pom artifactid woodstox-core-asl Low Vendor pom name Woodstox High Product Manifest bundle-symbolicname woodstox-core-asl Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product Manifest Bundle-Name Woodstox XML-processor Medium Product pom artifactid woodstox-core-asl Highest Product jar package name wstx Low Product Manifest specification-title Stax 1.0 API Medium Product pom description Woodstox is a high-performance XML processor that
implements Stax (JSR-173) and SAX2 APIs Medium Product pom url http://woodstox.codehaus.org Medium Product file name woodstox-core-asl High Product central artifactid woodstox-core-asl Highest Product pom organization url http://www.codehaus.org/ Low Product Manifest Implementation-Title Woodstox XML-processor High Product pom name Woodstox High Product pom organization name Codehaus Low Product pom groupid codehaus.woodstox Low Version Manifest Implementation-Version 4.2.0 High Version file version 4.2.0 Highest Version central version 4.2.0 Highest Version pom version 4.2.0 Highest
wsdl4j-1.6.2.jarDescription:
Java stub generator for WSDL License:
CPL: http://www.opensource.org/licenses/cpl1.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wsdl4j-1.6.2.jar
MD5: 2608a8ea3f07b0c08de8a7d3d0d3fc09
SHA1: dec1669fb6801b7328e01ad72fc9e10b69ea06c1
SHA256: e90120d26f1a163c5843c7a758d0a0c950d1b0970268ad0770d6c1cc50508c43
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor IBM High Vendor pom groupid wsdl4j Highest Vendor pom name WSDL4J High Vendor pom artifactid wsdl4j Low Vendor jar package name wsdl Low Vendor jar package name ibm Low Vendor Manifest specification-vendor IBM (Java Community Process) Low Vendor pom url http://sf.net/projects/wsdl4j Highest Vendor jar package name extensions Low Vendor pom description Java stub generator for WSDL Medium Vendor file name wsdl4j High Vendor central groupid wsdl4j Highest Product jar package name wsdl Low Product central artifactid wsdl4j Highest Product Manifest specification-title JWSDL Medium Product pom groupid wsdl4j Low Product jar package name extensions Low Product pom name WSDL4J High Product pom artifactid wsdl4j Highest Product pom description Java stub generator for WSDL Medium Product pom url http://sf.net/projects/wsdl4j Medium Product file name wsdl4j High Product Manifest Implementation-Title WSDL4J High Version file version 1.6.2 Highest Version central version 1.6.2 Highest Version pom version 1.6.2 Highest
wstx-asl-3.2.7.jarDescription:
Woodstox is a high-performance XML processor that implements Stax (JSR-173) API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/wstx-asl-3.2.7.jar
MD5: 5ca667e626a1b2f3e5522cb431370cc6
SHA1: 252c7faae9ce98cb9c9d29f02db88f7373e7f407
SHA256: 939f591b445c83f285191cef7603731ed373eaf000da005f49769a283110dd2d
Evidence Type Source Name Value Confidence Vendor pom description Woodstox is a high-performance XML processor that implements Stax (JSR-173) API Medium Vendor jar package name wstx Low Vendor pom groupid codehaus.woodstox Highest Vendor central groupid woodstox High Vendor pom organization name Codehaus High Vendor Manifest specification-vendor http://jcp.org/en/jsr/detail?id=173 Low Vendor pom organization url http://www.codehaus.org/ Medium Vendor Manifest Implementation-Vendor woodstox.codehaus.org High Vendor jar package name ctc Low Vendor pom artifactid wstx-asl Low Vendor pom url http://woodstox.codehaus.org Highest Vendor pom name Woodstox High Vendor file name wstx-asl High Vendor central groupid org.codehaus.woodstox High Product pom description Woodstox is a high-performance XML processor that implements Stax (JSR-173) API Medium Product jar package name wstx Low Product Manifest specification-title StAX 1.0 API Medium Product pom artifactid wstx-asl Highest Product pom url http://woodstox.codehaus.org Medium Product pom organization url http://www.codehaus.org/ Low Product Manifest Implementation-Title WoodSToX XML-processor High Product pom name Woodstox High Product pom organization name Codehaus Low Product file name wstx-asl High Product central artifactid wstx-asl High Product pom groupid codehaus.woodstox Low Version file version 3.2.7 Highest Version Manifest Implementation-Version 3.2.7 High Version central version 3.2.7 High Version pom version 3.2.7 Highest
Related Dependencies wstx-asl-3.2.7.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/wstx-asl-3.2.7.jar MD5: 5ca667e626a1b2f3e5522cb431370cc6 SHA1: 252c7faae9ce98cb9c9d29f02db88f7373e7f407 SHA256: 939f591b445c83f285191cef7603731ed373eaf000da005f49769a283110dd2d xercesImpl-2.9.1.jarDescription:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the
Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI),
a complete framework for building parser components and configurations that is extremely
modular and easy to program.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xercesImpl-2.9.1.jarMD5: f807f86d7d9db25edbfc782aca7ca2a9SHA1: 7bc7e49ddfe4fb5f193ed37ecc96c12292c8ceb6SHA256: 6ae540a7c85c814ac64bea48016b3a6f45c95d4765f547fcc0053dc36c94ed5c
Evidence Type Source Name Value Confidence Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xerces/impl/Version.class Implementation-Vendor Apache Software Foundation Medium Vendor pom url http://xerces.apache.org/xerces2-j Highest Vendor jar package name xerces Low Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor central groupid xerces Highest Vendor pom artifactid xercesImpl Low Vendor pom name Xerces2 Java Parser High Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name apache Low Vendor pom groupid xerces Highest Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor file name xercesImpl High Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product pom parent-groupid org.apache Low Product manifest: org/apache/xerces/impl/Version.class Implementation-Title org.apache.xerces.impl.Version Medium Product pom name Xerces2 Java Parser High Product file name xercesImpl High Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product pom groupid xerces Low Product pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium Product pom url http://xerces.apache.org/xerces2-j Medium Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product central artifactid xercesImpl Highest Product jar package name xerces Low Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium Product pom parent-artifactid apache Medium Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium Product pom artifactid xercesImpl Highest Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Version pom version 2.9.1 Highest Version central version 2.9.1 Highest Version file version 2.9.1 Highest
Related Dependencies xercesImpl-2.9.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-xml/xercesImpl-2.9.1.jar MD5: f807f86d7d9db25edbfc782aca7ca2a9 SHA1: 7bc7e49ddfe4fb5f193ed37ecc96c12292c8ceb6 SHA256: 6ae540a7c85c814ac64bea48016b3a6f45c95d4765f547fcc0053dc36c94ed5c Published Vulnerabilities CVE-2012-0881 suppress
Severity:High CVSS Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C) CWE: CWE-399 Resource Management Errors
Apache Xerces2 Java allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions. Vulnerable Software & Versions:
xml-apis-1.3.04.jarDescription:
xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xml-apis-1.3.04.jarMD5: 9ae9c29e4497fc35a3eade1e6dd0bbebSHA1: 90b215f48fe42776c8c7f6e3509ec54e84fd65efSHA256: d404aa881eb9c5f7a4fb546e84ea11506cd417a72b5972e88eff17f43f9f8a64
Evidence Type Source Name Value Confidence Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor central groupid xml-apis Highest Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid xml-apis Highest Vendor jar package name xml Low Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid xml-apis Low Vendor pom parent-artifactid apache Low Vendor pom name XML Commons External Components XML APIs High Vendor pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low Vendor pom url http://xml.apache.org/commons/components/external/ Highest Vendor file name xml-apis High Vendor pom parent-groupid org.apache Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium Product jar package name dom Low Product manifest: javax/xml/datatype/ Specification-Title JSR 206 Java API for XML Processing 1.3 Medium Product pom parent-groupid org.apache Low Product manifest: javax/xml/transform/ Specification-Title JSR 206 Java API for XML Processing 1.3 Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product pom name XML Commons External Components XML APIs High Product pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low Product file name xml-apis High Product manifest: javax/xml/xpath/ Specification-Title JSR 206 Java API for XML Processing 1.3 Medium Product manifest: javax/xml/parsers/ Specification-Title JSR 206, Java API for XML Processing 1.3 Medium Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model (DOM) Level 3 Core Medium Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium Product pom artifactid xml-apis Highest Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model (DOM) Level 3 Load and Save Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product pom url http://xml.apache.org/commons/components/external/ Medium Product manifest: javax/xml/validation/ Specification-Title JSR 206 Java API for XML Processing 1.3 Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product pom parent-artifactid apache Medium Product pom groupid xml-apis Low Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product central artifactid xml-apis Highest Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Version pom version 1.3.04 Highest Version file version 1.3.04 Highest Version central version 1.3.04 Highest
xmlParserAPIs-2.6.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xmlParserAPIs-2.6.2.jarMD5: 2651f9f7c39e3524f3e2c394625ac63aSHA1: 065acede1e5305bd2b92213d7b5761328c6f4fd9SHA256: 1c2867be1faa73c67e9232631241eb1df4cd0763048646e7bb575a9980e9d7e5
Evidence Type Source Name Value Confidence Vendor jar package name dom Low Vendor pom artifactid xmlParserAPIs Low Vendor jar package name w3c Low Vendor file name xmlParserAPIs High Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor central groupid xerces High Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid xerces Highest Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product jar package name dom Low Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product pom artifactid xmlParserAPIs Highest Product central artifactid xmlParserAPIs High Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.transform Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product pom groupid xerces Low Product file name xmlParserAPIs High Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Version manifest: javax/xml/transform/ Implementation-Version 1.2.01 Medium Version manifest: javax/xml/parsers/ Implementation-Version 1.2.01 Medium Version manifest: org/w3c/dom/ Implementation-Version 1.0 Medium Version manifest: org/xml/sax/ Implementation-Version 2.0.1 Medium Version central version 2.6.1 High Version pom version 2.6.2 Highest Version file version 2.6.2 Highest Version central version 2.6.2 High Version manifest: org/apache/xmlcommons/Version Implementation-Version 1.2.01 Medium Version file name xmlParserAPIs Medium Version pom version 2.6.0 Highest Version central version 2.6.0 High Version pom version 2.6.1 Highest
xmlenc-0.52.jarDescription:
xmlenc Library License:
The BSD License: http://www.opensource.org/licenses/bsd-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xmlenc-0.52.jar
MD5: c962b6bc3c8de46795b0ed94851fa9c7
SHA1: d82554efbe65906d83b3d97bd7509289e9db561a
SHA256: 282ae185fc2ff27da7714af9962897c09cfefafb88072219c4a2f9c73616c026
Evidence Type Source Name Value Confidence Vendor manifest: xmlenc Implementation-Vendor Ernst de Haan Medium Vendor central groupid xmlenc Highest Vendor file name xmlenc High Vendor jar package name xmlenc Low Vendor pom name xmlenc Library High Vendor pom url http://xmlenc.sourceforge.net Highest Vendor jar package name znerd Low Vendor pom groupid xmlenc Highest Vendor pom description xmlenc Library Medium Vendor pom artifactid xmlenc Low Product manifest: xmlenc Specification-Title xmlenc Medium Product pom url http://xmlenc.sourceforge.net Medium Product file name xmlenc High Product jar package name xmlenc Low Product pom groupid xmlenc Low Product pom name xmlenc Library High Product pom artifactid xmlenc Highest Product central artifactid xmlenc Highest Product pom description xmlenc Library Medium Product manifest: xmlenc Implementation-Title xmlenc Medium Version pom version 0.52 Highest Version central version 0.52 Highest Version file version 0.52 Highest
xmlschema-core-2.0.1.jarDescription:
Commons XMLSchema is a light weight schema object model that can be used to manipulate or
generate XML schema. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xmlschema-core-2.0.1.jar
MD5: b7f3197aebdcf95fa429e1c0e4c6f086
SHA1: e9f802631794bd9f8ad90c4234b50440dfbdb21e
SHA256: e31aff00d8eb77f91604f6758c02b5d7452937ccfd00c84ca0fc285bfc516e0e
Evidence Type Source Name Value Confidence Vendor pom groupid apache.ws.xmlschema Highest Vendor pom parent-groupid org.apache.ws.xmlschema Medium Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom artifactid xmlschema-core Low Vendor pom parent-artifactid xmlschema Low Vendor pom name XmlSchema Core High Vendor file name xmlschema-core High Vendor pom description Commons XMLSchema is a light weight schema object model that can be used to manipulate or generate XML schema. Low Vendor manifest Bundle-Description Commons XMLSchema is a light weight schema object model that can be used to manipulate or generate XML schema. Low Vendor Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product pom artifactid xmlschema-core Highest Product Manifest Bundle-Name XmlSchema Core Medium Product pom parent-artifactid xmlschema Medium Product pom name XmlSchema Core High Product file name xmlschema-core High Product pom parent-groupid org.apache.ws.xmlschema Low Product pom description Commons XMLSchema is a light weight schema object model that can be used to manipulate or generate XML schema. Low Product manifest Bundle-Description Commons XMLSchema is a light weight schema object model that can be used to manipulate or generate XML schema. Low Product Manifest bundle-symbolicname org.apache.ws.xmlschema.core Medium Product pom groupid apache.ws.xmlschema Low Version pom version 2.0.1 Highest Version file version 2.0.1 Highest
cpe: cpe:/a:ws_project:ws:2.0.1 Confidence :Low suppress maven: org.apache.ws.xmlschema:xmlschema-core:2.0.1 Confidence :High xz-1.5.jarDescription:
XZ data compression License:
Public Domain File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/xz-1.5.jar
MD5: 51050e595b308c4aec8ac314f66e18bc
SHA1: 9c64274b7dbb65288237216e3fae7877fd3f2bee
SHA256: 86f30fa8775fa3a62cdb39d1ed78a6019164c1058864048d42cbee244e26e840
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://tukaani.org/xz/java.html Low Vendor pom groupid tukaani Highest Vendor pom artifactid xz Low Vendor pom name XZ for Java High Vendor jar package name xz Low Vendor Manifest implementation-url http://tukaani.org/xz/java.html Low Vendor jar package name tukaani Low Vendor pom description XZ data compression Medium Vendor Manifest bundle-symbolicname org.tukaani.xz Medium Vendor file name xz High Vendor central groupid org.tukaani Highest Vendor pom url http://tukaani.org/xz/java.html Highest Product Manifest bundle-docurl http://tukaani.org/xz/java.html Low Product Manifest Bundle-Name XZ data compression Medium Product pom name XZ for Java High Product jar package name xz Low Product Manifest Implementation-Title XZ data compression High Product Manifest implementation-url http://tukaani.org/xz/java.html Low Product pom description XZ data compression Medium Product pom artifactid xz Highest Product Manifest bundle-symbolicname org.tukaani.xz Medium Product pom groupid tukaani Low Product pom url http://tukaani.org/xz/java.html Medium Product file name xz High Product central artifactid xz Highest Version pom version 1.5 Highest Version Manifest Implementation-Version 1.5 High Version file version 1.5 Highest Version central version 1.5 Highest
Related Dependencies xz-1.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/xz-1.5.jar MD5: 51050e595b308c4aec8ac314f66e18bc SHA1: 9c64274b7dbb65288237216e3fae7877fd3f2bee SHA256: 86f30fa8775fa3a62cdb39d1ed78a6019164c1058864048d42cbee244e26e840 maven: org.tukaani:xz:1.5 ✓ Confidence :Highestcpe: cpe:/a:tukaani:xz:1.5 Confidence :Low suppress Published Vulnerabilities CVE-2015-4035 suppress
Severity:Medium CVSS Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-20 Improper Input Validation
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name. Vulnerable Software & Versions:
zookeeper-3.4.5.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/zookeeper-3.4.5.jar
MD5: 00b9db19ad7f18681761edc6db524ceb
SHA1: c0f69fb36526552a8f0bc548a6c33c49cf08e562
SHA256: fadea8ad970ea76500db9fe8826a89dc66705a14e794389ea507fe4f5d090f55
Evidence Type Source Name Value Confidence Vendor pom groupid apache.zookeeper Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid zookeeper Low Vendor Manifest built-at 11/05/2012 07:58 GMT Low Vendor Manifest bundle-docurl http://hadoop.apache.org/zookeeper Low Vendor file name zookeeper High Vendor jar package name zookeeper Low Vendor central groupid org.apache.zookeeper Highest Vendor Manifest bundle-symbolicname org.apache.hadoop.zookeeper Medium Vendor jar package name apache Low Product central artifactid zookeeper Highest Product Manifest built-at 11/05/2012 07:58 GMT Low Product Manifest bundle-docurl http://hadoop.apache.org/zookeeper Low Product file name zookeeper High Product jar package name zookeeper Low Product Manifest Implementation-Title org.apache.zookeeper High Product Manifest Bundle-Name ZooKeeper Bundle Medium Product pom groupid apache.zookeeper Low Product pom artifactid zookeeper Highest Product Manifest bundle-symbolicname org.apache.hadoop.zookeeper Medium Version pom version 3.4.5 Highest Version file version 3.4.5 Highest Version central version 3.4.5 Highest
Related Dependencies zookeeper-3.4.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/zookeeper-3.4.5.jar MD5: 00b9db19ad7f18681761edc6db524ceb SHA1: c0f69fb36526552a8f0bc548a6c33c49cf08e562 SHA256: fadea8ad970ea76500db9fe8826a89dc66705a14e794389ea507fe4f5d090f55 Published Vulnerabilities CVE-2014-0085 suppress
Severity:Low CVSS Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-255 Credentials Management
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log. Vulnerable Software & Versions: (show all )
CVE-2016-5017 suppress
Severity:Medium CVSS Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string. Vulnerable Software & Versions: (show all )
CVE-2017-5637 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later. Vulnerable Software & Versions: (show all )
CVE-2018-8012 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-285 Improper Authorization
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader. Vulnerable Software & Versions: (show all )
creativecommons.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/creativecommons/creativecommons.jarMD5: 9b611e8f9893409a94d7ace9f1ff73d2SHA1: 05ef359b6cc0153f08429d313eb413e8eb46168cSHA256: 64bb3ebbb899e64403c23ac0f57a56ff8b3aec134d25b3426a0fa5af4884ba48
Evidence Type Source Name Value Confidence Vendor file name creativecommons High Vendor jar package name nutch Low Vendor jar package name creativecommons Low Product file name creativecommons High Product jar package name nutch Low
index-anchor.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/index-anchor/index-anchor.jarMD5: d3b869aea522c93bf13133afcb2f2cfeSHA1: 5edda05d9b9539c67c7050c3cf7fa4e1ffb327edSHA256: 252072abf7e6c9edfd117a4203bcd6d5acaeb3aae6966de043f1a537cd3ff9d3
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor jar package name indexer Low Vendor file name index-anchor High Vendor jar package name apache Low Product jar package name nutch Low Product jar package name anchor Low Product jar package name indexer Low Product file name index-anchor High
index-basic.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/index-basic/index-basic.jarMD5: 3e70463ddcea4c15a4e63b5b6021ed82SHA1: 348f95fa3760dd21f728022c8af2b9aee0eb02d4SHA256: 4b7f71385833ea40cfb9728427cba58b0d6eae5d00808e3a5a43b92102c1c7c4
Evidence Type Source Name Value Confidence Vendor file name index-basic High Vendor jar package name nutch Low Vendor jar package name indexer Low Vendor jar package name apache Low Product file name index-basic High Product jar package name nutch Low Product jar package name basic Low Product jar package name indexer Low
index-html.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/index-html/index-html.jarMD5: 3588474bbbcd41c9d5687142a3f1f2a8SHA1: 138813b40fb6f233c60e9c9306a7c57bdbd1cfd6SHA256: f1520f23bc856176ad4ee3be294e6309a15c0fbe18def5ebd907353b0a9dad89
Evidence Type Source Name Value Confidence Vendor file name index-html High Vendor jar package name nutch Low Vendor jar package name indexer Low Vendor jar package name apache Low Product file name index-html High Product jar package name nutch Low Product jar package name indexer Low Product jar package name html Low
index-metadata.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/index-metadata/index-metadata.jarMD5: 70c07d077680bc7d89926f396028a3ddSHA1: da874e0bb58ef449723d9b39aec3bd43abb4e50bSHA256: 922200d40eba5fa51140a6a7674abad670dea3cab3597330a6214eee226a9014
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor file name index-metadata High Vendor jar package name indexer Low Vendor jar package name apache Low Product jar package name nutch Low Product file name index-metadata High Product jar package name indexer Low Product jar package name metadata Low
index-more.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/index-more/index-more.jarMD5: 402b4b193b4cc100fe96bf4b17fc9b7cSHA1: 4a5385828696e2a4633d42c528a18e8700a76200SHA256: fcbf1a2749f40852653cb13abd6c76ca5ea67a45f7a49b06b9425cd0fee35d13
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor jar package name indexer Low Vendor file name index-more High Vendor jar package name apache Low Product jar package name nutch Low Product jar package name indexer Low Product file name index-more High Product jar package name more Low
HdrHistogram-2.1.6.jarDescription:
HdrHistogram supports the recording and analyzing sampled data value
counts across a configurable integer value range with configurable value
precision within the range. Value precision is expressed as the number of
significant digits in the value recording, and provides control over value
quantization behavior across the value range and the subsequent value
resolution at any given level.
License:
Public Domain, per Creative Commons CC0: http://creativecommons.org/publicdomain/zero/1.0/ File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/HdrHistogram-2.1.6.jar
MD5: 565bf21a1fec0dc39e8b9d5eb0642344
SHA1: 7495feb7f71ee124bd2a7e7d83590e296d71d80e
SHA256: 1d44b3a32d268aa453ee7a9bb89650dfccb159a3160df49d92f299f2b72e9988
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Vendor pom url http://hdrhistogram.github.io/HdrHistogram/ Highest Vendor pom name HdrHistogram High Vendor Manifest Implementation-Vendor-Id org.hdrhistogram Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom groupid hdrhistogram Highest Vendor file name HdrHistogram High Vendor pom description HdrHistogram supports the recording and analyzing sampled data value counts across a configurable integer value range with configurable value precision within the range. Value precision is expressed as the number of significant digits in the value recording, and provides control over value quantization behavior across the value range and the subsequent value resolution at any given level. Low Vendor manifest Bundle-Description HdrHistogram supports the recording and analyzing sampled data value counts across a configurable integer value range with configurable value precision within the range. Value precision is expressed as the number of significant digits in the value recording, and provides control over value quantization behavior across the value range and the subsequent value resolution at any given level. Low Vendor pom artifactid HdrHistogram Low Product Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Product pom url http://hdrhistogram.github.io/HdrHistogram/ Medium Product Manifest Bundle-Name HdrHistogram Medium Product pom artifactid HdrHistogram Highest Product Manifest specification-title HdrHistogram Medium Product Manifest Implementation-Title HdrHistogram High Product pom groupid hdrhistogram Low Product pom name HdrHistogram High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product file name HdrHistogram High Product pom description HdrHistogram supports the recording and analyzing sampled data value counts across a configurable integer value range with configurable value precision within the range. Value precision is expressed as the number of significant digits in the value recording, and provides control over value quantization behavior across the value range and the subsequent value resolution at any given level. Low Product manifest Bundle-Description HdrHistogram supports the recording and analyzing sampled data value counts across a configurable integer value range with configurable value precision within the range. Value precision is expressed as the number of significant digits in the value recording, and provides control over value quantization behavior across the value range and the subsequent value resolution at any given level. Low Version pom version 2.1.6 Highest Version Manifest Implementation-Version 2.1.6 High Version file version 2.1.6 Highest
maven: org.hdrhistogram:HdrHistogram:2.1.6 Confidence :High commons-cli-1.3.1.jarDescription:
Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/commons-cli-1.3.1.jar
MD5: 8d5fa2a42fef17d9034b35a9ac9cc750
SHA1: 1303efbc4b181e5a58bf2e967dc156a3132b97c0
SHA256: 3a2f057041aa6a8813f5b59b695f726c5e85014a703d208d7e1689098e92d8c0
Evidence Type Source Name Value Confidence Vendor pom groupid commons-cli Highest Vendor file name commons-cli High Vendor pom url http://commons.apache.org/proper/commons-cli/ Highest Vendor Manifest implementation-build tags/cli-1.3.1-RC1@r1685378; 2015-06-14 10:06:05+0000 Low Vendor pom artifactid commons-cli Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.cli Medium Vendor pom description Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-cli/ Low Vendor manifest Bundle-Description Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Vendor pom name Apache Commons CLI High Product Manifest specification-title Apache Commons CLI Medium Product file name commons-cli High Product Manifest Implementation-Title Apache Commons CLI High Product Manifest implementation-build tags/cli-1.3.1-RC1@r1685378; 2015-06-14 10:06:05+0000 Low Product pom parent-artifactid commons-parent Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product pom url http://commons.apache.org/proper/commons-cli/ Medium Product pom parent-groupid org.apache.commons Low Product Manifest bundle-symbolicname org.apache.commons.cli Medium Product pom description Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Product Manifest bundle-docurl http://commons.apache.org/proper/commons-cli/ Low Product Manifest Bundle-Name Apache Commons CLI Medium Product manifest Bundle-Description Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface. Low Product pom artifactid commons-cli Highest Product pom groupid commons-cli Low Product pom name Apache Commons CLI High Version file version 1.3.1 Highest Version Manifest Implementation-Version 1.3.1 High Version pom version 1.3.1 Highest
maven: commons-cli:commons-cli:1.3.1 Confidence :High compress-lzf-1.0.2.jarDescription:
Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.
Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.
See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package.
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/compress-lzf-1.0.2.jar
MD5: cfdf61e17e8b2f4f00ef58d9443aae5e
SHA1: 62896e6fca184c79cc01a14d143f3ae2b4f4b4ae
SHA256: 98f374ddd7c6bb8b5ad67ba3bf96dc0f7bac71b090ee28fdb130ba46167119c0
Evidence Type Source Name Value Confidence Vendor pom groupid ning Highest Vendor file name compress-lzf High Vendor pom description Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.
Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.
See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package. Low Vendor pom artifactid compress-lzf Low Vendor pom url http://github.com/ning/compress Highest Vendor Manifest bundle-symbolicname com.ning.compress-lzf Medium Vendor manifest Bundle-Description Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package. Low Vendor pom name Compress-LZF High Product Manifest Bundle-Name Compress-LZF Medium Product file name compress-lzf High Product pom artifactid compress-lzf Highest Product pom groupid ning Low Product pom url http://github.com/ning/compress Medium Product pom description Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.
Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.
See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package. Low Product Manifest bundle-symbolicname com.ning.compress-lzf Medium Product manifest Bundle-Description Compression codec for LZF encoding for particularly encoding/decoding, with reasonable compression.Compressor is basic Lempel-Ziv codec, without Huffman (deflate/gzip) or statistical post-encoding.See "http://oldhome.schmorp.de/marc/liblzf.html" for more on original LZF package. Low Product pom name Compress-LZF High Version pom version 1.0.2 Highest Version file version 1.0.2 Highest
maven: com.ning:compress-lzf:1.0.2 Confidence :High elasticsearch-2.2.0.jarDescription:
Elasticsearch - Open Source, Distributed, RESTful Search Engine File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/elasticsearch-2.2.0.jarMD5: b7fe75d93bfedff58f56ae62b334d7c1SHA1: 9b4096cb3b175d0d3a643b70fe95b6a1c8e48553SHA256: f273e3bdcdd675213e7136160fdd4b666d5105e69821e1585057713abeee07d8
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.elasticsearch Medium Vendor Manifest x-build-number 8ff36d139e16f8720f2947ef62c8167a888992fe Low Vendor Manifest x-build-time 1453901559725 Low Vendor pom parent-artifactid parent Low Vendor pom name Elasticsearch: Core High Vendor file name elasticsearch High Vendor Manifest x-build-branch 2.2 Low Vendor pom groupid elasticsearch Highest Vendor pom parent-groupid org.elasticsearch Medium Vendor pom description Elasticsearch - Open Source, Distributed, RESTful Search Engine Medium Vendor pom artifactid elasticsearch Low Product pom artifactid elasticsearch Highest Product Manifest Implementation-Title Elasticsearch: Core High Product Manifest x-build-number 8ff36d139e16f8720f2947ef62c8167a888992fe Low Product Manifest x-build-time 1453901559725 Low Product pom parent-artifactid parent Medium Product pom groupid elasticsearch Low Product pom name Elasticsearch: Core High Product file name elasticsearch High Product Manifest x-build-branch 2.2 Low Product pom parent-groupid org.elasticsearch Low Product pom description Elasticsearch - Open Source, Distributed, RESTful Search Engine Medium Version pom version 2.2.0 Highest Version file version 2.2.0 Highest Version Manifest Implementation-Version 2.2.0 High
cpe: cpe:/a:elasticsearch:elasticsearch:2.2.0 Confidence :Low suppress maven: org.elasticsearch:elasticsearch:2.2.0 Confidence :High guava-18.0.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/guava-18.0.jar
MD5: 947641f6bb535b1d942d1bc387c45290
SHA1: cce0823396aa693798f8882e64213b1772032b09
SHA256: d664fbfc03d2e5ce9cab2a44fb01f1d0bf9dfebeccc1a473b1f9ea31f79f6f99
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Vendor file name guava High Vendor pom artifactid guava Low Vendor pom parent-artifactid guava-parent Low Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-groupid com.google.guava Medium Vendor Manifest bundle-docurl https://guava-libraries.googlecode.com/ Low Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom groupid google.guava Highest Product pom groupid google.guava Low Product manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product file name guava High Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Product pom parent-artifactid guava-parent Medium Product Manifest bundle-docurl https://guava-libraries.googlecode.com/ Low Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Low Version pom version 18.0 Highest Version file version 18.0 Highest
maven: com.google.guava:guava:18.0 Confidence :High hppc-0.7.1.jarDescription:
High Performance Primitive Collections.
Fundamental data structures (maps, sets, lists, stacks, queues) generated for
combinations of object and primitive types to conserve JVM memory and speed
up execution. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/hppc-0.7.1.jarMD5: 2ff89be5b49144c330190cf7137c3a26SHA1: 8b5057f74ea378c0150a1860874a3ebdcb713767SHA256: 40d2a57f59e9eae7b018d3b4841954087ee40a5c1db6a54c3ea87742e3890391
Evidence Type Source Name Value Confidence Vendor pom groupid carrotsearch Highest Vendor pom description High Performance Primitive Collections. Fundamental data structures (maps, sets, lists, stacks, queues) generated for combinations of object and primitive types to conserve JVM memory and speed up execution. Low Vendor pom artifactid hppc Low Vendor pom parent-groupid com.carrotsearch Medium Vendor jar package name carrotsearch Low Vendor pom name HPPC Collections High Vendor pom parent-artifactid hppc-parent Low Vendor file name hppc High Vendor jar package name hppc Low Product pom parent-artifactid hppc-parent Medium Product pom description High Performance Primitive Collections. Fundamental data structures (maps, sets, lists, stacks, queues) generated for combinations of object and primitive types to conserve JVM memory and speed up execution. Low Product pom parent-groupid com.carrotsearch Low Product pom name HPPC Collections High Product pom artifactid hppc Highest Product file name hppc High Product pom groupid carrotsearch Low Product jar package name hppc Low Version file version 0.7.1 Highest Version pom version 0.7.1 Highest
maven: com.carrotsearch:hppc:0.7.1 Confidence :High indexer-elastic2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/indexer-elastic2.jarMD5: 429f0bea8db193fb76b9be2e8aa3f742SHA1: b3288b0723a40d2164f18676439c13fe3399a1b2SHA256: cdd19db20454a5904e7ba9f228d2e4ab9a7a5b79da2f67af271998e3bfbe6e7f
Evidence Type Source Name Value Confidence Vendor jar package name elasticsearch Low Vendor file name indexer-elastic2 High Product file name indexer-elastic2 High Version file version 2 Medium Version file name indexer-elastic2 Medium
jackson-core-2.6.2.jarDescription:
Core Jackson abstractions, basic JSON streaming API implementation
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jackson-core-2.6.2.jar
MD5: 5478388129427723d00ac8013b5b44a6
SHA1: 123f29333b2c6b3516b14252b6e93226bfcd6e37
SHA256: d7602c2afd4b2a184b21a1fddb0dc1552eadfc56ad79845a40a68ecd85d37634
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor pom parent-artifactid jackson-parent Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor Manifest implementation-build-date 2015-09-14 19:44:55-0700 Low Vendor pom url FasterXML/jackson-core Highest Vendor pom artifactid jackson-core Low Vendor Manifest specification-vendor FasterXML Low Vendor pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium Vendor pom name Jackson-core High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom groupid fasterxml.jackson.core Highest Vendor file name jackson-core High Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest implementation-build-date 2015-09-14 19:44:55-0700 Low Product pom parent-groupid com.fasterxml.jackson Low Product Manifest specification-title Jackson-core Medium Product pom groupid fasterxml.jackson.core Low Product pom url FasterXML/jackson-core High Product Manifest Implementation-Title Jackson-core High Product pom parent-artifactid jackson-parent Medium Product pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium Product pom name Jackson-core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product file name jackson-core High Product pom artifactid jackson-core Highest Version pom version 2.6.2 Highest Version file version 2.6.2 Highest Version Manifest Implementation-Version 2.6.2 High
Related Dependencies jackson-dataformat-smile-2.6.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jackson-dataformat-smile-2.6.2.jar MD5: 5e763c8df2aec3cc45a1c4a039c0161e SHA1: 395d18c1a1dd730b8026ee59c4067e5d2b45ba6e SHA256: 830216ec3a216bf21445a0f9450c7689b5d6a7720e61c9aea9191a3083280dbb jackson-dataformat-yaml-2.6.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jackson-dataformat-yaml-2.6.2.jar MD5: f523c16b734d7beea53bec893c8ad86e SHA1: 4ae23088dd3fae47c66843f2e4251d7255ee140e SHA256: fd8a78c3913f3ce7b01b5383708b11e3071051dd8b2d564d6af11e630595c542 jackson-dataformat-cbor-2.6.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jackson-dataformat-cbor-2.6.2.jar MD5: 46df61363d4faf621b174b6f365bd87e SHA1: 1e13c575f914c83761bb8e2aca7dfd9e4c647579 SHA256: 5528d4a7e59410345bbb3f1f54cfb955c0ff7e81aeb831d943a1bb6dafd522ab cpe: cpe:/a:fasterxml:jackson:2.6.2 Confidence :Low suppress maven: com.fasterxml.jackson.core:jackson-core:2.6.2 Confidence :High jarjar-1.3.jarDescription:
Jar Jar Links is a utility that makes it easy to repackage Java libraries and embed them into your own distribution. License:
Apache License version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jarjar-1.3.jar
MD5: 3948597624eed18ddc8cb628b08f536d
SHA1: b81c2719c63fa8e6f3eca5b11b8e9b5ad79463db
SHA256: 4225c8ee1bf3079c4b07c76fe03c3e28809a22204db6249c9417efa4f804b3a7
Evidence Type Source Name Value Confidence Vendor pom name Jar Jar Links High Vendor jar package name jarjar Low Vendor file name jarjar High Vendor pom url http://jarjar.googlecode.com/ Highest Vendor pom groupid googlecode.jarjar Highest Vendor jar package name tonicsystems Low Vendor central groupid com.googlecode.jarjar Highest Vendor pom artifactid jarjar Low Vendor pom description Jar Jar Links is a utility that makes it easy to repackage Java libraries and embed them into your own distribution. Low Product pom name Jar Jar Links High Product jar package name jarjar Low Product file name jarjar High Product pom artifactid jarjar Highest Product central artifactid jarjar Highest Product pom groupid googlecode.jarjar Low Product pom url http://jarjar.googlecode.com/ Medium Product pom description Jar Jar Links is a utility that makes it easy to repackage Java libraries and embed them into your own distribution. Low Version central version 1.3 Highest Version file version 1.3 Highest Version pom version 1.3 Highest Version Manifest Implementation-Version 1.3 High
joda-convert-1.2.jarDescription:
Library to convert Objects to and from String License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/joda-convert-1.2.jar
MD5: b0da47d5736aa6c16c0da7fd4fcfb8ba
SHA1: 35ec554f0cd00c956cc69051514d9488b1374dec
SHA256: 5703e1a2ac1969fe90f87076c1f1136822bf31d8948252159c86e6d0535c81a8
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://joda-convert.sourceforge.net/ Low Vendor pom artifactid joda-convert Low Vendor Manifest specification-vendor Joda.org Low Vendor pom groupid joda Highest Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor file name joda-convert High Vendor pom description Library to convert Objects to and from String Medium Vendor pom url http://joda-convert.sourceforge.net Highest Vendor pom organization url http://www.joda.org Medium Vendor Manifest extension-name joda-convert Medium Vendor Manifest Implementation-Vendor Joda.org High Vendor pom organization name Joda.org High Vendor Manifest bundle-symbolicname joda-convert Medium Vendor pom name Joda convert High Product Manifest bundle-docurl http://joda-convert.sourceforge.net/ Low Product pom url http://joda-convert.sourceforge.net Medium Product pom artifactid joda-convert Highest Product file name joda-convert High Product Manifest Implementation-Title org.joda.convert High Product pom organization name Joda.org Low Product pom groupid joda Low Product pom description Library to convert Objects to and from String Medium Product pom organization url http://www.joda.org Low Product Manifest Bundle-Name Joda-Convert Medium Product Manifest extension-name joda-convert Medium Product Manifest specification-title Joda-Convert Medium Product Manifest bundle-symbolicname joda-convert Medium Product pom name Joda convert High Version Manifest Implementation-Version 1.2 High Version file version 1.2 Highest Version pom version 1.2 Highest
maven: org.joda:joda-convert:1.2 Confidence :High joda-time-2.8.2.jarDescription:
Date and time library to replace JDK date handling License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/joda-time-2.8.2.jar
MD5: 59644e5f2e55a55ae8ccf2ca65a73b81
SHA1: d27c24204c5e507b16fec01006b3d0f1ec42aed4
SHA256: 7c71ac7b4c0e6b7e49bcc93c135825d23f427aba62397b313c7fdcd2c19c42cb
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://www.joda.org/joda-time/ Low Vendor Manifest specification-vendor Joda.org Low Vendor Manifest bundle-docurl http://www.joda.org/joda-time/ Low Vendor pom name Joda-Time High Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor pom groupid joda-time Highest Vendor pom description Date and time library to replace JDK date handling Medium Vendor Manifest extension-name joda-time Medium Vendor pom url http://www.joda.org/joda-time/ Highest Vendor file name joda-time High Vendor pom organization url http://www.joda.org Medium Vendor Manifest bundle-symbolicname joda-time Medium Vendor pom artifactid joda-time Low Vendor Manifest Implementation-Vendor Joda.org High Vendor pom organization name Joda.org High Product pom groupid joda-time Low Product Manifest specification-title Joda-Time Medium Product Manifest implementation-url http://www.joda.org/joda-time/ Low Product Manifest bundle-docurl http://www.joda.org/joda-time/ Low Product pom name Joda-Time High Product pom description Date and time library to replace JDK date handling Medium Product Manifest Bundle-Name Joda-Time Medium Product pom organization name Joda.org Low Product Manifest extension-name joda-time Medium Product pom organization url http://www.joda.org Low Product pom artifactid joda-time Highest Product file name joda-time High Product Manifest bundle-symbolicname joda-time Medium Product pom url http://www.joda.org/joda-time/ Medium Product Manifest Implementation-Title org.joda.time High Version pom version 2.8.2 Highest Version file version 2.8.2 Highest Version Manifest Implementation-Version 2.8.2 High
maven: joda-time:joda-time:2.8.2 Confidence :High jsr166e-1.1.0.jarDescription:
JSR166e License:
CC0 1.0 Universal: http://creativecommons.org/publicdomain/zero/1.0/ File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/jsr166e-1.1.0.jar
MD5: 3fcf5c9feec7c8331de1c6101dcf818f
SHA1: 233098147123ee5ddcd39ffc57ff648be4b7e5b2
SHA256: abd9acc93b3c93fc5534b63e5f7cccf29c488cdcfd9084dc19c0fe71631b564b
Evidence Type Source Name Value Confidence Vendor pom artifactid jsr166e Low Vendor pom name JSR166e High Vendor pom groupid twitter Highest Vendor jar package name jsr166e Low Vendor pom url http://github.com/twitter/jsr166e Highest Vendor jar package name twitter Low Vendor file name jsr166e High Vendor pom description JSR166e Medium Product pom groupid twitter Low Product pom name JSR166e High Product jar package name jsr166e Low Product pom artifactid jsr166e Highest Product file name jsr166e High Product pom description JSR166e Medium Product pom url http://github.com/twitter/jsr166e Medium Version file version 1.1.0 Highest Version pom version 1.1.0 Highest
cpe: cpe:/a:twitter:twitter:1.1.0 Confidence :Low suppress cpe: cpe:/a:twitter_project:twitter:1.1.0 Confidence :Low suppress maven: com.twitter:jsr166e:1.1.0 Confidence :High lucene-analyzers-common-5.4.1.jarDescription:
Additional Analyzers File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-analyzers-common-5.4.1.jarMD5: eab8af490c260d70638ed028d2e52ad9SHA1: c2aa2c4e00eb9cdeb5ac00dc0495e70c441f681eSHA256: 298f16d4e65b0c43b101983c1366c8dbb17ae7980257a3b38b3ef17cd0f5bc6e
Evidence Type Source Name Value Confidence Vendor pom name Lucene Common Analyzers High Vendor pom artifactid lucene-analyzers-common Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor pom description Additional Analyzers Medium Vendor jar package name apache Low Vendor file name lucene-analyzers-common High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor jar package name analysis Low Vendor pom parent-groupid org.apache.lucene Medium Product Manifest specification-title Lucene Search Engine: analyzers-common Medium Product pom parent-groupid org.apache.lucene Low Product pom name Lucene Common Analyzers High Product Manifest Implementation-Title org.apache.lucene High Product central artifactid lucene-analyzers-common Highest Product pom description Additional Analyzers Medium Product file name lucene-analyzers-common High Product Manifest extension-name org.apache.lucene Medium Product pom artifactid lucene-analyzers-common Highest Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product jar package name analysis Low Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-backward-codecs-5.4.1.jarDescription:
Codecs for older versions of Lucene.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-backward-codecs-5.4.1.jarMD5: 3d8d9c2a8d8a36b8a3e8ef02118a851bSHA1: 5273da96380dfab302ad06c27fe58100db4c4e2fSHA256: 130ba1ae781063148831c9b38110df335561180ee1ffd89a3353e80da777b3e3
Evidence Type Source Name Value Confidence Vendor jar package name codecs Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Lucene Memory High Vendor pom description
Codecs for older versions of Lucene.
Medium Vendor file name lucene-backward-codecs High Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom artifactid lucene-backward-codecs Low Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product Manifest Implementation-Title org.apache.lucene High Product jar package name codecs Low Product central artifactid lucene-backward-codecs Highest Product pom name Lucene Memory High Product pom description
Codecs for older versions of Lucene.
Medium Product file name lucene-backward-codecs High Product Manifest specification-title Lucene Search Engine: backward-codecs Medium Product pom artifactid lucene-backward-codecs Highest Product Manifest extension-name org.apache.lucene Medium Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-core-5.4.1.jarDescription:
Apache Lucene Java Core File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-core-5.4.1.jarMD5: f0f646aa1b57a3c37b251c92a2ff0fe2SHA1: c52b2088e2c30dfd95fd296ab6fb9cf8de9855abSHA256: 3518557dbe06f0aedc8c737b3d53de77ad60e46ebe8e81cc56f7a793a38bdf29
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-core Low Vendor pom description Apache Lucene Java Core Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom name Lucene Core High Vendor file name lucene-core High Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product Manifest specification-title Lucene Search Engine: core Medium Product Manifest Implementation-Title org.apache.lucene High Product pom description Apache Lucene Java Core Medium Product central artifactid lucene-core Highest Product pom artifactid lucene-core Highest Product Manifest extension-name org.apache.lucene Medium Product pom name Lucene Core High Product file name lucene-core High Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-grouping-5.4.1.jarDescription:
Lucene Grouping Module File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-grouping-5.4.1.jarMD5: 2b0c04347f9c5c6c4b18f152e76d5a1fSHA1: de757064b78b275583378501e9c18be563b6ae44SHA256: d6b434fc0a875209945fc960aaa8ea8097e97c88f4e1db662b95207326e97990
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Lucene Grouping High Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name search Low Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor file name lucene-grouping High Vendor pom description Lucene Grouping Module Medium Vendor pom artifactid lucene-grouping Low Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product Manifest Implementation-Title org.apache.lucene High Product pom name Lucene Grouping High Product Manifest specification-title Lucene Search Engine: grouping Medium Product jar package name search Low Product Manifest extension-name org.apache.lucene Medium Product jar package name grouping Low Product file name lucene-grouping High Product pom description Lucene Grouping Module Medium Product pom artifactid lucene-grouping Highest Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product central artifactid lucene-grouping Highest Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-highlighter-5.4.1.jarDescription:
This is the highlighter for apache lucene java
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-highlighter-5.4.1.jarMD5: ced2d944c32fa24b21724d42b6a17ccfSHA1: cf8b79f71cb5f36ecf1bbfbc380089e4640a74c2SHA256: 7e9c574562a291dd21a2ea287eee68561d7a3dd427edb4b0e8c2bff64b4239af
Evidence Type Source Name Value Confidence Vendor file name lucene-highlighter High Vendor pom artifactid lucene-highlighter Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom description
This is the highlighter for apache lucene java
Medium Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name search Low Vendor Manifest extension-name org.apache.lucene Medium Vendor pom name Lucene Highlighter High Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product Manifest specification-title Lucene Search Engine: highlighter Medium Product pom parent-groupid org.apache.lucene Low Product file name lucene-highlighter High Product Manifest Implementation-Title org.apache.lucene High Product pom description
This is the highlighter for apache lucene java
Medium Product central artifactid lucene-highlighter Highest Product jar package name search Low Product Manifest extension-name org.apache.lucene Medium Product pom name Lucene Highlighter High Product pom groupid apache.lucene Low Product pom artifactid lucene-highlighter Highest Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-join-5.4.1.jarDescription:
Lucene Join Module File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-join-5.4.1.jarMD5: 55f2895837fe475a29431d7dbcd67a14SHA1: 41c28c524b44395ebecdaf5e7cede904d9e4d2e4SHA256: cc786b259146238b5ed3d72e7a0013c865d53b36f3728167dd2c69fbe01532ad
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor file name lucene-join High Vendor jar package name apache Low Vendor pom description Lucene Join Module Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name search Low Vendor pom artifactid lucene-join Low Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Vendor pom name Lucene Join High Product central artifactid lucene-join Highest Product pom parent-groupid org.apache.lucene Low Product pom artifactid lucene-join Highest Product Manifest Implementation-Title org.apache.lucene High Product file name lucene-join High Product pom description Lucene Join Module Medium Product jar package name join Low Product jar package name search Low Product Manifest extension-name org.apache.lucene Medium Product Manifest specification-title Lucene Search Engine: join Medium Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product pom name Lucene Join High Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-memory-5.4.1.jarDescription:
High-performance single-document index to compare against Query
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-memory-5.4.1.jarMD5: af77dccd783d4b8151011c9b5d31091fSHA1: 806841bb63660530ccafc6fcb4dd239722547429SHA256: c8ad21de68ed8d5f79657ea70729c0a4c1573fd0a274a3bd34bca4f4c92c4585
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-memory Low Vendor pom description
High-performance single-document index to compare against Query
Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Lucene Memory High Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor file name lucene-memory High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor jar package name index Low Vendor pom parent-groupid org.apache.lucene Medium Product Manifest specification-title Lucene Search Engine: memory Medium Product pom parent-groupid org.apache.lucene Low Product central artifactid lucene-memory Highest Product Manifest Implementation-Title org.apache.lucene High Product pom description
High-performance single-document index to compare against Query
Medium Product pom name Lucene Memory High Product file name lucene-memory High Product Manifest extension-name org.apache.lucene Medium Product jar package name memory Low Product pom groupid apache.lucene Low Product pom artifactid lucene-memory Highest Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product jar package name index Low Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-misc-5.4.1.jarDescription:
Miscellaneous Lucene extensions File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-misc-5.4.1.jarMD5: 24095d90fd69bc6df26a92960c51f497SHA1: 95f433b9d7dd470cc0aa5076e0f233907745674bSHA256: 068ce23565513abc221367f07b8249c81b652b29bc2ea2fe3ed5982d0504b332
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-misc Low Vendor pom description Miscellaneous Lucene extensions Medium Vendor file name lucene-misc High Vendor pom name Lucene Miscellaneous High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom description Miscellaneous Lucene extensions Medium Product pom parent-groupid org.apache.lucene Low Product file name lucene-misc High Product Manifest Implementation-Title org.apache.lucene High Product pom name Lucene Miscellaneous High Product Manifest extension-name org.apache.lucene Medium Product pom artifactid lucene-misc Highest Product pom groupid apache.lucene Low Product Manifest specification-title Lucene Search Engine: misc Medium Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product central artifactid lucene-misc Highest Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-queries-5.4.1.jarDescription:
Lucene Queries Module File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-queries-5.4.1.jarMD5: 5b8017254369add8b47d3af0fe4d94e9SHA1: cbb34afcf0596e75731a493227eece69ac117522SHA256: 415f479ce93682a6b0feb078f0b35f18a42f7e9e403fec4d63a2e68b06b15566
Evidence Type Source Name Value Confidence Vendor file name lucene-queries High Vendor pom name Lucene Queries High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor jar package name queries Low Vendor pom artifactid lucene-queries Low Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom description Lucene Queries Module Medium Vendor pom parent-groupid org.apache.lucene Medium Product file name lucene-queries High Product pom parent-groupid org.apache.lucene Low Product Manifest Implementation-Title org.apache.lucene High Product pom name Lucene Queries High Product Manifest extension-name org.apache.lucene Medium Product jar package name queries Low Product pom groupid apache.lucene Low Product pom artifactid lucene-queries Highest Product Manifest specification-title Lucene Search Engine: queries Medium Product jar package name function Low Product central artifactid lucene-queries Highest Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product pom description Lucene Queries Module Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-queryparser-5.4.1.jarDescription:
Lucene QueryParsers module File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-queryparser-5.4.1.jarMD5: 5af2fc046fda801f560bb6a24d1d7d79SHA1: dccd5279bfa656dec21af444a7a66820eb1cd618SHA256: 1085bb30cb6caf36ca1d6d14a095d161de829b4611c5c2f6759d5153197950ed
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-queryparser Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor pom name Lucene QueryParsers High Vendor central groupid org.apache.lucene Highest Vendor pom description Lucene QueryParsers module Medium Vendor jar package name queryparser Low Vendor file name lucene-queryparser High Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product jar package name flexible Low Product pom parent-groupid org.apache.lucene Low Product Manifest specification-title Lucene Search Engine: queryparser Medium Product Manifest Implementation-Title org.apache.lucene High Product pom artifactid lucene-queryparser Highest Product Manifest extension-name org.apache.lucene Medium Product pom name Lucene QueryParsers High Product pom description Lucene QueryParsers module Medium Product jar package name queryparser Low Product pom groupid apache.lucene Low Product file name lucene-queryparser High Product central artifactid lucene-queryparser Highest Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-sandbox-5.4.1.jarDescription:
Lucene Sandbox File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-sandbox-5.4.1.jarMD5: 6b5076344f91626fb001379dd2bf9f6dSHA1: a2d8767abd7865048e6150bc689f5c942fc64048SHA256: 7df66192ff70eea5cfc9b2049befb1f9317306ae55565b8c44311adf46352b9d
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor file name lucene-sandbox High Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor pom description Lucene Sandbox Medium Vendor central groupid org.apache.lucene Highest Vendor pom artifactid lucene-sandbox Low Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Vendor pom name Lucene Sandbox High Product pom parent-groupid org.apache.lucene Low Product Manifest Implementation-Title org.apache.lucene High Product pom artifactid lucene-sandbox Highest Product file name lucene-sandbox High Product Manifest specification-title Lucene Search Engine: sandbox Medium Product Manifest extension-name org.apache.lucene Medium Product pom description Lucene Sandbox Medium Product central artifactid lucene-sandbox Highest Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Product pom name Lucene Sandbox High Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-spatial-5.4.1.jarDescription:
Spatial Strategies for Apache Lucene
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-spatial-5.4.1.jarMD5: b223509aa034e6b3d15fe9a1120a3d58SHA1: 68630557355cf7b4b0c51b210d6aec3d599ec43fSHA256: f90173cc1600dd54e321c24d92e36116f7383922dcb45db69ec72b28d8281ff6
Evidence Type Source Name Value Confidence Vendor pom name Lucene Spatial High Vendor file name lucene-spatial High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name spatial Low Vendor pom description
Spatial Strategies for Apache Lucene
Medium Vendor pom groupid apache.lucene Highest Vendor pom artifactid lucene-spatial Low Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product pom name Lucene Spatial High Product file name lucene-spatial High Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Search Engine: spatial Medium Product jar package name spatial Low Product pom description
Spatial Strategies for Apache Lucene
Medium Product central artifactid lucene-spatial Highest Product Manifest extension-name org.apache.lucene Medium Product pom artifactid lucene-spatial Highest Product pom groupid apache.lucene Low Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-spatial3d-5.4.1.jarDescription:
Lucene Spatial shapes implemented using 3D planar geometry
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-spatial3d-5.4.1.jarMD5: f6bfb560e7966cbb397cce30679b1ee9SHA1: ba3ad781a4b586898533ce928bff51b430a55e6aSHA256: 2cd581effd577df61fecd503dad800c563bc800e68c3cce30b88f701a469c438
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-spatial3d Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.lucene Medium Vendor pom description
Lucene Spatial shapes implemented using 3D planar geometry
Medium Vendor file name lucene-spatial3d High Vendor jar package name geo3d Low Vendor central groupid org.apache.lucene Highest Vendor pom name Lucene Spatial 3D High Vendor pom parent-artifactid lucene-parent Low Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product Manifest specification-title Lucene Search Engine: spatial3d Medium Product Manifest Implementation-Title org.apache.lucene High Product central artifactid lucene-spatial3d Highest Product pom artifactid lucene-spatial3d Highest Product Manifest extension-name org.apache.lucene Medium Product pom description
Lucene Spatial shapes implemented using 3D planar geometry
Medium Product file name lucene-spatial3d High Product jar package name geo3d Low Product pom groupid apache.lucene Low Product pom name Lucene Spatial 3D High Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
lucene-suggest-5.4.1.jarDescription:
Lucene Suggest Module File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/lucene-suggest-5.4.1.jarMD5: f05a38e8b2712a94d6489549ae07cd85SHA1: af6458f132b0974c4f40b82f9c7adde94a872f9bSHA256: fffee2c10ee96ea8ff1b50f43c7574818167f01939d442312e90f46f10a78c16
Evidence Type Source Name Value Confidence Vendor pom artifactid lucene-suggest Low Vendor file name lucene-suggest High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.lucene Highest Vendor jar package name apache Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name search Low Vendor Manifest extension-name org.apache.lucene Medium Vendor central groupid org.apache.lucene Highest Vendor pom name Lucene Suggest High Vendor pom parent-artifactid lucene-parent Low Vendor pom description Lucene Suggest Module Medium Vendor jar package name lucene Low Vendor pom parent-groupid org.apache.lucene Medium Product pom parent-groupid org.apache.lucene Low Product jar package name suggest Low Product Manifest Implementation-Title org.apache.lucene High Product file name lucene-suggest High Product Manifest specification-title Lucene Search Engine: suggest Medium Product pom artifactid lucene-suggest Highest Product jar package name search Low Product Manifest extension-name org.apache.lucene Medium Product central artifactid lucene-suggest Highest Product pom groupid apache.lucene Low Product pom name Lucene Suggest High Product pom description Lucene Suggest Module Medium Product jar package name lucene Low Product pom parent-artifactid lucene-parent Medium Version pom version 5.4.1 Highest Version central version 5.4.1 Highest Version file version 5.4.1 Highest
netty-3.10.5.Final.jarDescription:
The Netty project is an effort to provide an asynchronous event-driven
network application framework and tools for rapid development of
maintainable high performance and high scalability protocol servers and
clients. In other words, Netty is a NIO client server framework which
enables quick and easy development of network applications such as protocol
servers and clients. It greatly simplifies and streamlines network
programming such as TCP and UDP socket server.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/netty-3.10.5.Final.jar
MD5: 14466fef5f114f444c688f7977e9dbce
SHA1: 9ca7d55d246092bddd29b867706e2f6c7db701a0
SHA256: eb031acf8a00733481bcd60807925ecfc9ce3840f13823d4b96cdcb1132db1da
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://netty.io/ Low Vendor pom groupid io.netty Highest Vendor pom organization name The Netty Project High Vendor pom name Netty High Vendor pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Vendor Manifest bundle-symbolicname org.jboss.netty Medium Vendor pom organization url http://netty.io/ Medium Vendor pom artifactid netty Low Vendor file name netty High Vendor pom url http://netty.io/ Highest Vendor manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product pom url http://netty.io/ Medium Product pom organization url http://netty.io/ Low Product pom name Netty High Product pom organization name The Netty Project Low Product pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product Manifest Bundle-Name Netty Medium Product pom artifactid netty Highest Product file name netty High Product pom groupid io.netty Low Product Manifest bundle-docurl http://netty.io/ Low Product Manifest bundle-symbolicname org.jboss.netty Medium Product manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Version pom version 3.10.5.Final Highest Version file version 3.10.5 Highest
maven: io.netty:netty:3.10.5.Final Confidence :Highcpe: cpe:/a:netty_project:netty:3.10.5 Confidence :Low suppress securesm-1.0.jarDescription:
SecurityManager implementation that works around design flaws in Java License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/securesm-1.0.jar
MD5: 5c02fec76c6ac560f103da6586674a41
SHA1: c0c6cf986ba0057390bfcc80c366a0e3157f944b
SHA256: c1c017c7a267fc3815a3dcfd3c0959e4d665eacf08fca0b6494112b70134449f
Evidence Type Source Name Value Confidence Vendor pom description SecurityManager implementation that works around design flaws in Java Medium Vendor jar package name elasticsearch Low Vendor pom artifactid securesm Low Vendor file name securesm High Vendor pom name Elasticsearch SecureSM High Vendor pom groupid elasticsearch Highest Product pom artifactid securesm Highest Product pom description SecurityManager implementation that works around design flaws in Java Medium Product pom groupid elasticsearch Low Product file name securesm High Product pom name Elasticsearch SecureSM High Version pom version 1.0 Highest Version file version 1.0 Highest
maven: org.elasticsearch:securesm:1.0 Confidence :High snakeyaml-1.15.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License Version 2.0: LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/snakeyaml-1.15.jar
MD5: c6502713ff649a557b767b990830c786
SHA1: 3b132bea69e8ee099f416044970997bde80f4ea6
SHA256: 79ea8aac6590f49ee8390c2f17ed9343079e85b44158a097b301dfee42af86ec
Evidence Type Source Name Value Confidence Vendor pom description YAML 1.1 parser and emitter for Java Medium Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor pom groupid yaml Highest Vendor pom artifactid snakeyaml Low Vendor pom url http://www.snakeyaml.org Highest Vendor manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium Vendor pom name SnakeYAML High Vendor file name snakeyaml High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom description YAML 1.1 parser and emitter for Java Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium Product pom name SnakeYAML High Product pom groupid yaml Low Product pom artifactid snakeyaml Highest Product file name snakeyaml High Product pom url http://www.snakeyaml.org Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Version file version 1.15 Highest Version pom version 1.15 Highest
maven: org.yaml:snakeyaml:1.15 Confidence :High spatial4j-0.5.jarDescription:
Spatial4j is a general purpose spatial / geospatial ASL licensed open-source Java library. It's
core capabilities are 3-fold: to provide common geospatially-aware shapes, to provide distance
calculations and other math, and to read shape formats like WKT and GeoJSON.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/spatial4j-0.5.jar
MD5: f46efeafb997d3099238fe4f3ad0b1dc
SHA1: 6e16edaf6b1ba76db7f08c2f3723fce3b358ecc3
SHA256: a14338e0acc21793183f3dca6d8e7b1f036d9fa084169b9d94cf5cf81fbb4e3c
Evidence Type Source Name Value Confidence Vendor jar package name spatial4j Low Vendor pom artifactid spatial4j Low Vendor pom name Spatial4J High Vendor pom description Spatial4j is a general purpose spatial / geospatial ASL licensed open-source Java library. It's core capabilities are 3-fold: to provide common geospatially-aware shapes, to provide distance calculations and other math, and to read shape formats ... Low Vendor file name spatial4j High Vendor jar package name core Low Vendor pom groupid spatial4j Highest Product pom name Spatial4J High Product pom description Spatial4j is a general purpose spatial / geospatial ASL licensed open-source Java library. It's core capabilities are 3-fold: to provide common geospatially-aware shapes, to provide distance calculations and other math, and to read shape formats ... Low Product pom artifactid spatial4j Highest Product file name spatial4j High Product pom groupid spatial4j Low Product jar package name core Low Version pom version 0.5 Highest Version file version 0.5 Highest
maven: com.spatial4j:spatial4j:0.5 Confidence :High t-digest-3.0.jarDescription:
Data structure which allows accurate estimation of quantiles and related rank statistics License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-elastic2/t-digest-3.0.jar
MD5: e7ede835f73c70cc662ca4d241250f1a
SHA1: 84ccf145ac2215e6bfa63baa3101c0af41017cfc
SHA256: 5271fc25f94c01fa7a0e30a522118705bf3db7441a0b9636e5122b05a3d9c35d
Evidence Type Source Name Value Confidence Vendor file name t-digest High Vendor pom description Data structure which allows accurate estimation of quantiles and related rank statistics Medium Vendor pom groupid tdunning Highest Vendor pom artifactid t-digest Low Vendor pom name T-Digest High Vendor jar package name stats Low Vendor jar package name math Low Vendor pom url tdunning/t-digest Highest Vendor jar package name tdunning Low Product file name t-digest High Product pom groupid tdunning Low Product pom description Data structure which allows accurate estimation of quantiles and related rank statistics Medium Product pom url tdunning/t-digest High Product pom name T-Digest High Product pom artifactid t-digest Highest Product jar package name stats Low Product jar package name math Low Version file version 3.0 Highest Version pom version 3.0 Highest
maven: com.tdunning:t-digest:3.0 Confidence :High commons-logging-1.1.1.jarDescription:
Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/commons-logging-1.1.1.jarMD5: ed448347fc0104034aa14c8189bf37deSHA1: 5043bfebc3db072ed80fbd362e7caf00e885d8aeSHA256: ce6f913cad1f0db3aad70186d65c5bc7ffcc9a99e3fe8e0b137312819f7c362f
Evidence Type Source Name Value Confidence Vendor pom url http://commons.apache.org/logging Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom parent-artifactid commons-parent Low Vendor file name commons-logging High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest extension-name org.apache.commons.logging Medium Vendor pom groupid commons-logging Highest Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom name Commons Logging High Vendor pom artifactid commons-logging Low Product pom parent-groupid org.apache.commons Low Product Manifest Implementation-Title Jakarta Commons Logging High Product pom groupid commons-logging Low Product pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Product Manifest specification-title Jakarta Commons Logging Medium Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-logging Highest Product pom url http://commons.apache.org/logging Medium Product file name commons-logging High Product pom name Commons Logging High Product Manifest extension-name org.apache.commons.logging Medium Version pom version 1.1.1 Highest Version Manifest Implementation-Version 1.1.1 High Version file version 1.1.1 Highest
maven: commons-logging:commons-logging:1.1.1 Confidence :High findbugs-annotations-1.3.9-1.jarDescription:
A clean room implementation of the Findbugs Annotations based entirely on the specification provided
by the javadocs and at http://findbugs.sourceforge.net/manual/annotations.html.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/findbugs-annotations-1.3.9-1.jar
MD5: 70fda5202eb9d9ce4f250f2c2ba71152
SHA1: a6b11447635d80757d64b355bed3c00786d86801
SHA256: 1e651066ed9ae35d7e3001d635d1dbba1c2965db0e4e33e2c14ad610543f225c
Evidence Type Source Name Value Confidence Vendor pom groupid github.stephenc.findbugs Highest Vendor pom artifactid findbugs-annotations Low Vendor file name findbugs-annotations High Vendor pom description A clean room implementation of the Findbugs Annotations based entirely on the specification provided by the javadocs and at http://findbugs.sourceforge.net/manual/annotations.html. Low Vendor jar package name edu Low Vendor jar package name umd Low Vendor pom name Findbugs Annotations under Apache License High Vendor pom url http://stephenc.github.com/findbugs-annotations Highest Vendor jar package name cs Low Product pom groupid github.stephenc.findbugs Low Product pom artifactid findbugs-annotations Highest Product file name findbugs-annotations High Product pom description A clean room implementation of the Findbugs Annotations based entirely on the specification provided by the javadocs and at http://findbugs.sourceforge.net/manual/annotations.html. Low Product pom url http://stephenc.github.com/findbugs-annotations Medium Product jar package name umd Low Product jar package name findbugs Low Product pom name Findbugs Annotations under Apache License High Product jar package name cs Low Version pom version 1.3.9-1 Highest Version file version 1.3.9.1 Highest
maven: com.github.stephenc.findbugs:findbugs-annotations:1.3.9-1 Confidence :High guava-12.0.1.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/guava-12.0.1.jar
MD5: aeb6ae1449548bbbce1bda0f8ecc746c
SHA1: b8e78b9af7bf45900e14c6f958486b6ca682195f
SHA256: ec7f9928bc0cd5ca36b32bc3965055c49843d69ac1a9ccf380fdcc3f686af7fc
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Vendor file name guava High Vendor pom artifactid guava Low Vendor pom parent-artifactid guava-parent Low Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-groupid com.google.guava Medium Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom groupid google.guava Highest Product pom groupid google.guava Low Product manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product file name guava High Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Product pom parent-artifactid guava-parent Medium Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Low Version pom version 12.0.1 Highest Version file version 12.0.1 Highest
maven: com.google.guava:guava:12.0.1 Confidence :High hbase-client-0.98.8-hadoop2.jarDescription:
Client of HBase File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/hbase-client-0.98.8-hadoop2.jarMD5: a4aeeb216e73ba855ec59fd83002270cSHA1: 2c07bd0ee9bace297a1ff644da0c4684061904ddSHA256: 617babd99c7b113537c45a3c5c630eacb6172859f61198f72f8584649b01d3cd
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.hbase Medium Vendor pom groupid apache.hbase Highest Vendor pom artifactid hbase-client Low Vendor pom parent-artifactid hbase Low Vendor pom description Client of HBase Medium Vendor file name hbase-client High Vendor pom name HBase - Client High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-groupid org.apache.hbase Medium Product Manifest Implementation-Title HBase - Client High Product pom artifactid hbase-client Highest Product pom description Client of HBase Medium Product file name hbase-client High Product pom name HBase - Client High Product pom groupid apache.hbase Low Product pom parent-artifactid hbase Medium Product Manifest specification-title HBase - Client Medium Product pom parent-groupid org.apache.hbase Low Version pom version 0.98.8-hadoop2 Highest Version Manifest Implementation-Version 0.98.8-hadoop2 High
Related Dependencies hbase-common-0.98.8-hadoop2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/hbase-common-0.98.8-hadoop2.jar MD5: d6430028bffc063449e9d855f92680a2 SHA1: ce521d00a7ce8ba71fa9ee8b564f392b685328ec SHA256: c0c991bb677e383b4167ea8f4cc082deedfca2dbd6bc88bc69d8f166d28cb3bf cpe: cpe:/a:apache:hbase:0.98.8 hbase-protocol-0.98.8-hadoop2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/hbase-protocol-0.98.8-hadoop2.jar MD5: 0046fef8a3d2d44d64f9611e8d57568a SHA1: f3581971f5401f0aeccf7e8c14499dfae16ff87a SHA256: f5effdfc862b236532e5cff531c23a93936d9085fd4360f8618567bce9160282 cpe: cpe:/a:apache:hbase:0.98.8 Published Vulnerabilities CVE-2015-1836 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-284 Improper Access Control
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic. Vulnerable Software & Versions: (show all )
htrace-core-2.04.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/htrace-core-2.04.jarMD5: bb871c7a6541ca3dc726e765a5301a54SHA1: 80f30d70dfa29c78b1db994b6d9124ae271e0249SHA256: f92be09ba209655cf7a81db9803004b808e068c7ee3e6ef4fad1c94cc98bb709
Evidence Type Source Name Value Confidence Vendor file name htrace-core High Vendor pom parent-artifactid htrace Low Vendor pom name htrace-core High Vendor jar package name cloudera Low Vendor pom groupid cloudera.htrace Highest Vendor pom artifactid htrace-core Low Vendor pom parent-groupid org.cloudera.htrace Medium Vendor pom url cloudera/htrace Highest Vendor jar package name htrace Low Product file name htrace-core High Product pom parent-groupid org.cloudera.htrace Low Product pom parent-artifactid htrace Medium Product pom name htrace-core High Product pom url cloudera/htrace High Product pom artifactid htrace-core Highest Product pom groupid cloudera.htrace Low Product jar package name htrace Low Version file version 2.04 Highest Version pom version 2.04 Highest
maven: org.cloudera.htrace:htrace-core:2.04 Confidence :High indexer-hbase.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/indexer-hbase.jarMD5: 3e2b47307357036cbc20d9d5d2a6d4f9SHA1: e107416c12047f9ac094149128a13521cd5f1626SHA256: b4434bc7bcf1dd84565e98eee1be92a3c126d1fd5c487e081da1933045067574
Evidence Type Source Name Value Confidence Vendor file name indexer-hbase High Vendor jar package name nutch Low Vendor jar package name indexwriter Low Vendor jar package name apache Low Product jar package name hbase Low Product file name indexer-hbase High Product jar package name nutch Low Product jar package name indexwriter Low
cpe: cpe:/a:apache:hbase:- Confidence :Low suppress jackson-core-asl-1.8.8.jarDescription:
Jackson is a high-performance JSON processor (parser, generator)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/jackson-core-asl-1.8.8.jar
MD5: a65a9709da8186ed9a1c739355414460
SHA1: dd2e90bb710ea3bc4610e24299d6a4c8dac5049b
SHA256: 96b394f135bf396679681aca6716d8bea14a97cf306d3738a053c43d07a1308b
Evidence Type Source Name Value Confidence Vendor file name jackson-core-asl High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor pom url http://jackson.codehaus.org Highest Vendor pom groupid codehaus.jackson Highest Vendor jar package name codehaus Low Vendor central groupid org.codehaus.jackson Highest Vendor pom organization url http://fasterxml.com Medium Vendor jar package name jackson Low Vendor pom organization name FasterXML High Vendor pom name Jackson High Vendor pom artifactid jackson-core-asl Low Vendor Manifest bundle-symbolicname jackson-core-asl Medium Vendor pom description Jackson is a high-performance JSON processor (parser, generator)
Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor Manifest specification-vendor http://www.ietf.org/rfc/rfc4627.txt Low Product file name jackson-core-asl High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product pom organization name FasterXML Low Product pom artifactid jackson-core-asl Highest Product Manifest Bundle-Name Jackson JSON processor Medium Product Manifest specification-title JSON - JavaScript Object Notation Medium Product pom groupid codehaus.jackson Low Product pom organization url http://fasterxml.com Low Product jar package name jackson Low Product pom name Jackson High Product pom url http://jackson.codehaus.org Medium Product Manifest bundle-symbolicname jackson-core-asl Medium Product Manifest Implementation-Title Jackson JSON processor High Product pom description Jackson is a high-performance JSON processor (parser, generator)
Medium Product central artifactid jackson-core-asl Highest Version pom version 1.8.8 Highest Version Manifest Implementation-Version 1.8.8 High Version central version 1.8.8 Highest Version file version 1.8.8 Highest
Related Dependencies jackson-mapper-asl-1.8.8.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/jackson-mapper-asl-1.8.8.jar MD5: 3e6795b01c7b5fa40eeae9fe4eb7b523 SHA1: 01bb32d9d2527c083a56e234acca49a48d3c65c8 SHA256: 56436abd3e06c45e496b8604fd3f3b0f22451a9b5de8433b6f8b416e7a14a048 maven: org.codehaus.jackson:jackson-mapper-asl:1.8.8 ✓ jcodings-1.0.8.jarDescription:
Byte based encoding support library for java
License:
MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/jcodings-1.0.8.jar
MD5: 002720c095efbad852e2d3c896565c4b
SHA1: 33fa45fd853c277b888e3d5a2e6a4604b7c11e2c
SHA256: 897793ca4a37583082a6ceeaca4ff83874da6448f651a914d1bbc7fd51d75442
Evidence Type Source Name Value Confidence Vendor pom artifactid jcodings Low Vendor pom name JCodings High Vendor pom description
Byte based encoding support library for java
Medium Vendor pom groupid jruby.jcodings Highest Vendor file name jcodings High Product pom groupid jruby.jcodings Low Product pom name JCodings High Product pom description
Byte based encoding support library for java
Medium Product file name jcodings High Product Manifest Implementation-Title JCodings (Byte based encoding support library for java) High Product pom artifactid jcodings Highest Version pom version 1.0.8 Highest Version file version 1.0.8 Highest
maven: org.jruby.jcodings:jcodings:1.0.8 Confidence :High joni-2.1.2.jarDescription:
Java port of Oniguruma: http://www.geocities.jp/kosako3/oniguruma
that uses byte arrays directly instead of java Strings and chars
License:
MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/joni-2.1.2.jar
MD5: 56152e96fb4811f5017a65b3314d1acb
SHA1: 1f08024ec70e86a716188b7d069b0c2d2f183e14
SHA256: d6f254480ea62cd1587c4bdd23736e4d3ad3773ae445fc5f5c3c8cfbe82ffa2a
Evidence Type Source Name Value Confidence Vendor pom name Joni High Vendor pom groupid jruby.joni Highest Vendor file name joni High Vendor pom artifactid joni Low Vendor pom description Java port of Oniguruma: http://www.geocities.jp/kosako3/oniguruma that uses byte arrays directly instead of java Strings and chars Low Product pom groupid jruby.joni Low Product pom artifactid joni Highest Product pom name Joni High Product Manifest Implementation-Title Joni (java port of Oniguruma) High Product file name joni High Product pom description Java port of Oniguruma: http://www.geocities.jp/kosako3/oniguruma that uses byte arrays directly instead of java Strings and chars Low Version file version 2.1.2 Highest Version pom version 2.1.2 Highest
cpe: cpe:/a:oniguruma_project:oniguruma:2.1.2 Confidence :Low suppress maven: org.jruby.joni:joni:2.1.2 Confidence :High netty-3.6.6.Final.jarDescription:
The Netty project is an effort to provide an asynchronous event-driven
network application framework and tools for rapid development of
maintainable high performance and high scalability protocol servers and
clients. In other words, Netty is a NIO client server framework which
enables quick and easy development of network applications such as protocol
servers and clients. It greatly simplifies and streamlines network
programming such as TCP and UDP socket server.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/netty-3.6.6.Final.jar
MD5: e7e3ab10dcbe07972afe68cfa1bfcabe
SHA1: e4e40738ce9bee0a92389cb739c94d7839778647
SHA256: 8d9373e00c4e485cc9613c89fd7c05066c8be65adde8526474916a1bb1cc1797
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://netty.io/ Low Vendor pom groupid io.netty Highest Vendor pom organization name The Netty Project High Vendor pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Vendor Manifest bundle-symbolicname org.jboss.netty Medium Vendor pom name The Netty Project High Vendor pom organization url http://netty.io/ Medium Vendor pom artifactid netty Low Vendor file name netty High Vendor pom url http://netty.io/ Highest Vendor manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product pom url http://netty.io/ Medium Product pom organization url http://netty.io/ Low Product pom organization name The Netty Project Low Product pom description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Product pom name The Netty Project High Product pom artifactid netty Highest Product file name netty High Product pom groupid io.netty Low Product Manifest bundle-docurl http://netty.io/ Low Product Manifest Bundle-Name The Netty Project Medium Product Manifest bundle-symbolicname org.jboss.netty Medium Product manifest Bundle-Description The Netty project is an effort to provide an asynchronous event-driven network application framework and tools for rapid development of maintainable high performance and high scalability protocol servers and clients. In other words, Netty is a NIO client server framework which enables quick and easy development of network applications ... Low Version pom version 3.6.6.Final Highest Version file version 3.6.6 Highest
Published Vulnerabilities CVE-2014-0193 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames. Vulnerable Software & Versions: (show all )
CVE-2014-3488 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message. Vulnerable Software & Versions: (show all )
CVE-2015-2156 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-20 Improper Input Validation
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters. Vulnerable Software & Versions: (show all )
slf4j-api-1.6.4.jarDescription:
The slf4j API File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/slf4j-api-1.6.4.jarMD5: 75e1a2a3b84c59bf9d4f42de57a533b1SHA1: 2396d74b12b905f780ed7966738bb78438e8371aSHA256: 367b909030f714ee1176ab096b681e06348f03385e98d1bce0ed801b5452357e
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor pom artifactid slf4j-api Low Vendor pom description The slf4j API Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Vendor pom url http://www.slf4j.org Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor manifest Bundle-Description The slf4j API Medium Vendor pom name SLF4J API Module High Vendor pom groupid slf4j Highest Vendor pom parent-groupid org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Product pom groupid slf4j Low Product pom description The slf4j API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Product pom parent-groupid org.slf4j Low Product pom artifactid slf4j-api Highest Product manifest Bundle-Description The slf4j API Medium Product pom name SLF4J API Module High Product pom url http://www.slf4j.org Medium Product file name slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Bundle-Name slf4j-api Medium Product Manifest Implementation-Title slf4j-api High Product pom parent-artifactid slf4j-parent Medium Version pom version 1.6.4 Highest Version Manifest Implementation-Version 1.6.4 High Version file version 1.6.4 Highest
maven: org.slf4j:slf4j-api:1.6.4 Confidence :Highcpe: cpe:/a:slf4j:slf4j:1.6.4 Confidence :Low suppress zookeeper-3.4.6.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-hbase/zookeeper-3.4.6.jar
MD5: 7d01d317c717268725896cfb81b18152
SHA1: 01b2502e29da1ebaade2357cd1de35a855fa3755
SHA256: 8a375a1ef98cbc0e1f6e9dfd0d96d914b74d37ad00b4bf81beb77fa8f34d33ae
Evidence Type Source Name Value Confidence Vendor pom groupid apache.zookeeper Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid zookeeper Low Vendor Manifest built-at 02/23/2014 17:18 GMT Low Vendor Manifest bundle-docurl http://hadoop.apache.org/zookeeper Low Vendor file name zookeeper High Vendor jar package name zookeeper Low Vendor central groupid org.apache.zookeeper Highest Vendor Manifest bundle-symbolicname org.apache.hadoop.zookeeper Medium Vendor Manifest built-on fpj-Virtual-Machine Low Vendor jar package name apache Low Product central artifactid zookeeper Highest Product Manifest built-at 02/23/2014 17:18 GMT Low Product Manifest bundle-docurl http://hadoop.apache.org/zookeeper Low Product file name zookeeper High Product jar package name zookeeper Low Product Manifest Implementation-Title org.apache.zookeeper High Product Manifest Bundle-Name ZooKeeper Bundle Medium Product pom groupid apache.zookeeper Low Product pom artifactid zookeeper Highest Product Manifest bundle-symbolicname org.apache.hadoop.zookeeper Medium Product Manifest built-on fpj-Virtual-Machine Low Version central version 3.4.6 Highest Version pom version 3.4.6 Highest Version file version 3.4.6 Highest
Published Vulnerabilities CVE-2014-0085 suppress
Severity:Low CVSS Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-255 Credentials Management
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log. Vulnerable Software & Versions: (show all )
CVE-2016-5017 suppress
Severity:Medium CVSS Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string. Vulnerable Software & Versions: (show all )
CVE-2017-5637 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later. Vulnerable Software & Versions: (show all )
CVE-2018-8012 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N) CWE: CWE-285 Improper Authorization
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader. Vulnerable Software & Versions: (show all )
commons-io-2.1.jarDescription:
The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/commons-io-2.1.jar
MD5: 4854c2344aa182ad4f37976e83348aa0
SHA1: fd51f906669f49a4ffd06650666c3b8147a6106e
SHA256: 88dff860b1983f9640979196a4dfd9ae6cddd4a88119c81ce3a61de2f28cc927
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build trunk@r1178270; 2011-10-03 17:30:43-0400 Low Vendor pom groupid commons-io Highest Vendor pom name Commons IO High Vendor pom description The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes. Low Vendor pom artifactid commons-io Low Vendor pom url http://commons.apache.org/io/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor file name commons-io High Vendor manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes. Low Product Manifest implementation-build trunk@r1178270; 2011-10-03 17:30:43-0400 Low Product pom name Commons IO High Product pom description The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes. Low Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/io/ Medium Product Manifest bundle-docurl http://commons.apache.org/io/ Low Product Manifest Bundle-Name Commons IO Medium Product pom parent-groupid org.apache.commons Low Product Manifest specification-title Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.io Medium Product file name commons-io High Product Manifest Implementation-Title Commons IO High Product pom groupid commons-io Low Product pom artifactid commons-io Highest Product manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes. Low Version file version 2.1 Highest Version Manifest Implementation-Version 2.1 High Version pom version 2.1 Highest
maven: commons-io:commons-io:2.1 Confidence :High indexer-solr.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/indexer-solr.jarMD5: 4606795c34a426404abbc380186dbb4bSHA1: 81728bfcc1226225d75300c0c8e6f01f474e6620SHA256: 8a8adb5251fc4bbdd56f78befd42228328bf454ca752c5d515a50e4d67f3789d
Evidence Type Source Name Value Confidence Vendor file name indexer-solr High Vendor jar package name nutch Low Vendor jar package name indexwriter Low Vendor jar package name apache Low Product file name indexer-solr High Product jar package name nutch Low Product jar package name solr Low Product jar package name indexwriter Low
cpe: cpe:/a:apache:solr:- Confidence :Low suppress Published Vulnerabilities CVE-2012-6612 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407. Vulnerable Software & Versions: (show all )
CVE-2013-6397 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries. Vulnerable Software & Versions: (show all )
CVE-2013-6407 suppress
Severity:Medium CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. Vulnerable Software & Versions: (show all )
CVE-2013-6408 suppress
Severity:Medium CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407. Vulnerable Software & Versions: (show all )
CVE-2015-8795 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js. Vulnerable Software & Versions:
CVE-2015-8796 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL. Vulnerable Software & Versions:
CVE-2015-8797 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI. Vulnerable Software & Versions:
CVE-2017-3163 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access. Vulnerable Software & Versions: (show all )
slf4j-api-1.6.6.jarDescription:
The slf4j API File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/indexer-solr/slf4j-api-1.6.6.jarMD5: 17ba6715f5defd50b2e781201f57b408SHA1: ce53b0a0e2cfbb27e8a59d38f79a18a5c6a8d2b0SHA256: 43456b2ee31529a9c512d581e53e285c65feddec204a2c146945e032b07810ba
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor pom artifactid slf4j-api Low Vendor pom description The slf4j API Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Vendor pom url http://www.slf4j.org Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor manifest Bundle-Description The slf4j API Medium Vendor pom name SLF4J API Module High Vendor pom groupid slf4j Highest Vendor pom parent-groupid org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Product pom groupid slf4j Low Product pom description The slf4j API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.3 Low Product pom parent-groupid org.slf4j Low Product pom artifactid slf4j-api Highest Product manifest Bundle-Description The slf4j API Medium Product pom name SLF4J API Module High Product pom url http://www.slf4j.org Medium Product file name slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Bundle-Name slf4j-api Medium Product Manifest Implementation-Title slf4j-api High Product pom parent-artifactid slf4j-parent Medium Version pom version 1.6.6 Highest Version file version 1.6.6 Highest Version Manifest Implementation-Version 1.6.6 High
maven: org.slf4j:slf4j-api:1.6.6 Confidence :Highcpe: cpe:/a:slf4j:slf4j:1.6.6 Confidence :Low suppress jsoup-1.10.2.jarDescription:
jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-like methods. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers do. License:
The MIT License: https://jsoup.org/license File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/jsoup-extractor/jsoup-1.10.2.jar
MD5: 36145fee38e79b81035787f1be296a52
SHA1: 33ee82e324f4b1e40167f3dc5e01234a1c5cab61
SHA256: 6ebe6abd7775c10a49407ae22db45c840cd2cdaf715866a5b0b5af70941c3f4a
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl https://jsoup.org/ Low Vendor pom organization name Jonathan Hedley High Vendor pom groupid jsoup Highest Vendor pom url https://jsoup.org/ Highest Vendor pom name jsoup Java HTML Parser High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor pom description jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-... Low Vendor file name jsoup High Vendor pom organization url http://jonathanhedley.com/ Medium Vendor manifest Bundle-Description jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-... Low Vendor Manifest bundle-symbolicname org.jsoup Medium Vendor pom artifactid jsoup Low Product Manifest bundle-docurl https://jsoup.org/ Low Product Manifest Bundle-Name jsoup Java HTML Parser Medium Product pom name jsoup Java HTML Parser High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product pom groupid jsoup Low Product pom description jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-... Low Product pom organization url http://jonathanhedley.com/ Low Product file name jsoup High Product pom artifactid jsoup Highest Product pom organization name Jonathan Hedley Low Product manifest Bundle-Description jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-... Low Product Manifest bundle-symbolicname org.jsoup Medium Product pom url https://jsoup.org/ Medium Version file version 1.10.2 Highest Version pom version 1.10.2 Highest
cpe: cpe:/a:jsoup:jsoup:1.10.2 Confidence :Low suppress maven: org.jsoup:jsoup:1.10.2 Confidence :High jsoup-extractor.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/jsoup-extractor/jsoup-extractor.jarMD5: 581b50456564cdea2b32ae0fd909b165SHA1: d92fe7bbd33866544f42746195415dbce0b25eccSHA256: 530e01b145a344c51adf704b36833693e4c1c52833a06ab5bb0d57d1c8a64e0d
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor jar package name core Low Vendor jar package name apache Low Vendor file name jsoup-extractor High Product jar package name nutch Low Product jar package name core Low Product file name jsoup-extractor High Product jar package name jsoup Low
cpe: cpe:/a:jsoup:jsoup:- Confidence :Low suppress Published Vulnerabilities CVE-2015-6748 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. Vulnerable Software & Versions:
language-identifier.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/language-identifier/language-identifier.jarMD5: 3a0409effc14dfebafaea58919de1126SHA1: bcbbc2df39abfa751455fd23e2cf4c51da07b5bfSHA256: ebdead330badccc890a83ba6d172abb3ba7b8e562031d80c5975eca24f442f8f
Evidence Type Source Name Value Confidence Vendor file name language-identifier High Vendor jar package name nutch Low Vendor jar package name apache Low Vendor jar package name analysis Low Product file name language-identifier High Product jar package name lang Low Product jar package name nutch Low Product jar package name analysis Low
lib-http.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-http/lib-http.jarMD5: b51154c27f3f7bd3c1de94179e10fa9fSHA1: be359b59bb77a6eaa65402a681dfdf5781a3661eSHA256: 4a57cab95d11b39640034f93c8d36ae06a1d1ad7727281d758e8fd0fa2bf5909
Evidence Type Source Name Value Confidence Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor file name lib-http High Vendor jar package name apache Low Product jar package name http Low Product jar package name protocol Low Product jar package name nutch Low Product file name lib-http High
nekohtml-1.9.19.jarDescription:
An HTML parser and tag balancer. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-nekohtml/nekohtml-1.9.19.jar
MD5: 62aa02563ef8a3e0aaafe0f9cefa4d38
SHA1: 8a49406347d345bade1e6152e05e5f4dcbf7def5
SHA256: c60dd5e2e6fe77c715bb12b82358aaf94ab7687b7565d197a98e79c128517bc3
Evidence Type Source Name Value Confidence Vendor file name nekohtml High Vendor central groupid net.sourceforge.nekohtml Highest Vendor manifest: org/cyberneko/html/ Implementation-Vendor Andy Clark, Marc Guillemot Medium Vendor pom name Neko HTML High Vendor jar package name cyberneko Low Vendor pom artifactid nekohtml Low Vendor pom url http://nekohtml.sourceforge.net/ Highest Vendor jar package name html Low Vendor pom description An HTML parser and tag balancer. Medium Vendor pom groupid net.sourceforge.nekohtml Highest Product file name nekohtml High Product pom groupid net.sourceforge.nekohtml Low Product pom url http://nekohtml.sourceforge.net/ Medium Product manifest: org/cyberneko/html/ Specification-Title Hyper-Text Markup Language (HTML) Medium Product pom artifactid nekohtml Highest Product pom name Neko HTML High Product jar package name html Low Product pom description An HTML parser and tag balancer. Medium Product central artifactid nekohtml Highest Product manifest: org/cyberneko/html/ Implementation-Title CyberNeko HTML Parser Medium Version file version 1.9.19 Highest Version central version 1.9.19 Highest Version pom version 1.9.19 Highest
lib-regex-filter.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-regex-filter/lib-regex-filter.jarMD5: 77b10d1a3032fd3799bbf51224191788SHA1: 75b2c4b7b2e8cb10c6065c20454910a5535b9b81SHA256: a887aec760e29dc59ac4a2bf54a8467396d6bcc9e957481d0cf35ee17df87ef6
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name lib-regex-filter High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product file name lib-regex-filter High Product jar package name api Low
jaxen-1.1.1.jarDescription:
Jaxen is a universal Java XPath engine. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-xml/jaxen-1.1.1.jarMD5: 261d1aa59865842ecc32b3848b0c6538SHA1: 9f5d3c5974dbe5cf69c2c2ec7d8a4eb6e0fce7f9SHA256: 160958f42f60fff817d6c0b1b02fd9284b3f0fcb46e61d38866f65b7af4d329d
Evidence Type Source Name Value Confidence Vendor pom organization name Codehaus High Vendor pom organization url http://codehaus.org Medium Vendor file name jaxen High Vendor central groupid jaxen Highest Vendor pom url http://jaxen.codehaus.org/ Highest Vendor pom groupid jaxen Highest Vendor Manifest specification-vendor Codehaus Low Vendor Manifest extension-name jaxen Medium Vendor pom name jaxen High Vendor pom description Jaxen is a universal Java XPath engine. Medium Vendor Manifest Implementation-Vendor Codehaus High Vendor pom artifactid jaxen Low Vendor jar package name jaxen Low Product pom groupid jaxen Low Product central artifactid jaxen Highest Product Manifest specification-title Universal Java XPath Engine Medium Product pom artifactid jaxen Highest Product Manifest Implementation-Title org.jaxen High Product file name jaxen High Product pom organization url http://codehaus.org Low Product Manifest extension-name jaxen Medium Product pom name jaxen High Product pom description Jaxen is a universal Java XPath engine. Medium Product pom url http://jaxen.codehaus.org/ Medium Product pom organization name Codehaus Low Version central version 1.1.1 Highest Version pom version 1.1.1 Highest Version Manifest Implementation-Version 1.1.1 High Version file version 1.1.1 Highest
lib-xml.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/lib-xml/lib-xml.jarMD5: 967eb986592109dffe4ff17786ef2869SHA1: 0202dc22cce86640920486ea2605c0e16e1cfe44SHA256: 346e9eab58adfe9b456dcc4c3ac853f5d86bfee8e66798107cad430303184097
Evidence Type Source Name Value Confidence Vendor file name lib-xml High Product file name lib-xml High
microformats-reltag.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/microformats-reltag/microformats-reltag.jarMD5: 1f76deab4516dbe2a401009c6fd81817SHA1: 58bdd6a819ae063423a5387cd2fd745060506681SHA256: 564de25c57ec999579e8c4079a8c66e6375e878452fe09286519806fd5b43b69
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor file name microformats-reltag High Vendor jar package name microformats Low Vendor jar package name apache Low Product jar package name nutch Low Product jar package name reltag Low Product file name microformats-reltag High Product jar package name microformats Low
nutch-extensionpoints.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/nutch-extensionpoints/nutch-extensionpoints.jarMD5: 5491c59c46c19fe3741a4f14083a4f32SHA1: 7f054ea0494f4d2b719b528a88151f3df4a9e66eSHA256: 582299a71ab2edb2eae2a7ef2c5e0520bceac9b3bff98107a2a70e6a811f9332
Evidence Type Source Name Value Confidence Vendor file name nutch-extensionpoints High Product file name nutch-extensionpoints High
parse-html.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-html/parse-html.jarMD5: 5439e0c7825afa1b65eaa93a7b4a80d3SHA1: 7363a8bc9d939e057e004c7a74186b7a87562ceaSHA256: 9ca041e1e6cfb172a02fcddb699ef325a31dee87f0f44ccec33797e3fd03b1fc
Evidence Type Source Name Value Confidence Vendor file name parse-html High Vendor jar package name nutch Low Vendor jar package name parse Low Vendor jar package name apache Low Product file name parse-html High Product jar package name nutch Low Product jar package name parse Low Product jar package name html Low
tagsoup-1.2.jarDescription:
TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-html/tagsoup-1.2.jar
MD5: b11b44149277505c8eea5fc60e9c81d5
SHA1: 639fd364750d7363c85797dc944b4a80f78fa684
SHA256: 10d12b82c9a58a7842765a1152a56fbbd11eac9122a621f5a86a087503297266
Evidence Type Source Name Value Confidence Vendor pom artifactid tagsoup Low Vendor pom url http://home.ccil.org/~cowan/XML/tagsoup/ Highest Vendor file name tagsoup High Vendor jar package name tagsoup Low Vendor central groupid org.ccil.cowan.tagsoup Highest Vendor pom groupid ccil.cowan.tagsoup Highest Vendor pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low Vendor jar package name ccil Low Vendor jar package name cowan Low Vendor pom name TagSoup High Product central artifactid tagsoup Highest Product pom artifactid tagsoup Highest Product file name tagsoup High Product jar package name tagsoup Low Product pom groupid ccil.cowan.tagsoup Low Product pom url http://home.ccil.org/~cowan/XML/tagsoup/ Medium Product pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low Product jar package name cowan Low Product pom name TagSoup High Version central version 1.2 Highest Version file version 1.2 Highest Version pom version 1.2 Highest
parse-js.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-js/parse-js.jarMD5: f0b046ce4e9408a2a7a65d77558796d6SHA1: 443a9d25b5f85299b791e4b9e107f3a8711b96feSHA256: c34225b58abd61069a9015984feac662ee8877d8d89e1ae4e98df49e702a712d
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor file name parse-js High Vendor jar package name parse Low Vendor jar package name apache Low Product jar package name nutch Low Product file name parse-js High Product jar package name parse Low Product jar package name js Low
parse-metatags.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-metatags/parse-metatags.jarMD5: 75abb75797e656d87869d16f6df7e425SHA1: 410d497f0ec82be2f0b8a639345b016a17755685SHA256: 80393a3fb00ad82e2dc44b3ccf9da446d550f875e3509ae59fc37609c1a09d42
Evidence Type Source Name Value Confidence Vendor file name parse-metatags High Vendor jar package name nutch Low Vendor jar package name parse Low Vendor jar package name apache Low Product file name parse-metatags High Product jar package name nutch Low Product jar package name metatags Low Product jar package name parse Low
apache-mime4j-core-0.7.2.jarDescription:
Java stream based MIME message parser License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/apache-mime4j-core-0.7.2.jar
MD5: 88f799546eca803c53eee01a4ce5edcd
SHA1: a81264fe0265ebe8fd1d8128aad06dc320de6eef
SHA256: 4d7434c68f94b81a253c12f28e6bbb4d6239c361d6086a46e22e594bb43ac660
Evidence Type Source Name Value Confidence Vendor file name apache-mime4j-core High Vendor manifest Bundle-Description Java stream based MIME message parser Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.james Highest Vendor pom artifactid apache-mime4j-core Low Vendor pom parent-artifactid apache-mime4j-project Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium Vendor pom name Apache JAMES Mime4j (Core) High Vendor pom parent-groupid org.apache.james Medium Product file name apache-mime4j-core High Product manifest Bundle-Description Java stream based MIME message parser Medium Product Manifest specification-title Apache Mime4j Medium Product pom artifactid apache-mime4j-core Highest Product Manifest Implementation-Title Apache Mime4j High Product pom parent-artifactid apache-mime4j-project Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product Manifest Bundle-Name Apache JAMES Mime4j (Core) Medium Product Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium Product pom parent-groupid org.apache.james Low Product pom name Apache JAMES Mime4j (Core) High Product pom groupid apache.james Low Version file version 0.7.2 Highest Version Manifest Implementation-Version 0.7.2 High Version pom version 0.7.2 Highest
Related Dependencies apache-mime4j-dom-0.7.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/apache-mime4j-dom-0.7.2.jar MD5: dedc747b5c367fbd7f8a7235d1d7cbee SHA1: 1c289aa264548a0a1f1b43685a9cb2ab23f67287 SHA256: 7e6b06ee164a1c21b7e477249ea0b74a18fddce44764e5764085f58dd8c34633 maven: org.apache.james:apache-mime4j-core:0.7.2 Confidence :Highcpe: cpe:/a:apache:james:0.7.2 Confidence :Low suppress asm-debug-all-4.1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/asm-debug-all-4.1.jarMD5: 6c3a8842f484dd3d620002b361e3610eSHA1: dd6ba5c392d4102458494e29f54f70ac534ec2a2SHA256: c0f582e1eb589315a62939197116b24412c5f4386c5b78aee7b017a4532312ba
Evidence Type Source Name Value Confidence Vendor pom groupid ow2.asm Highest Vendor pom parent-artifactid asm-parent Low Vendor jar package name objectweb Low Vendor pom artifactid asm-debug-all Low Vendor central groupid org.ow2.asm Highest Vendor pom name ASM Debug All High Vendor Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-docurl http://asm.objectweb.org Low Vendor Manifest Implementation-Vendor France Telecom R&D High Vendor jar package name asm Low Vendor pom parent-groupid org.ow2.asm Medium Vendor file name asm-debug-all High Product pom name ASM Debug All High Product Manifest Implementation-Title ASM all classes with debug info High Product Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest Bundle-Name ASM all classes with debug info Medium Product central artifactid asm-debug-all Highest Product pom groupid ow2.asm Low Product Manifest bundle-docurl http://asm.objectweb.org Low Product jar package name asm Low Product pom parent-artifactid asm-parent Medium Product pom parent-groupid org.ow2.asm Low Product pom artifactid asm-debug-all Highest Product file name asm-debug-all High Version central version 4.1 Highest Version file version 4.1 Highest Version pom version 4.1 Highest Version Manifest Implementation-Version 4.1 High
aspectjrt-1.8.0.jarDescription:
The runtime needed to execute a program using AspectJ License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/aspectjrt-1.8.0.jar
MD5: 038daf8a4723e6f34cdd2cad7e023e4f
SHA1: 302d0fe0abba26bbf5f31c3cd5337b3125c744e3
SHA256: 946978e12c8431fdbd046633d5e9675329c2ea0ab92cad3402f1fe1f8478950d
Evidence Type Source Name Value Confidence Vendor pom groupid aspectj Highest Vendor jar package name aspectj Low Vendor jar package name lang Low Vendor central groupid org.aspectj Highest Vendor pom artifactid aspectjrt Low Vendor manifest: org/aspectj/lang/ Implementation-Vendor aspectj.org Medium Vendor pom name AspectJ runtime High Vendor pom url http://www.aspectj.org Highest Vendor file name aspectjrt High Vendor pom description The runtime needed to execute a program using AspectJ Medium Product jar package name reflect Low Product manifest: org/aspectj/lang/ Implementation-Title org.aspectj.tools Medium Product jar package name lang Low Product pom groupid aspectj Low Product pom name AspectJ runtime High Product file name aspectjrt High Product central artifactid aspectjrt Highest Product manifest: org/aspectj/lang/ Specification-Title AspectJ Runtime Classes Medium Product pom description The runtime needed to execute a program using AspectJ Medium Product pom artifactid aspectjrt Highest Product pom url http://www.aspectj.org Medium Version central version 1.8.0 Highest Version file version 1.8.0 Highest Version pom version 1.8.0 Highest
bcmail-jdk15on-1.52.jarDescription:
The Bouncy Castle Java S/MIME APIs for handling S/MIME protocols. This jar contains S/MIME APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. The JavaMail API and the Java activation framework will also be needed. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/bcmail-jdk15on-1.52.jar
MD5: 858597d61d2398a895c612f9df913dae
SHA1: 4995a870400e1554d1c7ed2afcb5d198fae12db9
SHA256: 343554ee6432655cab672a0e95bcb1ec929ebd9fe8839fce95d5a91aafbc4e6c
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest application-name Bouncy Castle S/MIME API Medium Vendor Manifest permissions all-permissions Low Vendor pom groupid bouncycastle Highest Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Vendor jar package name bouncycastle Low Vendor jar package name mail Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest extension-name org.bouncycastle.bcmail Medium Vendor pom url http://www.bouncycastle.org/java.html Highest Vendor Manifest bundle-symbolicname bcmail Medium Vendor jar package name smime Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Vendor Manifest caller-allowable-codebase * Low Vendor file name bcmail-jdk15on High Vendor pom name Bouncy Castle S/MIME API High Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest codebase * Low Vendor central groupid org.bouncycastle Highest Vendor pom artifactid bcmail-jdk15on Low Vendor pom description The Bouncy Castle Java S/MIME APIs for handling S/MIME protocols. This jar contains S/MIME APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider ... Low Product pom url http://www.bouncycastle.org/java.html Medium Product Manifest application-name Bouncy Castle S/MIME API Medium Product central artifactid bcmail-jdk15on Highest Product Manifest permissions all-permissions Low Product Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Product jar package name mail Low Product pom artifactid bcmail-jdk15on Highest Product Manifest extension-name org.bouncycastle.bcmail Medium Product Manifest bundle-symbolicname bcmail Medium Product jar package name smime Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Product Manifest caller-allowable-codebase * Low Product pom groupid bouncycastle Low Product file name bcmail-jdk15on High Product Manifest Bundle-Name bcmail Medium Product pom name Bouncy Castle S/MIME API High Product Manifest application-library-allowable-codebase * Low Product Manifest codebase * Low Product pom description The Bouncy Castle Java S/MIME APIs for handling S/MIME protocols. This jar contains S/MIME APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider ... Low Version file version 1.52 Highest Version central version 1.52 Highest Version pom version 1.52 Highest Version Manifest Implementation-Version 1.52.0.0 High
bcpkix-jdk15on-1.52.jarDescription:
The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/bcpkix-jdk15on-1.52.jar
MD5: 72104264eec0fd299cca4b07eada5d5b
SHA1: b8ffac2bbc6626f86909589c8cc63637cc936504
SHA256: 8e8e9ac258051ec8d6f7f1128d0ddec800ed87b14e7a55023d0f2850b8049615
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor pom description The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider ... Low Vendor Manifest permissions all-permissions Low Vendor Manifest bundle-symbolicname bcpkix Medium Vendor pom groupid bouncycastle Highest Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Vendor Manifest application-name Bouncy Castle PKIX API Medium Vendor jar package name bouncycastle Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest extension-name org.bouncycastle.bcpkix Medium Vendor pom url http://www.bouncycastle.org/java.html Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Vendor Manifest caller-allowable-codebase * Low Vendor pom artifactid bcpkix-jdk15on Low Vendor pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Vendor file name bcpkix-jdk15on High Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest codebase * Low Vendor central groupid org.bouncycastle Highest Product pom description The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 to JDK 1.8. The APIs can be used in conjunction with a JCE/JCA provider ... Low Product pom url http://www.bouncycastle.org/java.html Medium Product Manifest permissions all-permissions Low Product Manifest bundle-symbolicname bcpkix Medium Product Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Product pom artifactid bcpkix-jdk15on Highest Product Manifest application-name Bouncy Castle PKIX API Medium Product Manifest extension-name org.bouncycastle.bcpkix Medium Product central artifactid bcpkix-jdk15on Highest Product Manifest Bundle-Name bcpkix Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Product Manifest caller-allowable-codebase * Low Product pom groupid bouncycastle Low Product pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Product file name bcpkix-jdk15on High Product Manifest application-library-allowable-codebase * Low Product Manifest codebase * Low Version file version 1.52 Highest Version central version 1.52 Highest Version pom version 1.52 Highest Version Manifest Implementation-Version 1.52.0.0 High
bcprov-jdk15on-1.52.jarDescription:
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 to JDK 1.8. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/bcprov-jdk15on-1.52.jar
MD5: 873ac611cb0d7160c0a3d30eee964454
SHA1: 88a941faf9819d371e3174b5ed56a3f3f7d73269
SHA256: 0dc4d181e4d347893c2ddbd2e6cd5d7287fc651c03648fa64b2341c7366b1773
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest permissions all-permissions Low Vendor pom groupid bouncycastle Highest Vendor pom name Bouncy Castle Provider High Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Vendor file name bcprov-jdk15on High Vendor Manifest extension-name org.bouncycastle.bcprovider Medium Vendor jar package name bouncycastle Low Vendor pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 to JDK 1.8. Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest application-name Bouncy Castle Provider Medium Vendor pom url http://www.bouncycastle.org/java.html Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Vendor Manifest caller-allowable-codebase * Low Vendor pom artifactid bcprov-jdk15on Low Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest codebase * Low Vendor central groupid org.bouncycastle Highest Vendor Manifest bundle-symbolicname bcprov Medium Product pom url http://www.bouncycastle.org/java.html Medium Product pom artifactid bcprov-jdk15on Highest Product Manifest permissions all-permissions Low Product central artifactid bcprov-jdk15on Highest Product pom name Bouncy Castle Provider High Product Manifest originally-created-by 24.75-b04 (Oracle Corporation) Low Product file name bcprov-jdk15on High Product Manifest Bundle-Name bcprov Medium Product Manifest extension-name org.bouncycastle.bcprovider Medium Product pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 to JDK 1.8. Low Product Manifest application-name Bouncy Castle Provider Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low Product Manifest caller-allowable-codebase * Low Product pom groupid bouncycastle Low Product Manifest application-library-allowable-codebase * Low Product Manifest codebase * Low Product Manifest bundle-symbolicname bcprov Medium Version file version 1.52 Highest Version Manifest Implementation-Version 1.52.0 High Version central version 1.52 Highest Version pom version 1.52 Highest
cpe: cpe:/a:bouncycastle:bouncy_castle_crypto_package:1.52 Confidence :Low suppress maven: org.bouncycastle:bcprov-jdk15on:1.52 ✓ Confidence :Highestcpe: cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.52 Confidence :Low suppress boilerpipe-1.1.0.jarDescription:
The boilerpipe library provides algorithms to detect and remove the surplus "clutter" (boilerplate, templates) around the main textual content of a web page.
The library already provides specific strategies for common tasks (for example: news article extraction) and may also be easily extended for individual problem settings.
Extracting content is very fast (milliseconds), just needs the input document (no global or site-level information required) and is usually quite accurate.
Boilerpipe is a Java library written by Christian Kohlschütter. It is released under the Apache License 2.0.
The algorithms used by the library are based on (and extending) some concepts of the paper "Boilerplate Detection using Shallow Text Features" by Christian Kohlschütter et al., presented at WSDM 2010 -- The Third ACM International Conference on Web Search and Data Mining New York City, NY USA.
License:
Apache License 2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/boilerpipe-1.1.0.jar
MD5: 0616568083786d0f49e2cb07a5d09fe4
SHA1: f62cb75ed52455a9e68d1d05b84c500673340eb2
SHA256: 088203df4326c4dcc42cec1253a2b41e03dc8904984eae744543b48e2cc63846
Evidence Type Source Name Value Confidence Vendor jar package name boilerpipe Low Vendor central groupid de.l3s.boilerpipe Highest Vendor jar package name de Low Vendor pom artifactid boilerpipe Low Vendor pom description The boilerpipe library provides algorithms to detect and remove the surplus "clutter" (boilerplate, templates) around the main textual content of a web page. The library already provides specific strategies for common tasks (for example: news article extraction) and may also be easily extended for individual problem settings. Extracting content is very fast (milliseconds), just needs the input document (no global or site-level information required) and is usually quite accurate. Boilerpipe is a Java library written by Christian Kohlschütter. It is released under the Apache License 2.0. The algorithms used by the library are based on (and extending) some concepts of the paper "Boilerplate Detection using Shallow Text Features" by Christian Kohlschütter et al., presented at WSDM 2010 -- The Third ACM International Conference on Web Search and Data Mining New York City, NY USA. Low Vendor pom groupid de.l3s.boilerpipe Highest Vendor pom url http://code.google.com/p/boilerpipe/ Highest Vendor jar package name l3s Low Vendor pom name Boilerpipe -- Boilerplate Removal and Fulltext Extraction from HTML pages High Vendor file name boilerpipe High Product jar package name boilerpipe Low Product pom artifactid boilerpipe Highest Product pom url http://code.google.com/p/boilerpipe/ Medium Product pom description The boilerpipe library provides algorithms to detect and remove the surplus "clutter" (boilerplate, templates) around the main textual content of a web page. The library already provides specific strategies for common tasks (for example: news article extraction) and may also be easily extended for individual problem settings. Extracting content is very fast (milliseconds), just needs the input document (no global or site-level information required) and is usually quite accurate. Boilerpipe is a Java library written by Christian Kohlschütter. It is released under the Apache License 2.0. The algorithms used by the library are based on (and extending) some concepts of the paper "Boilerplate Detection using Shallow Text Features" by Christian Kohlschütter et al., presented at WSDM 2010 -- The Third ACM International Conference on Web Search and Data Mining New York City, NY USA. Low Product central artifactid boilerpipe Highest Product jar package name l3s Low Product pom name Boilerpipe -- Boilerplate Removal and Fulltext Extraction from HTML pages High Product pom groupid de.l3s.boilerpipe Low Product file name boilerpipe High Version file version 1.1.0 Highest Version pom version 1.1.0 Highest Version central version 1.1.0 Highest
bzip2-0.9.1.jarDescription:
jbzip2 is a Java bzip2 compression/decompression library. It can be used as a replacement for the Apache CBZip2InputStream / CBZip2OutputStream classes. License:
MIT License (MIT): http://opensource.org/licenses/mit-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/bzip2-0.9.1.jar
MD5: ddd5eb3a035655cbbb536e9b86907a00
SHA1: 47ca95f71e3ccae756c4a24354d48069c58f475c
SHA256: 865a7a13dd33ef0388f675993adaf4c6f95632ba80d609d42e9d42e6343aae77
Evidence Type Source Name Value Confidence Vendor pom groupid itadaki Highest Vendor file name bzip2 High Vendor pom artifactid bzip2 Low Vendor jar package name itadaki Low Vendor pom name Itadaki jbzip2 High Vendor pom description jbzip2 is a Java bzip2 compression/decompression library. It can be used as a replacement for the Apache CBZip2InputStream / CBZip2OutputStream classes. Low Vendor pom url https://code.google.com/p/jbzip2/ Highest Vendor jar package name bzip2 Low Product file name bzip2 High Product pom artifactid bzip2 Highest Product pom name Itadaki jbzip2 High Product pom description jbzip2 is a Java bzip2 compression/decompression library. It can be used as a replacement for the Apache CBZip2InputStream / CBZip2OutputStream classes. Low Product jar package name bzip2 Low Product pom groupid itadaki Low Product pom url https://code.google.com/p/jbzip2/ Medium Version file version 0.9.1 Highest Version pom version 0.9.1 Highest
Published Vulnerabilities CVE-2005-1260 suppress
Severity:Medium CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). Vulnerable Software & Versions:
CVE-2010-0405 suppress
Severity:Medium CVSS Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P) CWE: CWE-189 Numeric Errors
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file. Vulnerable Software & Versions: (show all )
CVE-2011-4089 suppress
Severity:Medium CVSS Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-264 Permissions, Privileges, and Access Controls
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory. Vulnerable Software & Versions: (show all )
c3p0-0.9.1.1.jarDescription:
c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources,
including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension.
License:
GNU LESSER GENERAL PUBLIC LICENSE: http://www.gnu.org/licenses/lgpl.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/c3p0-0.9.1.1.jar
MD5: 640c58226e7bb6beacc8ac3f6bb533d1
SHA1: 302704f30c6e7abb7a0457f7771739e03c973e80
SHA256: a3c772033d43c85f2635596e2421496d55840abbde64ad64b8d0298cacbba466
Evidence Type Source Name Value Confidence Vendor pom description c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources, including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension. Low Vendor central groupid c3p0 Highest Vendor jar package name mchange Low Vendor pom groupid c3p0 Highest Vendor file name c3p0 High Vendor pom name c3p0:JDBC DataSources/Resource Pools High Vendor Manifest Implementation-Vendor-Id com.mchange Medium Vendor Manifest specification-vendor Machinery For Change, Inc. Low Vendor pom url http://c3p0.sourceforge.net Highest Vendor jar package name v2 Low Vendor Manifest Implementation-Vendor Machinery For Change, Inc. High Vendor Manifest extension-name com.mchange.v2.c3p0 Medium Vendor pom artifactid c3p0 Low Product jar package name v2 Low Product pom artifactid c3p0 Highest Product pom description c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources, including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension. Low Product pom groupid c3p0 Low Product pom url http://c3p0.sourceforge.net Medium Product file name c3p0 High Product Manifest extension-name com.mchange.v2.c3p0 Medium Product central artifactid c3p0 Highest Product pom name c3p0:JDBC DataSources/Resource Pools High Version file version 0.9.1.1 Highest Version central version 0.9.1.1 Highest Version Manifest Implementation-Version 0.9.1.1 High Version pom version 0.9.1.1 Highest
cdm-4.5.5.jarDescription:
The NetCDF-Java Library is a Java interface to NetCDF files,
as well as to many other types of scientific data formats.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/cdm-4.5.5.jarMD5: 7770c86aabbd0ec5e12ed1f0600d5492SHA1: af1748a3d024069cb7fd3fc2591efe806c914589SHA256: 74ea183cda0f7aa06fae2f3cfa8c3c6c64d013ce8cb87bde4a06de6676eacfdb
Evidence Type Source Name Value Confidence Vendor pom artifactid cdm Low Vendor pom name CDM core library High Vendor Manifest Implementation-Vendor UCAR/Unidata High Vendor Manifest built-on 20150306.1537 Low Vendor pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low Vendor file name cdm High Vendor Manifest Implementation-Vendor-Id edu.ucar Medium Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/documentation.htm Highest Vendor pom parent-artifactid thredds-parent Low Vendor pom groupid edu.ucar Highest Product pom name CDM core library High Product pom url http://www.unidata.ucar.edu/software/netcdf-java/documentation.htm Medium Product Manifest built-on 20150306.1537 Low Product pom artifactid cdm Highest Product pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low Product file name cdm High Product Manifest Implementation-Title CDM core library High Product pom groupid edu.ucar Low Product pom parent-artifactid thredds-parent Medium Version file version 4.5.5 Highest Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
maven: edu.ucar:cdm:4.5.5 Confidence :High commons-codec-1.9.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-codec-1.9.jar
MD5: 75615356605c8128013da9e3ac62a249
SHA1: 9ce04e34240f674bc72680f8b843b1457383161a
SHA256: ad19d2601c3abf0b946b5c3a4113e226a8c1e3305e395b90013b78dd94a723ce
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build tags/1.9-RC1@r1552874; 2013-12-20 22:56:50-0500 Low Vendor manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Vendor pom groupid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Vendor pom name Apache Commons Codec High Vendor file name commons-codec High Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest Product Manifest specification-title Apache Commons Codec Medium Product Manifest implementation-build tags/1.9-RC1@r1552874; 2013-12-20 22:56:50-0500 Low Product Manifest Implementation-Title Apache Commons Codec High Product manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Product pom parent-artifactid commons-parent Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low Product pom parent-groupid org.apache.commons Low Product pom artifactid commons-codec Highest Product pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low Product pom name Apache Commons Codec High Product pom url http://commons.apache.org/proper/commons-codec/ Medium Product pom groupid commons-codec Low Product Manifest Bundle-Name Apache Commons Codec Medium Product file name commons-codec High Product Manifest bundle-symbolicname org.apache.commons.codec Medium Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: commons-codec:commons-codec:1.9 Confidence :High commons-compress-1.9.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats.
These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditional
Unix Compress, DEFLATE and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-compress-1.9.jar
MD5: 6c9ce8534b9e4c17e5dea7a97425245c
SHA1: cc18955ff1e36d5abd39a14bfe82b19154330a34
SHA256: b8e0a1700023359a2b4d9f04b9287d7b9aa200f4feac1079812337eef2dcb8e2
Evidence Type Source Name Value Confidence Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest bundle-symbolicname org.apache.commons.compress Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-compress/ Low Vendor manifest Bundle-Description Apache Commons Compress software defines an API for working withcompression and archive formats.These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditionalUnix Compress, DEFLATE and ar, cpio, jar, tar, zip, dump, 7z, arj. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom artifactid commons-compress Low Vendor pom description
Apache Commons Compress software defines an API for working with
compression and archive formats.
These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditional
Unix Compress, DEFLATE and ar, cpio, jar, tar, zip, dump, 7z, arj. Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name commons-compress High Vendor Manifest implementation-build trunk@r1629495; 2014-10-06 06:52:07+0200 Low Vendor pom groupid apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom url http://commons.apache.org/proper/commons-compress/ Highest Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product pom artifactid commons-compress Highest Product pom parent-artifactid commons-parent Medium Product Manifest bundle-symbolicname org.apache.commons.compress Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-compress/ Low Product manifest Bundle-Description Apache Commons Compress software defines an API for working withcompression and archive formats.These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditionalUnix Compress, DEFLATE and ar, cpio, jar, tar, zip, dump, 7z, arj. Low Product pom description
Apache Commons Compress software defines an API for working with
compression and archive formats.
These include: bzip2, gzip, pack200, lzma, xz, Snappy, traditional
Unix Compress, DEFLATE and ar, cpio, jar, tar, zip, dump, 7z, arj. Low Product pom parent-groupid org.apache.commons Low Product file name commons-compress High Product pom url http://commons.apache.org/proper/commons-compress/ Medium Product Manifest implementation-build trunk@r1629495; 2014-10-06 06:52:07+0200 Low Product Manifest specification-title Apache Commons Compress Medium Product pom groupid apache.commons Low Product Manifest Implementation-Title Apache Commons Compress High Product pom name Apache Commons Compress High Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest Version file version 1.9 Highest
maven: org.apache.commons:commons-compress:1.9 Confidence :Highcpe: cpe:/a:apache:commons-compress:1.9 Confidence :Low suppress commons-csv-1.0.jarDescription:
The Apache Commons CSV library provides a simple interface for reading and writing
CSV files of various types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-csv-1.0.jar
MD5: eb687d26cfef4382d01f28d5d5c2ad13
SHA1: 8a0796ad6541a144eb1c00b93e06fbac03a9f313
SHA256: ef368c9fa003963da78399b8f5a41ddfbef6b206f505f52293005730d87e7295
Evidence Type Source Name Value Confidence Vendor pom name Apache Commons CSV High Vendor Manifest bundle-symbolicname org.apache.commons.csv Medium Vendor pom description
The Apache Commons CSV library provides a simple interface for reading and writing
CSV files of various types. Low Vendor pom url http://commons.apache.org/proper/commons-csv/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor manifest Bundle-Description The Apache Commons CSV library provides a simple interface for reading and writingCSV files of various types. Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid commons-csv Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-csv/ Low Vendor Manifest implementation-build tags/CSV_1.0_RC3@r1617100; 2014-08-10 11:45:38+0000 Low Vendor file name commons-csv High Vendor pom groupid apache.commons Highest Product pom url http://commons.apache.org/proper/commons-csv/ Medium Product pom name Apache Commons CSV High Product Manifest bundle-symbolicname org.apache.commons.csv Medium Product pom artifactid commons-csv Highest Product pom parent-artifactid commons-parent Medium Product pom description
The Apache Commons CSV library provides a simple interface for reading and writing
CSV files of various types. Low Product Manifest Bundle-Name Apache Commons CSV Medium Product manifest Bundle-Description The Apache Commons CSV library provides a simple interface for reading and writingCSV files of various types. Low Product pom parent-groupid org.apache.commons Low Product Manifest bundle-docurl http://commons.apache.org/proper/commons-csv/ Low Product Manifest implementation-build tags/CSV_1.0_RC3@r1617100; 2014-08-10 11:45:38+0000 Low Product file name commons-csv High Product Manifest specification-title Apache Commons CSV Medium Product Manifest Implementation-Title Apache Commons CSV High Product pom groupid apache.commons Low Version pom version 1.0 Highest Version file version 1.0 Highest Version Manifest Implementation-Version 1.0 High
maven: org.apache.commons:commons-csv:1.0 Confidence :High commons-exec-1.3.jarDescription:
Apache Commons Exec is a library to reliably execute external processes from within the JVM. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-exec-1.3.jar
MD5: 8bb8fa2edfd60d5c7ed6bf9923d14aa8
SHA1: 8dfb9facd0830a27b1b5f29f84593f0aeee7773b
SHA256: cb49812dc1bfb0ea4f20f398bcae1a88c6406e213e67f7524fb10d4f8ad9347b
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.apache.commons.exec Medium Vendor pom description Apache Commons Exec is a library to reliably execute external processes from within the JVM. Medium Vendor file name commons-exec High Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-exec/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-build trunk@r1636211; 2014-11-02 23:51:55+0000 Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid commons-exec Low Vendor manifest Bundle-Description Apache Commons Exec is a library to reliably execute external processes from within the JVM. Medium Vendor pom name Apache Commons Exec High Vendor pom url http://commons.apache.org/proper/commons-exec/ Highest Vendor pom groupid apache.commons Highest Product Manifest bundle-symbolicname org.apache.commons.exec Medium Product Manifest Bundle-Name Apache Commons Exec Medium Product pom description Apache Commons Exec is a library to reliably execute external processes from within the JVM. Medium Product pom parent-artifactid commons-parent Medium Product file name commons-exec High Product Manifest bundle-docurl http://commons.apache.org/proper/commons-exec/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product Manifest implementation-build trunk@r1636211; 2014-11-02 23:51:55+0000 Low Product pom url http://commons.apache.org/proper/commons-exec/ Medium Product pom artifactid commons-exec Highest Product pom parent-groupid org.apache.commons Low Product manifest Bundle-Description Apache Commons Exec is a library to reliably execute external processes from within the JVM. Medium Product pom name Apache Commons Exec High Product pom groupid apache.commons Low Product Manifest specification-title Apache Commons Exec Medium Product Manifest Implementation-Title Apache Commons Exec High Version file version 1.3 Highest Version pom version 1.3 Highest Version Manifest Implementation-Version 1.3 High
maven: org.apache.commons:commons-exec:1.3 Confidence :High commons-logging-api-1.1.jarDescription:
Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
The Apache Software License, Version 2.0: /LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-logging-api-1.1.jar
MD5: 4374238076ab08e60e0d296234480837
SHA1: 7d4cf5231d46c8524f9b9ed75bb2d1c69ab93322
SHA256: 33a4dd47bb4764e4eb3692d86386d17a0d9827f4f4bb0f70121efab6bc03ba35
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor file name commons-logging-api High Vendor pom organization url http://jakarta.apache.org Medium Vendor pom url http://jakarta.apache.org/commons/logging/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor central groupid commons-logging Highest Vendor pom name Logging High Vendor jar package name logging Low Vendor Manifest extension-name org.apache.commons.logging Medium Vendor jar package name apache Low Vendor pom organization name The Apache Software Foundation High Vendor pom groupid commons-logging Highest Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom artifactid commons-logging-api Low Product jar package name commons Low Product file name commons-logging-api High Product pom organization name The Apache Software Foundation Low Product pom groupid commons-logging Low Product pom organization url http://jakarta.apache.org Low Product pom artifactid commons-logging-api Highest Product pom name Logging High Product jar package name logging Low Product Manifest extension-name org.apache.commons.logging Medium Product pom url http://jakarta.apache.org/commons/logging/ Medium Product Manifest Implementation-Title Jakarta Commons Logging High Product central artifactid commons-logging-api Highest Product jar package name impl Low Product pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low Product Manifest specification-title Jakarta Commons Logging Medium Version file version 1.1 Highest Version central version 1.1 Highest Version Manifest Implementation-Version 1.1 High Version pom version 1.1 Highest
commons-vfs2-2.0.jarDescription:
VFS is a Virtual File System library. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/commons-vfs2-2.0.jar
MD5: a2cabc6a91a9de9e3d5d460b06d65b45
SHA1: b5af3b9c96b060d77c68fa5ac9384b402dd58013
SHA256: 5af37bc47f6bcce94e740b9793115ff135dda54f9ccf98e057938c2c98765f4d
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-vfs2-project Low Vendor pom description VFS is a Virtual File System library. Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-vfs2 Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Commons VFS Core High Vendor Manifest bundle-docurl http://commons.apache.org/vfs/commons-vfs2/ Low Vendor Manifest bundle-symbolicname org.apache.commons.vfs Medium Vendor manifest Bundle-Description VFS is a Virtual File System library. Medium Vendor pom groupid apache.commons Highest Vendor file name commons-vfs2 High Product Manifest specification-title Commons VFS Core Medium Product Manifest Implementation-Title Commons VFS Core High Product pom parent-artifactid commons-vfs2-project Medium Product pom description VFS is a Virtual File System library. Medium Product Manifest Bundle-Name Commons VFS Core Medium Product pom parent-groupid org.apache.commons Low Product pom name Commons VFS Core High Product Manifest bundle-docurl http://commons.apache.org/vfs/commons-vfs2/ Low Product Manifest bundle-symbolicname org.apache.commons.vfs Medium Product manifest Bundle-Description VFS is a Virtual File System library. Medium Product pom groupid apache.commons Low Product pom artifactid commons-vfs2 Highest Product file name commons-vfs2 High Version file version 2.0 Highest Version Manifest Implementation-Version 2.0 High Version pom version 2.0 Highest
maven: org.apache.commons:commons-vfs2:2.0 Confidence :High ehcache-core-2.6.2.jarDescription:
This is the ehcache core module. Pair it with other modules for added functionality. License:
The Apache Software License, Version 2.0: src/assemble/EHCACHE-CORE-LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/ehcache-core-2.6.2.jar
MD5: b6abecd2c01070700a9001b33b94b3f4
SHA1: 3baecd92015a9f8fe4cf51c8b5d3a5bddcdd3e86
SHA256: df61f1a1724aa674d922dce21965b907df8f77e730679ae1abe92679390a2fd6
Evidence Type Source Name Value Confidence Vendor file name ehcache-core High Vendor pom name Ehcache Core High Vendor pom artifactid ehcache-core Low Vendor pom url http://ehcache.org Highest Vendor pom groupid net.sf.ehcache Highest Vendor pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium Vendor pom parent-artifactid ehcache-parent Low Product file name ehcache-core High Product pom name Ehcache Core High Product pom groupid net.sf.ehcache Low Product pom parent-artifactid ehcache-parent Medium Product pom url http://ehcache.org Medium Product pom artifactid ehcache-core Highest Product pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium Version pom version 2.6.2 Highest Version file version 2.6.2 Highest
maven: net.sf.ehcache:ehcache-core:2.6.2 Confidence :High fontbox-1.8.10.jarDescription:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/fontbox-1.8.10.jar
MD5: 010dcae8a1d4d9b1623d6c37ee228f6e
SHA1: 41776c7713e3f3a1ce688bd96459fc597298c340
SHA256: d0e866da54a51ed732487d4019b813102e554741ee1a9eea4a1f5d10fadc03c6
Evidence Type Source Name Value Confidence Vendor pom artifactid fontbox Low Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium Vendor manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low Vendor pom parent-artifactid pdfbox-parent Low Vendor file name fontbox High Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom url http://pdfbox.apache.org/ Highest Vendor pom groupid apache.pdfbox Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.pdfbox Medium Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor pom name Apache FontBox High Product Manifest Implementation-Title Apache FontBox High Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium Product manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low Product pom groupid apache.pdfbox Low Product file name fontbox High Product pom parent-artifactid pdfbox-parent Medium Product pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low Product pom parent-groupid org.apache.pdfbox Low Product pom artifactid fontbox Highest Product Manifest bundle-docurl http://pdfbox.apache.org Low Product Manifest Bundle-Name Apache FontBox Medium Product pom url http://pdfbox.apache.org/ Medium Product pom name Apache FontBox High Product Manifest specification-title Apache FontBox Medium Version file version 1.8.10 Highest Version pom version 1.8.10 Highest Version Manifest Implementation-Version 1.8.10 High
Published Vulnerabilities CVE-2016-2175 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser. Vulnerable Software & Versions: (show all )
geoapi-3.0.0.jarDescription:
The development community in building GIS solutions is sustaining an enormous level
of effort. The GeoAPI project aims to reduce duplication and increase interoperability
by providing neutral, interface-only APIs derived from OGC/ISO Standards.
License:
https://geoapi.svn.sourceforge.net/svnroot/geoapi/branches/3.0.x/LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/geoapi-3.0.0.jar
MD5: 97b6baee0cf3402e8360203bf6c23b3f
SHA1: 0a04e0f361627fb33a140b5aa4c019741f905577
SHA256: 95e171231c72d16ee60ca309456a72a5c774a657c5700f6fc6f50a7babf4731a
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid geoapi-parent Low Vendor pom name GeoAPI High Vendor manifest Bundle-Description The development community in building GIS solutions is sustaining an enormous level of effort. The GeoAPI project aims to reduce duplication and increase interoperability by providing neutral, interface-only APIs derived from OGC/ISO Standards. Low Vendor pom description The development community in building GIS solutions is sustaining an enormous level of effort. The GeoAPI project aims to reduce duplication and increase interoperability by providing neutral, interface-only APIs derived from OGC/ISO Standards. Low Vendor pom artifactid geoapi Low Vendor Manifest bundle-symbolicname org.opengis.geoapi Medium Vendor pom parent-groupid org.opengis Medium Vendor pom groupid opengis Highest Vendor file name geoapi High Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor Manifest bundle-docurl http://www.geoapi.org Low Product pom artifactid geoapi Highest Product pom description The development community in building GIS solutions is sustaining an enormous level of effort. The GeoAPI project aims to reduce duplication and increase interoperability by providing neutral, interface-only APIs derived from OGC/ISO Standards. Low Product Manifest Bundle-Name GeoAPI Medium Product pom parent-groupid org.opengis Low Product Manifest bundle-docurl http://www.geoapi.org Low Product Manifest specification-title GeoAPI Medium Product pom name GeoAPI High Product manifest Bundle-Description The development community in building GIS solutions is sustaining an enormous level of effort. The GeoAPI project aims to reduce duplication and increase interoperability by providing neutral, interface-only APIs derived from OGC/ISO Standards. Low Product pom parent-artifactid geoapi-parent Medium Product Manifest bundle-symbolicname org.opengis.geoapi Medium Product pom groupid opengis Low Product file name geoapi High Version pom version 3.0.0 Highest Version file version 3.0.0 Highest
maven: org.opengis:geoapi:3.0.0 Confidence :High grib-4.5.5.jarDescription:
Decoder for the GRIB format.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/grib-4.5.5.jarMD5: 0cb80276d8ea89cacc1d5632dbf39fe9SHA1: cfe552910e9a8d57ce71134796abb281a74ead16SHA256: 1e0492135f421f554c4651a95225f27f2a3230e993329f69348110f8521c32d9
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor UCAR/Unidata High Vendor Manifest built-on 20150306.1537 Low Vendor Manifest Implementation-Vendor-Id edu.ucar Medium Vendor pom description
Decoder for the GRIB format.
Medium Vendor pom artifactid grib Low Vendor pom parent-artifactid thredds-parent Low Vendor pom groupid edu.ucar Highest Vendor pom name GRIB IOSP and Feature Collection High Vendor file name grib High Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/ Highest Product Manifest Implementation-Title GRIB IOSP and Feature Collection High Product Manifest built-on 20150306.1537 Low Product pom description
Decoder for the GRIB format.
Medium Product pom url http://www.unidata.ucar.edu/software/netcdf-java/ Medium Product pom groupid edu.ucar Low Product pom artifactid grib Highest Product pom name GRIB IOSP and Feature Collection High Product file name grib High Product pom parent-artifactid thredds-parent Medium Version file version 4.5.5 Highest Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
maven: edu.ucar:grib:4.5.5 Confidence :High guava-11.0.2.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
This project is a complete packaging of all the Guava libraries
into a single jar. Individual portions of Guava can be used
by downloading the appropriate module and its dependencies.
Guava (complete) has only one code dependency - javax.annotation,
per the JSR-305 spec.
File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/guava-11.0.2.jarMD5: bed5977336ea1279d2bad3bb258dc8c3SHA1: 35a3c69e19d72743cac83778aecbee68680f63ebSHA256: e144a0ec7f5139c58d4f3729ccfb4240f9c576a1aa43790e4090e09316129ee1
Evidence Type Source Name Value Confidence Vendor jar package name collect Low Vendor file name guava High Vendor pom artifactid guava Low Vendor pom parent-artifactid guava-parent Low Vendor jar package name common Low Vendor pom name Guava: Google Core Libraries for Java High Vendor jar package name google Low Vendor pom parent-groupid com.google.guava Medium Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. This project is a complete packaging of all the Guava libraries into a single jar. Individual portions of Guava can be used by downloading the appropriate module and its dependencies. Guava (complete) has only one code dependency - javax.annotation, per the JSR-305 spec. Low Vendor pom groupid google.guava Highest Product pom groupid google.guava Low Product jar package name collect Low Product file name guava High Product jar package name common Low Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Product pom parent-artifactid guava-parent Medium Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. This project is a complete packaging of all the Guava libraries into a single jar. Individual portions of Guava can be used by downloading the appropriate module and its dependencies. Guava (complete) has only one code dependency - javax.annotation, per the JSR-305 spec. Low Product pom parent-groupid com.google.guava Low Version pom version 11.0.2 Highest Version file version 11.0.2 Highest
maven: com.google.guava:guava:11.0.2 Confidence :High httpservices-4.5.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/httpservices-4.5.5.jarMD5: c5207827b8b7e6045b2af7e1e8c5b1d4SHA1: ee5f217be599e5e03f7f0e55e03f9e721a154f62SHA256: 8334da7adc9ed7a7b941a780f4d22054f8a11d03973be83ae8399400d55300e4
Evidence Type Source Name Value Confidence Vendor pom artifactid httpservices Low Vendor Manifest Implementation-Vendor UCAR/Unidata High Vendor Manifest built-on 20150306.1537 Low Vendor Manifest Implementation-Vendor-Id edu.ucar Medium Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/documentation.htm Highest Vendor pom parent-artifactid thredds-parent Low Vendor pom name HttpClient Wrappers High Vendor pom groupid edu.ucar Highest Vendor file name httpservices High Product pom artifactid httpservices Highest Product pom url http://www.unidata.ucar.edu/software/netcdf-java/documentation.htm Medium Product Manifest built-on 20150306.1537 Low Product pom groupid edu.ucar Low Product pom name HttpClient Wrappers High Product Manifest Implementation-Title HttpClient Wrappers High Product file name httpservices High Product pom parent-artifactid thredds-parent Medium Version file version 4.5.5 Highest Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
maven: edu.ucar:httpservices:4.5.5 Confidence :High isoparser-1.0.2.jarDescription:
A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/isoparser-1.0.2.jar
MD5: ea67895a456476d6848a13b41a843bd0
SHA1: 6d9a5c5814ec67178dd1d5a25bae874d4697a5b8
SHA256: 151674d83665bbf39240531d8c8ae506747811d4766cb1d2d3962d294f9d7957
Evidence Type Source Name Value Confidence Vendor jar package name boxes Low Vendor jar package name mp4parser Low Vendor pom artifactid isoparser Low Vendor pom name ISO Parser High Vendor jar package name googlecode Low Vendor file name isoparser High Vendor pom groupid googlecode.mp4parser Highest Vendor pom url http://code.google.com/p/mp4parser/ Highest Vendor pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium Product pom url http://code.google.com/p/mp4parser/ Medium Product jar package name boxes Low Product jar package name mp4parser Low Product pom name ISO Parser High Product pom artifactid isoparser Highest Product pom groupid googlecode.mp4parser Low Product file name isoparser High Product pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium Version pom version 1.0.2 Highest Version file version 1.0.2 Highest
maven: com.googlecode.mp4parser:isoparser:1.0.2 Confidence :Highcpe: cpe:/a:boxes_project:boxes:1.0.2 Confidence :Low suppress jackcess-2.1.2.jarDescription:
A pure Java library for reading from and writing to MS Access databases. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jackcess-2.1.2.jar
MD5: 08f01ae3bb03c73d29954d4b23e43fac
SHA1: b7f61fbb78919cb851868ce177d8fe626a6b4370
SHA256: 785df69c67240a90d31228ef1a018ba5b733102d9696266ba4cd73544bdb94b3
Evidence Type Source Name Value Confidence Vendor file name jackcess High Vendor pom groupid healthmarketscience.jackcess Highest Vendor Manifest bundle-symbolicname com.healthmarketscience.jackcess Medium Vendor pom artifactid jackcess Low Vendor pom name Jackcess High Vendor pom url http://jackcess.sf.net Highest Vendor pom parent-artifactid openhms-parent Low Vendor pom parent-groupid com.healthmarketscience Medium Vendor Manifest bundle-docurl http://www.healthmarketscience.com Low Vendor pom description A pure Java library for reading from and writing to MS Access databases. Medium Vendor manifest Bundle-Description A pure Java library for reading from and writing to MS Access databases. Medium Product pom parent-artifactid openhms-parent Medium Product Manifest bundle-symbolicname com.healthmarketscience.jackcess Medium Product pom groupid healthmarketscience.jackcess Low Product pom description A pure Java library for reading from and writing to MS Access databases. Medium Product pom url http://jackcess.sf.net Medium Product file name jackcess High Product Manifest Bundle-Name Jackcess Medium Product pom name Jackcess High Product pom artifactid jackcess Highest Product Manifest bundle-docurl http://www.healthmarketscience.com Low Product manifest Bundle-Description A pure Java library for reading from and writing to MS Access databases. Medium Product pom parent-groupid com.healthmarketscience Low Version file version 2.1.2 Highest Version pom version 2.1.2 Highest
maven: com.healthmarketscience.jackcess:jackcess:2.1.2 Confidence :High jackcess-encrypt-2.1.0.jarDescription:
An add-on to the Jackcess library for handling encryption in MS Access files. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jackcess-encrypt-2.1.0.jar
MD5: be37c31ae7f40b2a1c5f470db6879189
SHA1: 84160bd02d773d42acdfb165b84cce227c006bc9
SHA256: 425066fc931cdfdcf2a3f478a808c9006f98c044a8d14e086c1c7aa8bcf661ec
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description An add-on to the Jackcess library for handling encryption in MS Access files. Medium Vendor pom artifactid jackcess-encrypt Low Vendor pom groupid healthmarketscience.jackcess Highest Vendor file name jackcess-encrypt High Vendor pom url http://jackcessencrypt.sf.net Highest Vendor pom name Jackcess Encrypt High Vendor pom description An add-on to the Jackcess library for handling encryption in MS Access files. Medium Vendor Manifest bundle-symbolicname com.healthmarketscience.jackcess.encrypt Medium Vendor pom parent-artifactid openhms-parent Low Vendor pom parent-groupid com.healthmarketscience Medium Vendor Manifest bundle-docurl http://www.healthmarketscience.com Low Product pom parent-artifactid openhms-parent Medium Product file name jackcess-encrypt High Product pom name Jackcess Encrypt High Product pom description An add-on to the Jackcess library for handling encryption in MS Access files. Medium Product Manifest bundle-symbolicname com.healthmarketscience.jackcess.encrypt Medium Product pom groupid healthmarketscience.jackcess Low Product manifest Bundle-Description An add-on to the Jackcess library for handling encryption in MS Access files. Medium Product Manifest Bundle-Name Jackcess Encrypt Medium Product pom artifactid jackcess-encrypt Highest Product Manifest bundle-docurl http://www.healthmarketscience.com Low Product pom parent-groupid com.healthmarketscience Low Product pom url http://jackcessencrypt.sf.net Medium Version pom version 2.1.0 Highest Version file version 2.1.0 Highest
maven: com.healthmarketscience.jackcess:jackcess-encrypt:2.1.0 Confidence :High java-libpst-0.8.1.jarDescription:
A library to read PST files with java, without need for external libraries. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/java-libpst-0.8.1.jar
MD5: 6be27662e0b06154e5f05938937d16b7
SHA1: ad31986653dac9cb5132ea5b2999c20b4b286255
SHA256: a3f7b3c934f477b0fc3c0eadebc3d24872bbebc3ac5a22ab575e5f476ea34757
Evidence Type Source Name Value Confidence Vendor pom artifactid java-libpst Low Vendor pom name java-libpst High Vendor pom url https://code.google.com/p/java-libpst/ Highest Vendor pom groupid pff Highest Vendor file name java-libpst High Vendor jar package name pff Low Vendor pom description A library to read PST files with java, without need for external libraries. Medium Product pom name java-libpst High Product pom url https://code.google.com/p/java-libpst/ Medium Product pom artifactid java-libpst Highest Product file name java-libpst High Product pom groupid pff Low Product pom description A library to read PST files with java, without need for external libraries. Medium Version file version 0.8.1 Highest Version pom version 0.8.1 Highest
maven: com.pff:java-libpst:0.8.1 Confidence :High jcip-annotations-1.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jcip-annotations-1.0.jarMD5: 9d5272954896c5a5d234f66b7372b17aSHA1: afba4942caaeaf46aab0b976afd57cc7c181467eSHA256: be5805392060c71474bf6c9a67a099471274d30b83eef84bfc4e0889a4f1dcc0
Evidence Type Source Name Value Confidence Vendor pom groupid net.jcip Highest Vendor pom name "Java Concurrency in Practice" book annotations High Vendor file name jcip-annotations High Vendor central groupid net.jcip Highest Vendor jar package name net Low Vendor jar package name annotations Low Vendor pom artifactid jcip-annotations Low Vendor jar package name jcip Low Vendor pom url http://jcip.net/ Highest Product pom url http://jcip.net/ Medium Product pom name "Java Concurrency in Practice" book annotations High Product file name jcip-annotations High Product central artifactid jcip-annotations Highest Product pom groupid net.jcip Low Product pom artifactid jcip-annotations Highest Product jar package name annotations Low Product jar package name jcip Low Version pom version 1.0 Highest Version file version 1.0 Highest Version central version 1.0 Highest
jcommander-1.35.jarDescription:
A Java framework to parse command line options with annotations. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jcommander-1.35.jar
MD5: 90216444fab67357c5bdf3293b47107e
SHA1: 47592e181b0bdbbeb63029e08c5e74f6803c4edd
SHA256: 019c12fec1ce5c02cbabb150f6ac8a86d92a0ecc9c89a549e5537283e863000c
Evidence Type Source Name Value Confidence Vendor file name jcommander High Vendor Manifest bundle-symbolicname com.beust.jcommander Medium Vendor pom groupid beust Highest Vendor pom url http://beust.com/jcommander Highest Vendor pom name JCommander High Vendor manifest Bundle-Description A Java framework to parse command line options with annotations. Medium Vendor pom description A Java framework to parse command line options with annotations. Medium Vendor pom artifactid jcommander Low Product Manifest Bundle-Name JCommander Medium Product file name jcommander High Product Manifest bundle-symbolicname com.beust.jcommander Medium Product pom artifactid jcommander Highest Product pom name JCommander High Product pom url http://beust.com/jcommander Medium Product manifest Bundle-Description A Java framework to parse command line options with annotations. Medium Product pom groupid beust Low Product pom description A Java framework to parse command line options with annotations. Medium Version file version 1.35 Highest Version pom version 1.35 Highest
maven: com.beust:jcommander:1.35 Confidence :High jdom-1.0.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jdom-1.0.jarMD5: 0b8f97de82fc9529b1028a77125ce4f8SHA1: a2ac1cd690ab4c80defe7f9bce14d35934c35cecSHA256: 3b23bc3979aec14a952a12aafc483010dc57579775f2ffcacef5256a90eeda02
Evidence Type Source Name Value Confidence Vendor manifest: org/jdom/output/ Implementation-Vendor jdom.org Medium Vendor central groupid com.sun.phobos High Vendor manifest: org/jdom/transform/ Implementation-Vendor jdom.org Medium Vendor jar package name jdom Low Vendor pom url http://www.jdom.org/ Highest Vendor manifest: org/jdom/xpath/ Implementation-Vendor jdom.org Medium Vendor pom groupid jdom Highest Vendor central groupid jdom High Vendor manifest: org/jdom/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/filter/ Implementation-Vendor jdom.org Medium Vendor pom groupid sun.phobos Highest Vendor file name jdom High Vendor manifest: org/jdom/input/ Implementation-Vendor jdom.org Medium Vendor pom artifactid jdom Low Vendor manifest: org/jdom/ Implementation-Vendor jdom.org Medium Vendor pom name JDOM library High Product manifest: org/jdom/transform/ Specification-Title JDOM Transformation Classes Medium Product manifest: org/jdom/ Implementation-Title org.jdom Medium Product pom groupid jdom Low Product manifest: org/jdom/ Specification-Title JDOM Classes Medium Product central artifactid jdom High Product manifest: org/jdom/adapters/ Specification-Title JDOM Adapter Classes Medium Product pom groupid sun.phobos Low Product manifest: org/jdom/adapters/ Implementation-Title org.jdom.adapters Medium Product manifest: org/jdom/filter/ Implementation-Title org.jdom.filter Medium Product manifest: org/jdom/transform/ Implementation-Title org.jdom.transform Medium Product manifest: org/jdom/output/ Specification-Title JDOM Output Classes Medium Product pom artifactid jdom Highest Product manifest: org/jdom/xpath/ Implementation-Title org.jdom.xpath Medium Product file name jdom High Product manifest: org/jdom/xpath/ Specification-Title JDOM XPath Classes Medium Product manifest: org/jdom/filter/ Specification-Title JDOM Filter Classes Medium Product manifest: org/jdom/input/ Specification-Title JDOM Input Classes Medium Product manifest: org/jdom/input/ Implementation-Title org.jdom.input Medium Product manifest: org/jdom/output/ Implementation-Title org.jdom.output Medium Product pom name JDOM library High Product pom url http://www.jdom.org/ Medium Version pom version 1.0 Highest Version file version 1.0 Highest Version central version 1.0 High
jdom2-2.0.4.jarDescription:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jdom2-2.0.4.jar
MD5: e51c9485a3a38525a7df4bd25a05dec6
SHA1: 4b65e55cc61b34bc634b25f0359d1242e4c519de
SHA256: ca379b0ad57499c9d35066b7018ce868a225db9c8d2143eeb31cc8e396b2919c
Evidence Type Source Name Value Confidence Vendor manifest: org/jdom2/filter/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/input/ Implementation-Vendor jdom.org Medium Vendor pom name JDOM High Vendor pom organization url http://www.jdom.org Medium Vendor central groupid org.jdom Highest Vendor pom groupid jdom Highest Vendor file name jdom2 High Vendor manifest: org/jdom2/output/ Implementation-Vendor jdom.org Medium Vendor pom organization name JDOM High Vendor manifest: org/jdom2/transform/ Implementation-Vendor jdom.org Medium Vendor pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium Vendor pom artifactid jdom2 Low Vendor pom url http://www.jdom.org Highest Vendor jar package name jdom2 Low Vendor manifest: org/jdom2/xpath/ Implementation-Vendor jdom.org Medium Product manifest: org/jdom2/input/ Implementation-Title org.jdom2.input Medium Product manifest: org/jdom2/transform/ Implementation-Title org.jdom2.transform Medium Product pom groupid jdom Low Product pom organization url http://www.jdom.org Low Product manifest: org/jdom2/adapters/ Specification-Title JDOM Adapter Classes Medium Product manifest: org/jdom2/xpath/ Implementation-Title org.jdom2.xpath Medium Product pom name JDOM High Product manifest: org/jdom2/xpath/ Specification-Title JDOM XPath Classes Medium Product central artifactid jdom2 Highest Product manifest: org/jdom2/filter/ Specification-Title JDOM Filter Classes Medium Product manifest: org/jdom2/input/ Specification-Title JDOM Input Classes Medium Product pom organization name JDOM Low Product manifest: org/jdom2/filter/ Implementation-Title org.jdom2.filter Medium Product pom artifactid jdom2 Highest Product pom url http://www.jdom.org Medium Product manifest: org/jdom2/adapters/ Implementation-Title org.jdom2.adapters Medium Product file name jdom2 High Product manifest: org/jdom2/ Specification-Title JDOM Classes Medium Product pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium Product manifest: org/jdom2/output/ Implementation-Title org.jdom2.output Medium Product manifest: org/jdom2/ Implementation-Title org.jdom2 Medium Product manifest: org/jdom2/output/ Specification-Title JDOM Output Classes Medium Product manifest: org/jdom2/transform/ Specification-Title JDOM Transformation Classes Medium Version central version 2.0.4 Highest Version file version 2.0.4 Highest Version pom version 2.0.4 Highest
jempbox-1.8.10.jarDescription:
The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM)
specification. JempBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jempbox-1.8.10.jar
MD5: 903a0f2729626ce8fa0d74566732a738
SHA1: 40df4e4ca884aadc20b82d5abd0a3679774c55a6
SHA256: 6b246dcc8c38c0f9f2c5608198fa55c7edff9bc76abf7ffca9be81ebdf918981
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low Vendor pom parent-artifactid pdfbox-parent Low Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.pdfbox Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.pdfbox Medium Vendor pom name Apache JempBox High Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor file name jempbox High Vendor pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low Vendor pom artifactid jempbox Low Product manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low Product pom groupid apache.pdfbox Low Product pom parent-artifactid pdfbox-parent Medium Product Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium Product pom parent-groupid org.apache.pdfbox Low Product pom name Apache JempBox High Product Manifest bundle-docurl http://pdfbox.apache.org Low Product file name jempbox High Product pom artifactid jempbox Highest Product pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low Product Manifest Bundle-Name Apache JempBox Medium Product Manifest Implementation-Title Apache JempBox High Product Manifest specification-title Apache JempBox Medium Version file version 1.8.10 Highest Version pom version 1.8.10 Highest Version Manifest Implementation-Version 1.8.10 High
Published Vulnerabilities CVE-2016-2175 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser. Vulnerable Software & Versions: (show all )
jhighlight-1.0.2.jarDescription:
JHighlight is an embeddable pure Java syntax highlighting
library that supports Java, HTML, XHTML, XML and LZX
languages and outputs to XHTML.
It also supports RIFE templates tags and highlights them
clearly so that you can easily identify the difference
between your RIFE markup and the actual marked up source.
License:
CDDL, v1.0: http://www.opensource.org/licenses/cddl1.php
LGPL, v2.1 or later: http://www.opensource.org/licenses/lgpl-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jhighlight-1.0.2.jar
MD5: 867f23891848a72f1284ff3aaf18d94e
SHA1: 992a8a8add10468930efc1f110f2895f68258a1e
SHA256: db48fddb05ece10834158e62b2d272eb3fdcb8cb1dd3482f3aebf5cc7065ca1e
Evidence Type Source Name Value Confidence Vendor jar package name uwyn Low Vendor pom url codelibs/jhighlight Highest Vendor pom name JHighlight High Vendor pom groupid codelibs Highest Vendor jar package name fastutil Low Vendor pom artifactid jhighlight Low Vendor pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low Vendor file name jhighlight High Vendor jar package name jhighlight Low Product pom name JHighlight High Product jar package name fastutil Low Product pom artifactid jhighlight Highest Product pom groupid codelibs Low Product pom url codelibs/jhighlight High Product pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low Product file name jhighlight High Product jar package name jhighlight Low Version pom version 1.0.2 Highest Version file version 1.0.2 Highest
maven: org.codelibs:jhighlight:1.0.2 Confidence :High jj2000-5.2.jarDescription:
Fork of jpeg2k code from https://code.google.com/p/jj2000/.
This is a dependency for support of compression in Grib2 files in netCDF-java and TDS.
We welcome bug fixes and other contributions to this code. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jj2000-5.2.jar
MD5: 61bc76a853403e6566975699194ab981
SHA1: b857c9bdf12fe17d8ef98218eaa39e6a0c6ff493
SHA256: da2a8d287a2c1f724560841108fdb4af25648a6352474c5a269e8e14080b1919
Evidence Type Source Name Value Confidence Vendor pom url Unidata/jj2000 Highest Vendor pom description Fork of jpeg2k code from https://code.google.com/p/jj2000/. This is a dependency for support of compression in Grib2 files in netCDF-java and TDS. We welcome bug fixes and other contributions to this code. Low Vendor pom name Unidata jj2000 High Vendor file name jj2000 High Vendor jar package name jj2000 Low Vendor pom groupid edu.ucar Highest Vendor pom artifactid jj2000 Low Vendor jar package name j2k Low Product pom artifactid jj2000 Highest Product pom url Unidata/jj2000 High Product pom description Fork of jpeg2k code from https://code.google.com/p/jj2000/. This is a dependency for support of compression in Grib2 files in netCDF-java and TDS. We welcome bug fixes and other contributions to this code. Low Product pom name Unidata jj2000 High Product pom groupid edu.ucar Low Product file name jj2000 High Product jar package name j2k Low Version pom version 5.2 Highest Version file version 5.2 Highest
maven: edu.ucar:jj2000:5.2 Confidence :High jmatio-1.0.jarDescription:
Matlab's MAT-file I/O API in JAVA. Supports Matlab 5 MAT-flie format reading and writing. Written in pure JAVA.
License:
BSD: http://www.linfo.org/bsdlicense.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jmatio-1.0.jar
MD5: 43be2be98c772ac63fb9d7c958fed6ca
SHA1: df72993ea17d34c3bacd983558d2970a866abaf6
SHA256: ce61d45b2a8669f65cbf9df1a4520439e5b18c7721fe5d823588bb12441ab1b5
Evidence Type Source Name Value Confidence Vendor jar package name jmatio Low Vendor pom description Matlab's MAT-file I/O API in JAVA. Supports Matlab 5 MAT-flie format reading and writing. Written in pure JAVA. Low Vendor pom artifactid jmatio Low Vendor file name jmatio High Vendor pom url http://sourceforge.net/projects/jmatio/ Highest Vendor pom groupid net.sourceforge.jmatio Highest Vendor pom name jmatio High Vendor jar package name types Low Product pom artifactid jmatio Highest Product pom url http://sourceforge.net/projects/jmatio/ Medium Product pom description Matlab's MAT-file I/O API in JAVA. Supports Matlab 5 MAT-flie format reading and writing. Written in pure JAVA. Low Product file name jmatio High Product pom groupid net.sourceforge.jmatio Low Product pom name jmatio High Product jar package name types Low Version pom version 1.0 Highest Version file version 1.0 Highest
maven: net.sourceforge.jmatio:jmatio:1.0 Confidence :High jna-4.1.0.jarDescription:
Java Native Access License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
ASL, version 2: http://www.apache.org/licenses/ File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jna-4.1.0.jar
MD5: b0e08c9936dc52aa40439c71fcad6297
SHA1: 1c12d070e602efd8021891cdd7fd18bc129372d4
SHA256: 1aa37e9ea6baa0ee152d89509f758f0847eac66ec179b955cafe0919e540a92e
Evidence Type Source Name Value Confidence Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor pom groupid net.java.dev.jna Highest Vendor Manifest Implementation-Vendor JNA Development Team High Vendor manifest Bundle-Description JNA Library Medium Vendor central groupid net.java.dev.jna Highest Vendor pom name Java Native Access High Vendor Manifest specification-vendor JNA Development Team Low Vendor pom url twall/jna Highest Vendor jar package name jna Low Vendor pom description Java Native Access Medium Vendor pom artifactid jna Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor Manifest bundle-symbolicname com.sun.jna Medium Vendor file name jna High Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product Manifest specification-title Java Native Access (JNA) Medium Product manifest Bundle-Description JNA Library Medium Product central artifactid jna Highest Product Manifest Implementation-Title com.sun.jna High Product pom name Java Native Access High Product jar package name jna Low Product pom description Java Native Access Medium Product pom url twall/jna High Product pom groupid net.java.dev.jna Low Product Manifest Bundle-Name jna Medium Product Manifest bundle-symbolicname com.sun.jna Medium Product file name jna High Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Product pom artifactid jna Highest Version central version 4.1.0 Highest Version file version 4.1.0 Highest Version pom version 4.1.0 Highest
joda-time-2.2.jarDescription:
Date and time library to replace JDK date handling License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/joda-time-2.2.jar
MD5: 226f5207543c490f10f234e82108b998
SHA1: a5f29a7acaddea3f4af307e8cf2d0cc82645fd7d
SHA256: e5183ca131f7195bde5b27e4cd18deeb6d14f8bc5c483b1431421132927240af
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor Joda.org Low Vendor Manifest bundle-docurl http://joda-time.sourceforge.net/ Low Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor pom groupid joda-time Highest Vendor pom description Date and time library to replace JDK date handling Medium Vendor Manifest extension-name joda-time Medium Vendor file name joda-time High Vendor pom organization url http://www.joda.org Medium Vendor Manifest bundle-symbolicname joda-time Medium Vendor pom name Joda time High Vendor pom artifactid joda-time Low Vendor Manifest Implementation-Vendor Joda.org High Vendor pom organization name Joda.org High Vendor pom url http://joda-time.sourceforge.net Highest Product pom groupid joda-time Low Product Manifest specification-title Joda-Time Medium Product Manifest bundle-docurl http://joda-time.sourceforge.net/ Low Product pom url http://joda-time.sourceforge.net Medium Product pom description Date and time library to replace JDK date handling Medium Product Manifest Bundle-Name Joda-Time Medium Product pom organization name Joda.org Low Product Manifest extension-name joda-time Medium Product pom organization url http://www.joda.org Low Product pom artifactid joda-time Highest Product file name joda-time High Product Manifest bundle-symbolicname joda-time Medium Product pom name Joda time High Product Manifest Implementation-Title org.joda.time High Version file version 2.2 Highest Version Manifest Implementation-Version 2.2 High Version pom version 2.2 Highest
maven: joda-time:joda-time:2.2 Confidence :High json-simple-1.1.1.jarDescription:
A simple Java toolkit for JSON License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/json-simple-1.1.1.jar
MD5: 5cc2c478d73e8454b4c369cee66c5bc7
SHA1: c9ad4a0850ab676c5c64461a05ca524cdfff59f1
SHA256: 4e69696892b88b41c55d49ab2fdcc21eead92bf54acc588c0050596c3b75199c
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description A simple Java toolkit for JSON Medium Vendor pom description A simple Java toolkit for JSON Medium Vendor pom artifactid json-simple Low Vendor pom url http://code.google.com/p/json-simple/ Highest Vendor pom name JSON.simple High Vendor Manifest bundle-symbolicname com.googlecode.json-simple Medium Vendor file name json-simple High Vendor pom groupid googlecode.json-simple Highest Product manifest Bundle-Description A simple Java toolkit for JSON Medium Product pom description A simple Java toolkit for JSON Medium Product pom groupid googlecode.json-simple Low Product pom url http://code.google.com/p/json-simple/ Medium Product pom name JSON.simple High Product Manifest bundle-symbolicname com.googlecode.json-simple Medium Product file name json-simple High Product pom artifactid json-simple Highest Product Manifest Bundle-Name JSON.simple Medium Version pom version 1.1.1 Highest Version file version 1.1.1 Highest
maven: com.googlecode.json-simple:json-simple:1.1.1 Confidence :High jsoup-1.7.2.jarDescription:
jsoup HTML parser License:
The MIT License: http://jsoup.com/license File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jsoup-1.7.2.jar
MD5: 06cca626f92fca16f8d2dd9994ff9ab0
SHA1: d7e275ba05aa380ca254f72d0c0ffebaedc3adcf
SHA256: bdd2f2b281dae829915fbd1802c09269f7f5add5a886242eaa0d1ae362d329cc
Evidence Type Source Name Value Confidence Vendor pom url http://jsoup.org/ Highest Vendor pom organization name Jonathan Hedley High Vendor Manifest bundle-symbolicname org.jsoup Medium Vendor pom artifactid jsoup Low Vendor pom name jsoup High Vendor pom groupid jsoup Highest Vendor Manifest bundle-docurl http://jsoup.org/ Low Vendor pom description jsoup HTML parser Medium Vendor manifest Bundle-Description jsoup HTML parser Medium Vendor file name jsoup High Vendor pom organization url http://jonathanhedley.com/ Medium Product Manifest Bundle-Name jsoup Medium Product Manifest bundle-docurl http://jsoup.org/ Low Product pom description jsoup HTML parser Medium Product pom groupid jsoup Low Product pom organization url http://jonathanhedley.com/ Low Product file name jsoup High Product pom artifactid jsoup Highest Product pom organization name Jonathan Hedley Low Product Manifest bundle-symbolicname org.jsoup Medium Product pom name jsoup High Product pom url http://jsoup.org/ Medium Product manifest Bundle-Description jsoup HTML parser Medium Version pom version 1.7.2 Highest Version file version 1.7.2 Highest
cpe: cpe:/a:jsoup:jsoup:1.7.2 Confidence :Low suppress maven: org.jsoup:jsoup:1.7.2 Confidence :High Published Vulnerabilities CVE-2015-6748 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. Vulnerable Software & Versions:
jsr-275-0.9.3.jarDescription:
JSR-275 specifies Java packages for the programmatic handling
of physical quantities and their expression as numbers of units.
License:
Specification License: LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jsr-275-0.9.3.jar
MD5: e7a135baa55ec464055d75e4fd4d6b6f
SHA1: ab2fb094fc5297ae5636ef6ed0d6051d5a656588
SHA256: bab7f6456c79790362b0669aab20d511d3ad99dc22e020bafb5a708f2b18d78e
Evidence Type Source Name Value Confidence Vendor file name jsr-275 High Vendor pom organization name JScience High Vendor pom name JSR-275 High Vendor pom description JSR-275 specifies Java packages for the programmatic handling of physical quantities and their expression as numbers of units. Low Vendor Manifest bundle-symbolicname javax.measure Medium Vendor pom url https://kenai.com/projects/jsr-275 Highest Vendor pom artifactid jsr-275 Low Vendor pom groupid javax.measure Highest Vendor pom organization url http://jscience.org Medium Product file name jsr-275 High Product pom groupid javax.measure Low Product pom organization name JScience Low Product pom organization url http://jscience.org Low Product Manifest Implementation-Title JSR-275 High Product pom name JSR-275 High Product pom description JSR-275 specifies Java packages for the programmatic handling of physical quantities and their expression as numbers of units. Low Product pom url https://kenai.com/projects/jsr-275 Medium Product pom artifactid jsr-275 Highest Product Manifest bundle-symbolicname javax.measure Medium Product Manifest Bundle-Name Measures and Units Medium Version pom version 0.9.3 Highest Version Manifest Implementation-Version 0.9.3 High Version file version 0.9.3 Highest
maven: javax.measure:jsr-275:0.9.3 Confidence :High junrar-0.7.jarDescription:
rar decompression library in plain java License:
UnRar License: https://raw.github.com/junrar/junrar/master/license.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/junrar-0.7.jar
MD5: 75a215b9e921044cd2c88e73f6cb9745
SHA1: 18cc717b85af0b12ba922abf415c2ff4716f8219
SHA256: 7c764fa1af319b98ff452189ab31bb722ea74ed7a52b17b0c6282249c10a61fc
Evidence Type Source Name Value Confidence Vendor pom groupid github.junrar Highest Vendor pom url junrar/junrar Highest Vendor Manifest url https://github.com/junrar/junrar Low Vendor pom name Java UnRar High Vendor file name junrar High Vendor pom artifactid junrar Low Vendor pom description rar decompression library in plain java Medium Product pom artifactid junrar Highest Product pom url junrar/junrar High Product Manifest url https://github.com/junrar/junrar Low Product pom name Java UnRar High Product file name junrar High Product pom groupid github.junrar Low Product pom description rar decompression library in plain java Medium Version file version 0.7 Highest Version pom version 0.7 Highest
maven: com.github.junrar:junrar:0.7 Confidence :High jwnl-1.3.3.jarDescription:
JWNL is an API for accessing WordNet-style relational dictionaries. It also provides
functionality beyond data access, such as relationship discovery and morphological
processing.
License:
BSD 3-Clause License: http://jwordnet.svn.sourceforge.net/svnroot/jwordnet/trunk/jwnl/license.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jwnl-1.3.3.jar
MD5: 5332f834387eddf0206a48ba65b1e792
SHA1: 7108e5b6a8875fe0488d942238575407c7ab8649
SHA256: 3d0d84238717727ed66aa339907c2456e08d5dd01e1aa243f5d92811581c5830
Evidence Type Source Name Value Confidence Vendor pom description JWNL is an API for accessing WordNet-style relational dictionaries. It also provides functionality beyond data access, ... Low Vendor central groupid net.sf.jwordnet Highest Vendor file name jwnl High Vendor pom artifactid jwnl Low Vendor pom url http://jwordnet.sourceforge.net/ Highest Vendor pom groupid net.sf.jwordnet Highest Vendor jar package name jwnl Low Vendor jar package name net Low Vendor pom name Java WordNet Library High Vendor jar package name didion Low Product pom description JWNL is an API for accessing WordNet-style relational dictionaries. It also provides functionality beyond data access, ... Low Product pom url http://jwordnet.sourceforge.net/ Medium Product file name jwnl High Product central artifactid jwnl Highest Product pom groupid net.sf.jwordnet Low Product pom artifactid jwnl Highest Product jar package name jwnl Low Product pom name Java WordNet Library High Product jar package name didion Low Version file version 1.3.3 Highest Version pom version 1.3.3 Highest Version central version 1.3.3 Highest
maven-scm-api-1.4.jarDescription:
The SCM API provides mechanisms to manage all SCM tools. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/maven-scm-api-1.4.jarMD5: bc840a6620ec3d3c56ce58b10076cef4SHA1: e294693ce217bd6f470b728127854e6ca787fd29SHA256: 8603b43b7f6cd3d11785acd9f2d507ab6bdccda5cbd2c316a23979e7822fe64f
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.apache.maven.scm Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name maven-scm-api High Vendor Manifest Implementation-Vendor-Id org.apache.maven.scm Medium Vendor pom artifactid maven-scm-api Low Vendor pom description The SCM API provides mechanisms to manage all SCM tools. Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid maven-scm Low Vendor pom groupid apache.maven.scm Highest Vendor pom name Maven SCM API High Product file name maven-scm-api High Product Manifest Implementation-Title Maven SCM API High Product pom parent-groupid org.apache.maven.scm Low Product pom parent-artifactid maven-scm Medium Product pom description The SCM API provides mechanisms to manage all SCM tools. Medium Product pom artifactid maven-scm-api Highest Product Manifest specification-title Maven SCM API Medium Product pom groupid apache.maven.scm Low Product pom name Maven SCM API High Version pom version 1.4 Highest Version Manifest Implementation-Version 1.4 High Version file version 1.4 Highest
maven: org.apache.maven.scm:maven-scm-api:1.4 Confidence :High maven-scm-provider-svn-commons-1.4.jarDescription:
Common library for SCM SVN Provider. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/maven-scm-provider-svn-commons-1.4.jarMD5: 09e3cb24fa48c3d6427e1d2b79b42d26SHA1: 54bc1dc24c5d205b4d251a83f4ea63808c21a628SHA256: dfce4e5f3e5273df241f1848eaa7c18d73de766f127d4a6b5727193c4c30d40d
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.apache.maven.scm Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.scm Medium Vendor pom artifactid maven-scm-provider-svn-commons Low Vendor pom name Maven SCM Subversion Provider - Common library High Vendor pom parent-artifactid maven-scm-providers-svn Low Vendor file name maven-scm-provider-svn-commons High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom description Common library for SCM SVN Provider. Medium Vendor pom groupid apache.maven.scm Highest Product pom artifactid maven-scm-provider-svn-commons Highest Product pom parent-groupid org.apache.maven.scm Low Product pom name Maven SCM Subversion Provider - Common library High Product Manifest Implementation-Title Maven SCM Subversion Provider - Common library High Product file name maven-scm-provider-svn-commons High Product Manifest specification-title Maven SCM Subversion Provider - Common library Medium Product pom groupid apache.maven.scm Low Product pom parent-artifactid maven-scm-providers-svn Medium Product pom description Common library for SCM SVN Provider. Medium Version pom version 1.4 Highest Version Manifest Implementation-Version 1.4 High Version file version 1.4 Highest
maven: org.apache.maven.scm:maven-scm-provider-svn-commons:1.4 Confidence :High maven-scm-provider-svnexe-1.4.jarDescription:
Executable library for SCM SVN Provider. File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/maven-scm-provider-svnexe-1.4.jarMD5: 6624c9c3324f88619205c2b8c60e583bSHA1: b3213b40157b701ba079b738baac391e41418c18SHA256: 03580d8d7f8c0061bc784aaccdb9460c3dbd8a31c1944453fa30a98e2bd7d36d
Evidence Type Source Name Value Confidence Vendor file name maven-scm-provider-svnexe High Vendor pom parent-groupid org.apache.maven.scm Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.scm Medium Vendor pom name Maven SCM Subversion Provider - SVN Executable Impl. High Vendor pom parent-artifactid maven-scm-providers-svn Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.maven.scm Highest Vendor pom artifactid maven-scm-provider-svnexe Low Vendor pom description Executable library for SCM SVN Provider. Medium Product file name maven-scm-provider-svnexe High Product Manifest specification-title Maven SCM Subversion Provider - SVN Executable Impl. Medium Product pom parent-groupid org.apache.maven.scm Low Product pom name Maven SCM Subversion Provider - SVN Executable Impl. High Product pom artifactid maven-scm-provider-svnexe Highest Product pom groupid apache.maven.scm Low Product pom parent-artifactid maven-scm-providers-svn Medium Product Manifest Implementation-Title Maven SCM Subversion Provider - SVN Executable Impl. High Product pom description Executable library for SCM SVN Provider. Medium Version pom version 1.4 Highest Version Manifest Implementation-Version 1.4 High Version file version 1.4 Highest
maven: org.apache.maven.scm:maven-scm-provider-svnexe:1.4 Confidence :High metadata-extractor-2.8.0.jarDescription:
Java library for extracting EXIF, IPTC, XMP, ICC and other metadata from image files. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/metadata-extractor-2.8.0.jar
MD5: ad99c1e862666b05723da6d952d4df41
SHA1: c771dba842e459b704081212c66182eb351728de
SHA256: cad026495cb5c5bd92f4daf6ad278cb1f4db1ec76ff05f1530e6bb701c486edc
Evidence Type Source Name Value Confidence Vendor file name metadata-extractor High Vendor pom url https://drewnoakes.com/code/exif/ Highest Vendor pom name ${project.groupId}:${project.artifactId} High Vendor pom description Java library for extracting EXIF, IPTC, XMP, ICC and other metadata from image files. Medium Vendor pom groupid drewnoakes Highest Vendor pom artifactid metadata-extractor Low Vendor Manifest Implementation-Vendor Drew Noakes High Product file name metadata-extractor High Product pom groupid drewnoakes Low Product Manifest Implementation-Title metadata-extractor High Product pom artifactid metadata-extractor Highest Product pom name ${project.groupId}:${project.artifactId} High Product pom description Java library for extracting EXIF, IPTC, XMP, ICC and other metadata from image files. Medium Product pom url https://drewnoakes.com/code/exif/ Medium Version file version 2.8.0 Highest Version pom version 2.8.0 Highest Version Manifest Implementation-Version 2.8.0 High
cpe: cpe:/a:id:id-software:2.8.0 Confidence :Low suppress maven: com.drewnoakes:metadata-extractor:2.8.0 Confidence :High netcdf4-4.5.5.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/netcdf4-4.5.5.jarMD5: 5f14df469295650fd65748a003c9ba56SHA1: 0675d63ecc857c50dd50858011b670160aa30b62SHA256: 131e3983dcf001677be069a7471797a4a9ad2c9783e88db56e32506cf1039635
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor UCAR/Unidata High Vendor Manifest built-on 20150306.1537 Low Vendor pom name netCDF-4 IOSP JNI connection to C library High Vendor Manifest Implementation-Vendor-Id edu.ucar Medium Vendor pom parent-artifactid thredds-parent Low Vendor pom artifactid netcdf4 Low Vendor pom groupid edu.ucar Highest Vendor file name netcdf4 High Product Manifest Implementation-Title netCDF-4 IOSP JNI connection to C library High Product Manifest built-on 20150306.1537 Low Product pom name netCDF-4 IOSP JNI connection to C library High Product pom groupid edu.ucar Low Product pom artifactid netcdf4 Highest Product file name netcdf4 High Product pom parent-artifactid thredds-parent Medium Version file version 4.5.5 Highest Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
maven: edu.ucar:netcdf4:4.5.5 Confidence :High opennlp-maxent-3.0.3.jarDescription:
The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/opennlp-maxent-3.0.3.jar
MD5: 4fb8e129416ef5ef838d4aa77050d1bd
SHA1: 55e39e6b46e71f35229cdd6950e72d8cce3b5fd4
SHA256: 6e99fa57b1f3645b4992ab3cfaa8b24abca0921cf2f575d63fca43cd84dd44e6
Evidence Type Source Name Value Confidence Vendor pom artifactid opennlp-maxent Low Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor file name opennlp-maxent High Vendor pom groupid apache.opennlp Highest Vendor Manifest bundle-symbolicname org.apache.opennlp.maxent Medium Vendor pom parent-artifactid opennlp Low Vendor pom name Apache OpenNLP Maxent High Vendor manifest Bundle-Description The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. Low Vendor pom parent-groupid org.apache.opennlp Medium Product Manifest Bundle-Name Apache OpenNLP Maxent Medium Product pom parent-artifactid opennlp Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product pom parent-groupid org.apache.opennlp Low Product pom artifactid opennlp-maxent Highest Product file name opennlp-maxent High Product Manifest bundle-symbolicname org.apache.opennlp.maxent Medium Product pom name Apache OpenNLP Maxent High Product pom groupid apache.opennlp Low Product manifest Bundle-Description The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. Low Version file version 3.0.3 Highest Version pom version 3.0.3 Highest
maven: org.apache.opennlp:opennlp-maxent:3.0.3 Confidence :Highcpe: cpe:/a:apache:opennlp:3.0.3 Confidence :Low suppress opennlp-tools-1.5.3.jarDescription:
The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/opennlp-tools-1.5.3.jar
MD5: 2cd1835ad00c26fc978b691b52563afd
SHA1: 826d34168b0e4870c9f599ed7f2b8fee4194ba3b
SHA256: 5a7eae0b545ff517c8010440ccc4144cfcf83baac2b67a21a1af668e6022d5d2
Evidence Type Source Name Value Confidence Vendor file name opennlp-tools High Vendor Manifest Implementation-Vendor-Id org.apache.opennlp Medium Vendor pom artifactid opennlp-tools Low Vendor pom name Apache OpenNLP Tools High Vendor pom parent-artifactid opennlp Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor manifest Bundle-Description The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom parent-groupid org.apache.opennlp Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor pom groupid apache.opennlp Highest Vendor Manifest bundle-symbolicname org.apache.opennlp.tools Medium Product pom parent-artifactid opennlp Medium Product file name opennlp-tools High Product pom name Apache OpenNLP Tools High Product Manifest specification-title Apache OpenNLP Tools Medium Product manifest Bundle-Description The Apache Software Foundation provides support for the Apache community of open-source software projects. The Apache projects are characterized by a collaborative, consensus based development process, an open and pragmatic software license, and a desire to create high quality software that leads the way in its field. We consider ourselves not simply a group of projects sharing a server, but rather a community of developers and users. Low Product Manifest Implementation-Title Apache OpenNLP Tools High Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest Bundle-Name Apache OpenNLP Tools Medium Product Manifest bundle-docurl http://www.apache.org/ Low Product pom parent-groupid org.apache.opennlp Low Product pom artifactid opennlp-tools Highest Product pom groupid apache.opennlp Low Product Manifest bundle-symbolicname org.apache.opennlp.tools Medium Version file version 1.5.3 Highest Version pom version 1.5.3 Highest Version Manifest Implementation-Version 1.5.3 High
Published Vulnerabilities CVE-2017-12620 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected. Vulnerable Software & Versions: (show all )
parse-tika.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/parse-tika.jarMD5: 51185e4c129f63d83d8fdaf0b6e58113SHA1: 461cb552e2fea283143b18037b6b75dc27cf7eadSHA256: a91434236ec5f45f64ea6b29500e12c65e16f7e89b5eeb89b3170301a902c592
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor file name parse-tika High Vendor jar package name parse Low Vendor jar package name apache Low Product jar package name nutch Low Product file name parse-tika High Product jar package name parse Low Product jar package name tika Low
cpe: cpe:/a:apache:tika:- Confidence :Low suppress Published Vulnerabilities CVE-2016-6809 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization. Vulnerable Software & Versions:
pdfbox-1.8.10.jarDescription:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/pdfbox-1.8.10.jar
MD5: e597e15826739a22b262924f0f091a84
SHA1: bc5d1254495be36d0a3b3d6c35f88d05200b9311
SHA256: 71a7d23980ca386719d2e8dce79735b2d1ca066a1b122ff3f6129824de2c984d
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium Vendor pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium Vendor pom parent-artifactid pdfbox-parent Low Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor pom name Apache PDFBox High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.pdfbox Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name pdfbox High Vendor pom parent-groupid org.apache.pdfbox Medium Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium Vendor pom artifactid pdfbox Low Product Manifest bundle-symbolicname org.apache.pdfbox Medium Product pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium Product pom groupid apache.pdfbox Low Product pom parent-artifactid pdfbox-parent Medium Product pom name Apache PDFBox High Product pom artifactid pdfbox Highest Product Manifest Bundle-Name Apache PDFBox Medium Product Manifest Implementation-Title Apache PDFBox High Product pom parent-groupid org.apache.pdfbox Low Product file name pdfbox High Product Manifest bundle-docurl http://pdfbox.apache.org Low Product Manifest specification-title Apache PDFBox Medium Product manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium Version file version 1.8.10 Highest Version pom version 1.8.10 Highest Version Manifest Implementation-Version 1.8.10 High
Published Vulnerabilities CVE-2016-2175 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser. Vulnerable Software & Versions: (show all )
plexus-utils-1.5.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/plexus-utils-1.5.6.jarMD5: d6070c2e77ca56adafa953215ddf744bSHA1: 8fb6b798a4036048b3005e058553bf21a87802edSHA256: 6990ec1b05c978c9940ebf7ec1b4dd911d16c524ee9f4a386a14ec0b07016ab4
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom artifactid plexus-utils Low Vendor jar package name util Low Vendor file name plexus-utils High Vendor pom parent-artifactid plexus Low Vendor central groupid org.codehaus.plexus Highest Vendor jar package name codehaus Low Vendor pom url http://plexus.codehaus.org/plexus-utils Highest Vendor jar package name plexus Low Vendor pom groupid codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Product jar package name util Low Product pom groupid codehaus.plexus Low Product pom artifactid plexus-utils Highest Product file name plexus-utils High Product pom url http://plexus.codehaus.org/plexus-utils Medium Product pom parent-groupid org.codehaus.plexus Low Product jar package name plexus Low Product central artifactid plexus-utils Highest Product pom name Plexus Common Utilities High Version pom version 1.5.6 Highest Version central version 1.5.6 Highest Version file version 1.5.6 Highest
poi-3.13-beta1.jarDescription:
Apache POI - Java API To Access Microsoft Format Files License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/poi-3.13-beta1.jar
MD5: 2f25ed53588219bc3442428dd22a46db
SHA1: 98598dda21aba14833bc015d13eece2c0f49ca01
SHA256: b079a9950ddd151b34892866c6acb953fbe9bdb3639d5181b5198578a17df26e
Evidence Type Source Name Value Confidence Vendor central groupid org.apache.poi Highest Vendor pom groupid apache.poi Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name poi High Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium Vendor pom organization url http://www.apache.org/ Medium Vendor jar package name apache Low Vendor pom url http://poi.apache.org/ Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Apache POI High Vendor pom organization name Apache Software Foundation High Vendor pom description Apache POI - Java API To Access Microsoft Format Files Medium Vendor jar package name poi Low Vendor pom artifactid poi Low Product central artifactid poi Highest Product pom organization name Apache Software Foundation Low Product pom organization url http://www.apache.org/ Low Product pom artifactid poi Highest Product file name poi High Product Manifest Implementation-Title Apache POI High Product Manifest specification-title Apache POI Medium Product pom groupid apache.poi Low Product pom name Apache POI High Product pom description Apache POI - Java API To Access Microsoft Format Files Medium Product pom url http://poi.apache.org/ Medium Product jar package name poi Low Version pom version 3.13-beta1 Highest Version Manifest Implementation-Version 3.13-beta1 High Version central version 3.13-beta1 Highest
Related Dependencies poi-ooxml-3.13-beta1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/poi-ooxml-3.13-beta1.jar MD5: ae2fa7681e37f968a392fc90fac4ff83 SHA1: 33ce1843dcfaa5c401725ab78ffe7e1e97a04118 SHA256: 3b4e5ebd2b3bbbd11bbfc73f2c4d9026f75d5e5af2f52bf38ed2c2d5c004dda3 maven: org.apache.poi:poi-ooxml:3.13-beta1 ✓ poi-ooxml-schemas-3.13-beta1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/poi-ooxml-schemas-3.13-beta1.jar MD5: 0f75acb870cf54685d86c58a9c5cb2c7 SHA1: 00c3afc5f96a26a2a3e5712e5cd8c9f37cbd59e9 SHA256: 6a9946821556e55ee1684c313d08418928738f7c559c4a6cbfc668233f539f6b maven: org.apache.poi:poi-ooxml-schemas:3.13-beta1 ✓ poi-scratchpad-3.13-beta1.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/poi-scratchpad-3.13-beta1.jar MD5: f2d9b3904c33b6fdd4a7464170c8c514 SHA1: d989e67c3c01a29cdc244576f65f97f4b1befbbb SHA256: e07074c1b5a1b929b558eae9de4b9fcbb61fffc4d02edcea6b96b2e4099b9d95 maven: org.apache.poi:poi-scratchpad:3.13-beta1 ✓ Published Vulnerabilities CVE-2016-5000 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. Vulnerable Software & Versions:
CVE-2017-5644 suppress
Severity:High CVSS Score: 7.1 (AV:N/AC:M/Au:N/C:N/I:N/A:C) CWE: CWE-399 Resource Management Errors
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack. Vulnerable Software & Versions:
quartz-2.2.0.jarDescription:
Enterprise Job Scheduler License:
http://www.apache.org/licenses/LICENSE-2.0.txt
Apache Software License, Version 2.0 File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/quartz-2.2.0.jar
MD5: 56d748f33fa07cb50c86eb72f53141b5
SHA1: 2eb16fce055d5f3c9d65420f6fc4efd3a079a3d8
SHA256: ad9fbd38399b2c5c5931b9a9161ca07ec5ba916b22f4292bd9791259c5c1f1d6
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid quartz-parent Low Vendor Manifest bundle-docurl http://www.terracotta.org Low Vendor pom groupid quartz-scheduler Highest Vendor pom description Enterprise Job Scheduler Medium Vendor Manifest buildinfo-revision 2359 Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor pom parent-groupid org.quartz-scheduler Medium Vendor Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium Vendor Manifest buildinfo-timestamp 20130629-140504 Low Vendor Manifest terracotta-name quartz Medium Vendor file name quartz High Vendor pom artifactid quartz Low Vendor pom name quartz High Vendor Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.0 Low Vendor manifest Bundle-Description Enterprise Job Scheduler Medium Vendor manifest terracotta-description Enterprise Job Scheduler Medium Product Manifest bundle-docurl http://www.terracotta.org Low Product pom description Enterprise Job Scheduler Medium Product Manifest buildinfo-revision 2359 Low Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom parent-groupid org.quartz-scheduler Low Product Manifest Bundle-Name quartz Medium Product Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium Product Manifest buildinfo-timestamp 20130629-140504 Low Product Manifest terracotta-name quartz Medium Product file name quartz High Product pom groupid quartz-scheduler Low Product pom artifactid quartz Highest Product pom name quartz High Product Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.0 Low Product manifest Bundle-Description Enterprise Job Scheduler Medium Product manifest terracotta-description Enterprise Job Scheduler Medium Product pom parent-artifactid quartz-parent Medium Version pom version 2.2.0 Highest Version file version 2.2.0 Highest
maven: org.quartz-scheduler:quartz:2.2.0 Confidence :High regexp-1.3.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/regexp-1.3.jarMD5: 6dcdc325850e40b843cac2a25fb2121eSHA1: 973df2b78b67bcd3144c3dbbb88da691065a3f8dSHA256: 27998732ecd5745924644f891f41adaf73736fe259a0a20843979452574f0385
Evidence Type Source Name Value Confidence Vendor pom groupid regexp Highest Vendor pom artifactid regexp Low Vendor jar package name regexp Low Vendor file name regexp High Vendor central groupid regexp Highest Vendor jar package name apache Low Product pom groupid regexp Low Product jar package name regexp Low Product pom artifactid regexp Highest Product file name regexp High Product central artifactid regexp Highest Version central version 1.3 Highest Version file version 1.3 Highest Version pom version 1.3 Highest
rome-0.9.jarDescription:
All Roads Lead to ROME.
ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats.
Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0) and Atom 0.3 feeds.
Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another.
The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/rome-0.9.jar
MD5: 19589699b01c59ccb4d5e61e4c78b311
SHA1: dee2705dd01e79a5a96a17225f5a1ae30470bb18
SHA256: 89f6d95a52afdf448e7b278738fe79189ae26c8bc67da78db3230af0dd0754bd
Evidence Type Source Name Value Confidence Vendor pom artifactid rome Low Vendor pom organization url http://java.sun.com/ Medium Vendor pom groupid rome Highest Vendor pom name ROME, RSS and atOM utilitiEs for Java High Vendor pom url https://rome.dev.java.net/ Highest Vendor Manifest extension-name rome Medium Vendor pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0) and Atom 0.3 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low Vendor Manifest specification-vendor Sun Microsystems Low Vendor jar package name syndication Low Vendor pom organization name Sun Microsystems High Vendor Manifest Implementation-Vendor Sun Microsystems High Vendor jar package name feed Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor central groupid rome Highest Vendor file name rome High Product pom organization name Sun Microsystems Low Product Manifest Implementation-Title com.sun.syndication High Product pom name ROME, RSS and atOM utilitiEs for Java High Product Manifest extension-name rome Medium Product pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0) and Atom 0.3 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low Product jar package name syndication Low Product pom url https://rome.dev.java.net/ Medium Product jar package name feed Low Product central artifactid rome Highest Product Manifest specification-title Rss and atOM utilitiEs (ROME) Medium Product pom groupid rome Low Product pom organization url http://java.sun.com/ Low Product pom artifactid rome Highest Product file name rome High Version central version 0.9 Highest Version file version 0.9 Highest Version Manifest Implementation-Version 0.9 High Version pom version 0.9 Highest
sis-metadata-0.5.jarDescription:
Implementations of metadata derived from ISO 19115. This module provides both an implementation
of the metadata interfaces defined in GeoAPI, and a framework for handling those metadata through
Java reflection.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/sis-metadata-0.5.jar
MD5: 6d9ccec08cffd1ce52be1f9b50260cfc
SHA1: 1bbd65e52d27b61c64944b9275c44ccd79f267a7
SHA256: 57945d86f1755121de3f8f0361c23fc596be6bf4186342014a3f4f25f6417604
Evidence Type Source Name Value Confidence Vendor pom name Apache SIS metadata High Vendor file name sis-metadata High Vendor pom parent-artifactid core Low Vendor jar package name sis Low Vendor pom description Implementations of metadata derived from ISO 19115. This module provides both an implementation of the metadata interfaces defined in GeoAPI, and a framework for handling those metadata through Java reflection. Low Vendor Manifest implementation-url http://sis.apache.org/core/sis-metadata Low Vendor central groupid org.apache.sis.core Highest Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor Manifest bundle-docurl http://sis.apache.org/core/sis-metadata Low Vendor pom artifactid sis-metadata Low Vendor jar package name apache Low Vendor pom groupid apache.sis.core Highest Vendor pom parent-groupid org.apache.sis Medium Vendor Manifest bundle-symbolicname org.apache.sis.metadata Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor manifest Bundle-Description Implementations of metadata derived from ISO 19115. This module provides both an implementation of the metadata interfaces defined in GeoAPI, and a framework for handling those metadata through Java reflection. Low Vendor Manifest Implementation-Vendor-Id org.apache.sis.core Medium Vendor Manifest built-on 2015-02-05T18:42:58Z Low Vendor jar package name metadata Low Product pom name Apache SIS metadata High Product file name sis-metadata High Product jar package name sis Low Product pom parent-artifactid core Medium Product pom description Implementations of metadata derived from ISO 19115. This module provides both an implementation of the metadata interfaces defined in GeoAPI, and a framework for handling those metadata through Java reflection. Low Product Manifest implementation-url http://sis.apache.org/core/sis-metadata Low Product pom parent-groupid org.apache.sis Low Product Manifest bundle-docurl http://sis.apache.org/core/sis-metadata Low Product pom groupid apache.sis.core Low Product Manifest specification-title GeoAPI Medium Product Manifest bundle-symbolicname org.apache.sis.metadata Medium Product central artifactid sis-metadata Highest Product manifest Bundle-Description Implementations of metadata derived from ISO 19115. This module provides both an implementation of the metadata interfaces defined in GeoAPI, and a framework for handling those metadata through Java reflection. Low Product Manifest Implementation-Title Apache SIS metadata High Product pom artifactid sis-metadata Highest Product Manifest built-on 2015-02-05T18:42:58Z Low Product Manifest Bundle-Name Apache SIS metadata Medium Product jar package name metadata Low Version pom version 0.5 Highest Version Manifest Implementation-Version 0.5 High Version central version 0.5 Highest Version file version 0.5 Highest
sis-netcdf-0.5.jarDescription:
Bridge between NetCDF Climate and Forecast (CF) convention and ISO 19115 metadata.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/sis-netcdf-0.5.jar
MD5: 58f26afee7da53fa9ce07ef08ce7f306
SHA1: 2b416e4506caebe7df6dd21b878dae888e0eea39
SHA256: eb76dc565d2d75a401ba3a49a651f4da807939cde8e09bcb3ec30c5642541bdc
Evidence Type Source Name Value Confidence Vendor pom description
Bridge between NetCDF Climate and Forecast (CF) convention and ISO 19115 metadata.
Medium Vendor Manifest Implementation-Vendor-Id org.apache.sis.storage Medium Vendor jar package name internal Low Vendor Manifest bundle-symbolicname org.apache.sis.storage.netcdf Medium Vendor manifest Bundle-Description Bridge between NetCDF Climate and Forecast (CF) convention and ISO 19115 metadata. Medium Vendor jar package name sis Low Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor jar package name apache Low Vendor pom groupid apache.sis.storage Highest Vendor pom name Apache SIS NetCDF storage High Vendor pom parent-groupid org.apache.sis Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name sis-netcdf High Vendor pom artifactid sis-netcdf Low Vendor pom parent-artifactid storage Low Vendor central groupid org.apache.sis.storage Highest Vendor Manifest built-on 2015-02-05T18:42:58Z Low Vendor Manifest implementation-url http://sis.apache.org/storage/sis-netcdf Low Vendor Manifest bundle-docurl http://sis.apache.org/storage/sis-netcdf Low Product Manifest Implementation-Title Apache SIS NetCDF storage High Product jar package name netcdf Low Product central artifactid sis-netcdf Highest Product pom description
Bridge between NetCDF Climate and Forecast (CF) convention and ISO 19115 metadata.
Medium Product jar package name internal Low Product Manifest bundle-symbolicname org.apache.sis.storage.netcdf Medium Product manifest Bundle-Description Bridge between NetCDF Climate and Forecast (CF) convention and ISO 19115 metadata. Medium Product jar package name sis Low Product Manifest Bundle-Name Apache SIS NetCDF storage Medium Product pom parent-groupid org.apache.sis Low Product Manifest specification-title GeoAPI Medium Product pom name Apache SIS NetCDF storage High Product file name sis-netcdf High Product pom parent-artifactid storage Medium Product pom groupid apache.sis.storage Low Product pom artifactid sis-netcdf Highest Product Manifest built-on 2015-02-05T18:42:58Z Low Product Manifest implementation-url http://sis.apache.org/storage/sis-netcdf Low Product Manifest bundle-docurl http://sis.apache.org/storage/sis-netcdf Low Version pom version 0.5 Highest Version Manifest Implementation-Version 0.5 High Version central version 0.5 Highest Version file version 0.5 Highest
sis-referencing-0.5.jarDescription:
Implementations of Coordinate Reference Systems (CRS),
conversion and transformation services derived from ISO 19111.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/sis-referencing-0.5.jar
MD5: f63fe6facd76480205141db7d605f10a
SHA1: 377246c70fd858346fab8a0e554bed3b3cfcde70
SHA256: bcbf4ae0bcde58aacebc7d92b6293e6bffd2bb8523030adeadfeb5d17e14ca6e
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://sis.apache.org/core/sis-referencing Low Vendor pom parent-artifactid core Low Vendor jar package name sis Low Vendor pom description Implementations of Coordinate Reference Systems (CRS), conversion and transformation services derived from ISO 19111. Low Vendor central groupid org.apache.sis.core Highest Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor jar package name apache Low Vendor jar package name referencing Low Vendor pom groupid apache.sis.core Highest Vendor pom parent-groupid org.apache.sis Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name sis-referencing High Vendor manifest Bundle-Description Implementations of Coordinate Reference Systems (CRS), conversion and transformation services derived from ISO 19111. Low Vendor pom artifactid sis-referencing Low Vendor Manifest bundle-symbolicname org.apache.sis.referencing Medium Vendor Manifest Implementation-Vendor-Id org.apache.sis.core Medium Vendor Manifest bundle-docurl http://sis.apache.org/core/sis-referencing Low Vendor Manifest built-on 2015-02-05T18:42:58Z Low Vendor pom name Apache SIS referencing High Product Manifest implementation-url http://sis.apache.org/core/sis-referencing Low Product central artifactid sis-referencing Highest Product jar package name sis Low Product pom parent-artifactid core Medium Product pom description Implementations of Coordinate Reference Systems (CRS), conversion and transformation services derived from ISO 19111. Low Product pom parent-groupid org.apache.sis Low Product pom groupid apache.sis.core Low Product Manifest specification-title GeoAPI Medium Product jar package name referencing Low Product file name sis-referencing High Product manifest Bundle-Description Implementations of Coordinate Reference Systems (CRS), conversion and transformation services derived from ISO 19111. Low Product Manifest bundle-symbolicname org.apache.sis.referencing Medium Product Manifest Bundle-Name Apache SIS referencing Medium Product pom artifactid sis-referencing Highest Product Manifest bundle-docurl http://sis.apache.org/core/sis-referencing Low Product Manifest Implementation-Title Apache SIS referencing High Product Manifest built-on 2015-02-05T18:42:58Z Low Product pom name Apache SIS referencing High Version pom version 0.5 Highest Version Manifest Implementation-Version 0.5 High Version central version 0.5 Highest Version file version 0.5 Highest
sis-storage-0.5.jarDescription:
Provides the interfaces and base classes to be implemented by various storage formats.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/sis-storage-0.5.jar
MD5: 24b522892175ec483d4db474bcf7309f
SHA1: 29d1ea6422b68fbfe1f1702f122019ae376ee2c8
SHA256: 246b0faad5a5bcd8eb5750f2cbc03e38577f641246856e8412c2e53ed0395379
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.apache.sis.storage Medium Vendor jar package name internal Low Vendor file name sis-storage High Vendor manifest Bundle-Description Provides the interfaces and base classes to be implemented by various storage formats. Medium Vendor jar package name sis Low Vendor Manifest bundle-symbolicname org.apache.sis.storage Medium Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor jar package name apache Low Vendor pom groupid apache.sis.storage Highest Vendor pom name Apache SIS common storage High Vendor pom parent-groupid org.apache.sis Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://sis.apache.org/storage/sis-storage Low Vendor pom description
Provides the interfaces and base classes to be implemented by various storage formats.
Medium Vendor pom parent-artifactid storage Low Vendor central groupid org.apache.sis.storage Highest Vendor pom artifactid sis-storage Low Vendor Manifest built-on 2015-02-05T18:42:58Z Low Vendor Manifest implementation-url http://sis.apache.org/storage/sis-storage Low Product jar package name internal Low Product file name sis-storage High Product manifest Bundle-Description Provides the interfaces and base classes to be implemented by various storage formats. Medium Product jar package name sis Low Product Manifest bundle-symbolicname org.apache.sis.storage Medium Product pom artifactid sis-storage Highest Product pom parent-groupid org.apache.sis Low Product Manifest Bundle-Name Apache SIS common storage Medium Product Manifest specification-title GeoAPI Medium Product pom name Apache SIS common storage High Product Manifest bundle-docurl http://sis.apache.org/storage/sis-storage Low Product pom description
Provides the interfaces and base classes to be implemented by various storage formats.
Medium Product pom parent-artifactid storage Medium Product Manifest Implementation-Title Apache SIS common storage High Product pom groupid apache.sis.storage Low Product Manifest built-on 2015-02-05T18:42:58Z Low Product Manifest implementation-url http://sis.apache.org/storage/sis-storage Low Product central artifactid sis-storage Highest Product jar package name storage Low Version pom version 0.5 Highest Version Manifest Implementation-Version 0.5 High Version central version 0.5 Highest Version file version 0.5 Highest
sis-utility-0.5.jarDescription:
Miscellaneous utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/sis-utility-0.5.jar
MD5: d6b7770eb395a8c4bc3bf84c99563119
SHA1: aaea81deda0e3c7ca2602e7fb9459bcc19894ecf
SHA256: 0b912ef7ee6eebe8b20c4b0282a25a37cb744edf6cd9b4e8a09a8990488def9f
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Miscellaneous utilities. Medium Vendor pom parent-artifactid core Low Vendor jar package name sis Low Vendor Manifest bundle-docurl http://sis.apache.org/core/sis-utility Low Vendor central groupid org.apache.sis.core Highest Vendor Manifest specification-vendor Open Geospatial Consortium Low Vendor pom name Apache SIS utilities High Vendor file name sis-utility High Vendor jar package name apache Low Vendor pom description
Miscellaneous utilities.
Medium Vendor pom groupid apache.sis.core Highest Vendor pom parent-groupid org.apache.sis Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-url http://sis.apache.org/core/sis-utility Low Vendor pom artifactid sis-utility Low Vendor Manifest Implementation-Vendor-Id org.apache.sis.core Medium Vendor Manifest built-on 2015-02-05T18:42:58Z Low Vendor Manifest bundle-symbolicname org.apache.sis.utility Medium Product manifest Bundle-Description Miscellaneous utilities. Medium Product jar package name sis Low Product Manifest bundle-docurl http://sis.apache.org/core/sis-utility Low Product pom parent-artifactid core Medium Product pom parent-groupid org.apache.sis Low Product pom name Apache SIS utilities High Product pom groupid apache.sis.core Low Product pom artifactid sis-utility Highest Product file name sis-utility High Product Manifest specification-title GeoAPI Medium Product Manifest Bundle-Name Apache SIS utilities Medium Product pom description
Miscellaneous utilities.
Medium Product Manifest Implementation-Title Apache SIS utilities High Product Manifest implementation-url http://sis.apache.org/core/sis-utility Low Product central artifactid sis-utility Highest Product Manifest built-on 2015-02-05T18:42:58Z Low Product Manifest bundle-symbolicname org.apache.sis.utility Medium Version pom version 0.5 Highest Version Manifest Implementation-Version 0.5 High Version central version 0.5 Highest Version file version 0.5 Highest
slf4j-api-1.7.12.jarDescription:
The slf4j API File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/slf4j-api-1.7.12.jarMD5: 68910bf95dbcf90ce5859128f0f75d1eSHA1: 8e20852d05222dc286bf1c71d78d0531e177c317SHA256: 0aee9a77a4940d72932b0d0d9557793f872e66a03f598e473f45e7efecdccf99
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor pom artifactid slf4j-api Low Vendor pom description The slf4j API Medium Vendor pom url http://www.slf4j.org Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor manifest Bundle-Description The slf4j API Medium Vendor pom name SLF4J API Module High Vendor pom groupid slf4j Highest Vendor pom parent-groupid org.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom groupid slf4j Low Product pom description The slf4j API Medium Product pom parent-groupid org.slf4j Low Product pom artifactid slf4j-api Highest Product manifest Bundle-Description The slf4j API Medium Product pom name SLF4J API Module High Product pom url http://www.slf4j.org Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product file name slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Bundle-Name slf4j-api Medium Product Manifest Implementation-Title slf4j-api High Product pom parent-artifactid slf4j-parent Medium Version pom version 1.7.12 Highest Version file version 1.7.12 Highest Version Manifest Implementation-Version 1.7.12 High
cpe: cpe:/a:slf4j:slf4j:1.7.12 Confidence :Low suppress maven: org.slf4j:slf4j-api:1.7.12 Confidence :High tagsoup-1.2.1.jarDescription:
TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/tagsoup-1.2.1.jar
MD5: ae73a52cdcbec10cd61d9ef22fab5936
SHA1: 5584627487e984c03456266d3f8802eb85a9ce97
SHA256: ac97f7b4b1d8e9337edfa0e34044f8d0efe7223f6ad8f3a85d54cc1018ea2e04
Evidence Type Source Name Value Confidence Vendor pom artifactid tagsoup Low Vendor pom url http://home.ccil.org/~cowan/XML/tagsoup/ Highest Vendor file name tagsoup High Vendor jar package name tagsoup Low Vendor central groupid org.ccil.cowan.tagsoup Highest Vendor pom groupid ccil.cowan.tagsoup Highest Vendor pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low Vendor jar package name ccil Low Vendor jar package name cowan Low Vendor pom name TagSoup High Product central artifactid tagsoup Highest Product pom artifactid tagsoup Highest Product file name tagsoup High Product jar package name tagsoup Low Product pom groupid ccil.cowan.tagsoup Low Product pom url http://home.ccil.org/~cowan/XML/tagsoup/ Medium Product pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low Product jar package name cowan Low Product pom name TagSoup High Version pom version 1.2.1 Highest Version central version 1.2.1 Highest Version file version 1.2.1 Highest
tika-parsers-1.10.jarDescription:
Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/tika-parsers-1.10.jar
MD5: d1eb2e0d4f4f74f72cde7fb2b0ec8242
SHA1: a8c3c882eaadbf26e9c3195ae19650a45de183a3
SHA256: 8b08e6e83bd3e22bbd99be1e2697d7d52367ccd40415ae9993d6e367adc4bbdc
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. Low Vendor Manifest bundle-docurl http://tika.apache.org/ Low Vendor pom parent-artifactid tika-parent Low Vendor pom parent-groupid org.apache.tika Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache.tika Medium Vendor Manifest bundle-symbolicname org.apache.tika.parsers Medium Vendor pom artifactid tika-parsers Low Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.tika Highest Vendor pom organization url http://www.apache.org Medium Vendor pom url http://tika.apache.org/ Highest Vendor pom name Apache Tika parsers High Vendor file name tika-parsers High Product manifest Bundle-Description Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. Low Product Manifest bundle-docurl http://tika.apache.org/ Low Product Manifest Implementation-Title Apache Tika parsers High Product pom organization name The Apache Software Foundation Low Product Manifest specification-title Apache Tika parsers Medium Product pom groupid apache.tika Low Product Manifest bundle-symbolicname org.apache.tika.parsers Medium Product pom parent-groupid org.apache.tika Low Product pom url http://tika.apache.org/ Medium Product pom organization url http://www.apache.org Low Product pom artifactid tika-parsers Highest Product pom name Apache Tika parsers High Product pom parent-artifactid tika-parent Medium Product file name tika-parsers High Product Manifest Bundle-Name Apache Tika parsers Medium Version Manifest Implementation-Version 1.10 High Version pom version 1.10 Highest Version file version 1.10 Highest
Published Vulnerabilities CVE-2016-6809 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization. Vulnerable Software & Versions:
CVE-2018-1338 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
udunits-4.5.5.jarDescription:
The ucar.units Java package is for decoding and encoding
formatted unit specifications (e.g. "m/s"), converting numeric values
between compatible units (e.g. between "m/s" and "knot"), and for
performing arithmetic operations on units (e.g. dividing one unit by
another, raising a unit to a power). File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/udunits-4.5.5.jarMD5: 025ffadf77de73601443c8262c995df0SHA1: d8c8d65ade13666eedcf764889c69321c247f153SHA256: fb641ad901d1526d53f2b13bc86baec703c57d58e6001cfa54ca7734c97fb30d
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor UCAR/Unidata High Vendor pom description The ucar.units Java package is for decoding and encoding formatted unit specifications (e.g. "m/s"), converting numeric values between compatible units (e.g. between "m/s" and "knot"), and for performing arithmetic operations on units (e.g. dividing one unit by another, raising a unit to a power). Low Vendor Manifest built-on 20150306.1537 Low Vendor file name udunits High Vendor Manifest Implementation-Vendor-Id edu.ucar Medium Vendor pom artifactid udunits Low Vendor pom name udunits High Vendor pom parent-artifactid thredds-parent Low Vendor pom groupid edu.ucar Highest Vendor pom url http://www.unidata.ucar.edu/software/udunits// Highest Product Manifest Implementation-Title udunits High Product pom description The ucar.units Java package is for decoding and encoding formatted unit specifications (e.g. "m/s"), converting numeric values between compatible units (e.g. between "m/s" and "knot"), and for performing arithmetic operations on units (e.g. dividing one unit by another, raising a unit to a power). Low Product Manifest built-on 20150306.1537 Low Product pom artifactid udunits Highest Product file name udunits High Product pom url http://www.unidata.ucar.edu/software/udunits// Medium Product pom groupid edu.ucar Low Product pom name udunits High Product pom parent-artifactid thredds-parent Medium Version file version 4.5.5 Highest Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
maven: edu.ucar:udunits:4.5.5 Confidence :High vorbis-java-core-0.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/vorbis-java-core-0.6.jarMD5: 724a557bf19d77f362b41f2796be158cSHA1: 71deedbdfe6a1b0dcadd6c5ae335e3e9b427524cSHA256: 97924481cb27fc0fc6e5784d9d42ea5e21ada1ae703c88eb5d0bb8360b3b0b30
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid vorbis-java-parent Low Vendor pom groupid gagravarr Highest Vendor pom url Gagravarr/VorbisJava Highest Vendor jar package name gagravarr Low Vendor pom parent-groupid org.gagravarr Medium Vendor file name vorbis-java-core High Vendor pom artifactid vorbis-java-core Low Vendor pom name Ogg and Vorbis for Java, Core High Product pom artifactid vorbis-java-core Highest Product pom groupid gagravarr Low Product pom url Gagravarr/VorbisJava High Product pom parent-artifactid vorbis-java-parent Medium Product file name vorbis-java-core High Product pom parent-groupid org.gagravarr Low Product pom name Ogg and Vorbis for Java, Core High Version pom version 0.6 Highest Version file version 0.6 Highest
maven: org.gagravarr:vorbis-java-core:0.6 Confidence :High vorbis-java-tika-0.6.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/vorbis-java-tika-0.6.jarMD5: 9906a3a825381c64756962ebe99df47bSHA1: be5b08ff4c45632975646f286a1d13e325bec59aSHA256: 3bb42a03241f6a30e11308d53bdb64de8785328862714e07bcd41c76edd63016
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid vorbis-java-parent Low Vendor pom groupid gagravarr Highest Vendor pom name Apache Tika plugin for Ogg, Vorbis and FLAC High Vendor pom url Gagravarr/VorbisJava Highest Vendor jar package name gagravarr Low Vendor pom parent-groupid org.gagravarr Medium Vendor jar package name tika Low Vendor pom artifactid vorbis-java-tika Low Vendor file name vorbis-java-tika High Product pom name Apache Tika plugin for Ogg, Vorbis and FLAC High Product pom groupid gagravarr Low Product pom url Gagravarr/VorbisJava High Product pom parent-artifactid vorbis-java-parent Medium Product jar package name tika Low Product pom parent-groupid org.gagravarr Low Product pom artifactid vorbis-java-tika Highest Product file name vorbis-java-tika High Version pom version 0.6 Highest Version file version 0.6 Highest
cpe: cpe:/a:apache:tika:0.6 Confidence :Highest suppress cpe: cpe:/a:flac_project:flac:0.6 Confidence :Low suppress maven: org.gagravarr:vorbis-java-tika:0.6 Confidence :High Published Vulnerabilities CVE-2016-6809 suppress
Severity:High CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization. Vulnerable Software & Versions:
CVE-2017-6888 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file. Vulnerable Software & Versions:
CVE-2018-1338 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P) CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18. Vulnerable Software & Versions: (show all )
xmlbeans-2.6.0.jarDescription:
XmlBeans main jar License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
SHA256: c77974359688b2823b48fa9a33da68559d64f8474441480d9df4f9e254332a96
Evidence Type Source Name Value Confidence Vendor pom url http://xmlbeans.apache.org Highest Vendor pom organization url http://xmlbeans.apache.org/ Medium Vendor pom artifactid xmlbeans Low Vendor pom name XmlBeans High Vendor jar package name apache Low Vendor jar package name xmlbeans Low Vendor pom groupid apache.xmlbeans Highest Vendor pom organization name XmlBeans High Vendor pom description XmlBeans main jar Medium Vendor jar package name impl Low Vendor file name xmlbeans High Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor Apache Software Foundation Medium Vendor central groupid org.apache.xmlbeans Highest Product pom organization url http://xmlbeans.apache.org/ Low Product pom organization name XmlBeans Low Product pom groupid apache.xmlbeans Low Product manifest: org/apache/xmlbeans/ Implementation-Title org.apache.xmlbeans Medium Product pom name XmlBeans High Product jar package name xmlbeans Low Product pom description XmlBeans main jar Medium Product jar package name impl Low Product central artifactid xmlbeans Highest Product pom url http://xmlbeans.apache.org Medium Product file name xmlbeans High Product pom artifactid xmlbeans Highest Version file version 2.6.0 Highest Version central version 2.6.0 Highest Version pom version 2.6.0 Highest
xmpcore-5.1.2.jarDescription:
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
License:
The BSD License: http://www.adobe.com/devnet/xmp/library/eula-xmp-library-java.html File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/xmpcore-5.1.2.jar
MD5: 0b2cf2a09d32abdedd17de864e93ad25
SHA1: 55615fa2582424e38705487d1d3969af8554f637
SHA256: 0adcd63003aaff0a87b938f6accc2d890a2169c751a9b36881237f8546287090
Evidence Type Source Name Value Confidence Vendor pom artifactid xmpcore Low Vendor Manifest implementation-major 5 Low Vendor Manifest Implementation-Vendor Copyright 2006-2009 Adobe Systems Incorporated. All rights reserved High Vendor jar package name adobe Low Vendor Manifest implementation-engbuild 003 Low Vendor pom groupid adobe.xmp Highest Vendor Manifest implementation-micro 1 Low Vendor pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium Vendor Manifest builddate 2012 Jul 03 11:48:46-CEST Low Vendor jar package name impl Low Vendor jar package name xmp Low Vendor central groupid com.adobe.xmp Highest Vendor pom url http://www.adobe.com/devnet/xmp.html Highest Vendor file name xmpcore High Vendor pom name XMP Library for Java High Vendor Manifest implementation-minor 1 Low Product Manifest implementation-major 5 Low Product Manifest implementation-engbuild 003 Low Product central artifactid xmpcore Highest Product Manifest implementation-micro 1 Low Product pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium Product Manifest builddate 2012 Jul 03 11:48:46-CEST Low Product jar package name impl Low Product pom artifactid xmpcore Highest Product jar package name xmp Low Product file name xmpcore High Product pom groupid adobe.xmp Low Product Manifest Implementation-Title Adobe XMP Core High Product pom name XMP Library for Java High Product Manifest implementation-minor 1 Low Product pom url http://www.adobe.com/devnet/xmp.html Medium Version central version 5.1.2 Highest Version pom version 5.1.2 Highest Version file version 5.1.2 Highest
protocol-file.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-file/protocol-file.jarMD5: 3f26484ad5509f33e70507e0fc566194SHA1: 7af15ecdbd291f612b7fc7838720ab1ae674269dSHA256: f8c82c80b49ace7e45e140669cf759da1be019d4f1c4d8a9631feaba1c5e86f5
Evidence Type Source Name Value Confidence Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor file name protocol-file High Vendor jar package name apache Low Product jar package name protocol Low Product jar package name nutch Low Product file name protocol-file High Product jar package name file Low
commons-net-1.2.2.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-ftp/commons-net-1.2.2.jarMD5: 092ead7cc4989f3a14495f6006cf9d2fSHA1: 57a100f070def45b3161783235df6ba8c610ba17SHA256: 4a0232e659088776082f3b0af0ba28bca9531bb5a92276abc0a5344635ad5928
Evidence Type Source Name Value Confidence Vendor jar package name commons Low Vendor file name commons-net High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor central groupid commons-net Highest Vendor pom groupid commons-net Highest Vendor pom artifactid commons-net Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name net Low Vendor Manifest extension-name commons-net Medium Vendor jar package name apache Low Product jar package name commons Low Product file name commons-net High Product pom groupid commons-net Low Product Manifest Implementation-Title org.apache.commons.net High Product pom artifactid commons-net Highest Product jar package name net Low Product Manifest specification-title Jakarta Commons Net Medium Product central artifactid commons-net Highest Product Manifest extension-name commons-net Medium Version file version 1.2.2 Highest Version central version 1.2.2 Highest Version Manifest Implementation-Version 1.2.2 High Version pom version 1.2.2 Highest
protocol-ftp.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-ftp/protocol-ftp.jarMD5: 4f7fac6823776bfc7b21f752581f7a24SHA1: f22f2a0bbfff3f09776065fa030870c8ed096a2aSHA256: d94b6f64ea580e3c5481b19046355d4c2db55c2ddebf62e57dab74d26ce0b91c
Evidence Type Source Name Value Confidence Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor file name protocol-ftp High Vendor jar package name apache Low Product jar package name ftp Low Product jar package name protocol Low Product jar package name nutch Low Product file name protocol-ftp High
protocol-http.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-http/protocol-http.jarMD5: 7dba65a228e8d12c24c70466fdb7a168SHA1: a1dcc985b7bb2c9d51a9498aa6360fbff38c2962SHA256: 96bb1a5fcafcba443c682a26952134424dd3ac6df0ededf159102ad1565b229f
Evidence Type Source Name Value Confidence Vendor file name protocol-http High Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor jar package name apache Low Product file name protocol-http High Product jar package name http Low Product jar package name protocol Low Product jar package name nutch Low
protocol-httpclient.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-httpclient/protocol-httpclient.jarMD5: 96316f3ebc51f9bace0f6988b8a48559SHA1: 6421b2b63f055b8948213d7b7d94032eeada6b68SHA256: a3f03f3a8f0f10a5de231ca295d1f8fca80e62726087e8a5fae3f440bd9f11d7
Evidence Type Source Name Value Confidence Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor file name protocol-httpclient High Vendor jar package name apache Low Product jar package name httpclient Low Product jar package name protocol Low Product jar package name nutch Low Product file name protocol-httpclient High
cpe: cpe:/a:apache:httpclient:- Confidence :Low suppress jsch-0.1.41.jarDescription:
JSch is a pure Java implementation of SSH2 License:
BSD: http://www.jcraft.com/jsch/LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-sftp/jsch-0.1.41.jar
MD5: 5258a03131d0b0699e6371afa44891ce
SHA1: ddf7dd99e57004c9c871d35fd53943efef4bdb0e
SHA256: 18b2333b33b78e8853f317c6e7361ace239c30d3f2c9bdd41723da8d9085d4ea
Evidence Type Source Name Value Confidence Vendor file name jsch High Vendor jar package name jcraft Low Vendor pom url http://www.jcraft.com/jsch/ Highest Vendor pom groupid jcraft Highest Vendor central groupid com.jcraft Highest Vendor jar package name jsch Low Vendor pom artifactid jsch Low Vendor pom name JSch High Vendor pom description JSch is a pure Java implementation of SSH2 Medium Vendor pom organization name jcraft High Vendor pom organization url http://www.jcraft.com/jsch Medium Product file name jsch High Product jar package name jsch Low Product pom artifactid jsch Highest Product pom url http://www.jcraft.com/jsch/ Medium Product pom name JSch High Product pom description JSch is a pure Java implementation of SSH2 Medium Product central artifactid jsch Highest Product pom organization name jcraft Low Product pom organization url http://www.jcraft.com/jsch Low Product pom groupid jcraft Low Version file version 0.1.41 Highest Version pom version 0.1.41 Highest Version central version 0.1.41 Highest
Published Vulnerabilities CVE-2016-5725 suppress
Severity:Medium CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command. Vulnerable Software & Versions:
protocol-sftp.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/protocol-sftp/protocol-sftp.jarMD5: a72cf23be9ced0df077e0eb88b1cdc92SHA1: 32344efff196e72c5b66e0f0ad65c23a117a118fSHA256: 70e50783531db769a316ca15345c4e2ccc8c1b639842cd86f4ad051f5a177fc7
Evidence Type Source Name Value Confidence Vendor jar package name protocol Low Vendor jar package name nutch Low Vendor file name protocol-sftp High Vendor jar package name apache Low Product jar package name protocol Low Product jar package name nutch Low Product file name protocol-sftp High Product jar package name sftp Low
scoring-link.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/scoring-link/scoring-link.jarMD5: b517a0b9a3e0794d14049ffbf0b8b15fSHA1: 4acaa5d5e88edfdc6c69a0cde947e015bdca26c5SHA256: c1efdb612356bf1ff7b3ddea21165965dd39509dae2dbddbe3f1b41cd08081a8
Evidence Type Source Name Value Confidence Vendor jar package name scoring Low Vendor jar package name nutch Low Vendor file name scoring-link High Vendor jar package name apache Low Product jar package name scoring Low Product jar package name nutch Low Product file name scoring-link High Product jar package name link Low
scoring-opic.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/scoring-opic/scoring-opic.jarMD5: c29b4a9c9b0da02bce6dfc51b9785150SHA1: 6b45b7736b8ea3930aafe45b330ab2623f63aebaSHA256: bef9f9bff6aa64d34f8a748893eb0f0c2c025ae3046defa8afab53b8423e8e53
Evidence Type Source Name Value Confidence Vendor jar package name scoring Low Vendor jar package name nutch Low Vendor file name scoring-opic High Vendor jar package name apache Low Product jar package name scoring Low Product jar package name nutch Low Product file name scoring-opic High Product jar package name opic Low
subcollection.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/subcollection/subcollection.jarMD5: b82c1ad15af3420e1d5c90f46c32267bSHA1: e5df2de413b86d95003ac09122ff92f3757128b5SHA256: 1a22b589e9ff0956e8d74ff94a3b4b5106a3c02644486f3b78fc6676724bc4a3
Evidence Type Source Name Value Confidence Vendor file name subcollection High Vendor jar package name nutch Low Vendor jar package name apache Low Product file name subcollection High Product jar package name nutch Low Product jar package name subcollection Low
tld.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/tld/tld.jarMD5: 059e40effc86e03de9e4b4f6a1967d0eSHA1: 5529768148b70f3597037c8c979a75dd3de085ddSHA256: 3a3081dadb931f6bba02eff790280fb72a67b8ad64435d07eb83191ac82fa9b7
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor file name tld High Vendor jar package name apache Low Product jar package name nutch Low Product jar package name tld Low Product file name tld High
automaton-1.11-8.jarDescription:
A DFA/NFA (finite-state automata) implementation with
Unicode alphabet (UTF16) and support for the standard regular
expression operations (concatenation, union, Kleene star) and a number
of non-standard ones (intersection, complement, etc.) License:
BSD: http://www.opensource.org/licenses/bsd-license.php File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-automaton/automaton-1.11-8.jar
MD5: 3467dcbbba2fe68a4e07a5826988e034
SHA1: 6ebfa65eb431ff4b715a23be7a750cbc4cc96d0f
SHA256: a24475f6ccfe1cc7a4fe9e34e05ce687b0ce0c6e8cb781e0eced3b186482c61e
Evidence Type Source Name Value Confidence Vendor jar package name brics Low Vendor jar package name dk Low Vendor pom name Automaton High Vendor pom description A DFA/NFA (finite-state automata) implementation with Unicode alphabet (UTF16) and support for the standard regular expression operations (concatenation, union, Kleene star) and a number of non-standard ones (intersection, complement, etc.) Low Vendor pom artifactid automaton Low Vendor central groupid dk.brics.automaton Highest Vendor pom groupid dk.brics.automaton Highest Vendor jar package name automaton Low Vendor file name automaton High Vendor pom url http://www.brics.dk/automaton/ Highest Product jar package name brics Low Product central artifactid automaton Highest Product pom name Automaton High Product pom description A DFA/NFA (finite-state automata) implementation with Unicode alphabet (UTF16) and support for the standard regular expression operations (concatenation, union, Kleene star) and a number of non-standard ones (intersection, complement, etc.) Low Product pom url http://www.brics.dk/automaton/ Medium Product pom groupid dk.brics.automaton Low Product jar package name automaton Low Product file name automaton High Product pom artifactid automaton Highest Version pom version 1.11-8 Highest Version central version 1.11-8 Highest Version file version 1.11.8 Highest
urlfilter-automaton.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-automaton/urlfilter-automaton.jarMD5: 0f9aed027fec9ea84d7c78fcf0b64198SHA1: 2692c0ba1b7c73b1de762412f1db6f3c006daffaSHA256: e03af3bf3d5f71b9675e15eccec96b39fd0ac0baacc54bff7f50d4d8494c0584
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name urlfilter-automaton High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product file name urlfilter-automaton High Product jar package name automaton Low
urlfilter-domain.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-domain/urlfilter-domain.jarMD5: 68e5d801c1f46623c6730cd492352facSHA1: 8bbcc85c347106c98955266e25eec6f7f4f5e1ebSHA256: 034b4299242acc32e355d89ac23a6d2cdda34a42b62a1f44c15cb2e419525899
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name urlfilter-domain High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product jar package name domain Low Product file name urlfilter-domain High
urlfilter-prefix.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-prefix/urlfilter-prefix.jarMD5: 59613c91a5bf728791b949fd3f107eadSHA1: 379746262b6a619202db0a6cd4ae7701bbc0cd6cSHA256: 4c1b4af61857e755d5ee657550e2841dd2e87cb3a01fdc692f93dd3172eb71fe
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name urlfilter-prefix High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product file name urlfilter-prefix High Product jar package name prefix Low
urlfilter-regex.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-regex/urlfilter-regex.jarMD5: ba4bc98103125651c04e0eae41441746SHA1: a6f18dab3755d7792fe90b1fb89cd7f09c728561SHA256: 80e8c6c3795bf4c8405202209cf0e814e96bc0592b0e2fce8db257e860465d7a
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name urlfilter-regex High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product file name urlfilter-regex High Product jar package name regex Low
urlfilter-suffix.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-suffix/urlfilter-suffix.jarMD5: 95e25f1789c0b4f931717633b19a84eeSHA1: 84627556b6087085569cd42206ecf87f580730f8SHA256: 8615592b4c6d1de478e046b307fa722e6d504d66464678bd0e243d646b443c11
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor jar package name nutch Low Vendor file name urlfilter-suffix High Vendor jar package name apache Low Product jar package name urlfilter Low Product jar package name nutch Low Product file name urlfilter-suffix High Product jar package name suffix Low
urlfilter-validator.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlfilter-validator/urlfilter-validator.jarMD5: 293ebd7f0fae3daad3bf8ba2e5fbae18SHA1: 0b1a3ccb2d482c1cfadc9c1c4b27ad636b1f91f3SHA256: 7eb8041e52ed554403b229cd0a7f2d6e202e600bd7c74a65993a1a56395de3cc
Evidence Type Source Name Value Confidence Vendor jar package name urlfilter Low Vendor file name urlfilter-validator High Vendor jar package name nutch Low Vendor jar package name apache Low Product jar package name urlfilter Low Product file name urlfilter-validator High Product jar package name nutch Low Product jar package name validator Low
urlnormalizer-basic.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlnormalizer-basic/urlnormalizer-basic.jarMD5: 33aa32a908b82ad1230a9d433f2a4e3eSHA1: 88e5b2194ea8800b237e2bf925b60dff8891504bSHA256: 4ef12a339468564db921c3c28b0217857fd354995725a5d537b81bcda1e0bd4f
Evidence Type Source Name Value Confidence Vendor jar package name nutch Low Vendor jar package name net Low Vendor file name urlnormalizer-basic High Vendor jar package name apache Low Product jar package name nutch Low Product jar package name net Low Product jar package name urlnormalizer Low Product file name urlnormalizer-basic High
urlnormalizer-pass.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlnormalizer-pass/urlnormalizer-pass.jarMD5: dd568a8da7f999487b29bc52b3199520SHA1: 16f9cdb3cba71b22890e7b2e33f5e76e76bf8f45SHA256: 266d4c5c28bdc6481ffeff5f7de3b75d037ae14a2e27fe35a27e5ff9cc88848c
Evidence Type Source Name Value Confidence Vendor file name urlnormalizer-pass High Vendor jar package name nutch Low Vendor jar package name net Low Vendor jar package name apache Low Product file name urlnormalizer-pass High Product jar package name nutch Low Product jar package name net Low Product jar package name urlnormalizer Low
urlnormalizer-regex.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/urlnormalizer-regex/urlnormalizer-regex.jarMD5: 04b655c2d6e8711cb1d4dbfbdc9f80f7SHA1: 9d0f1b2e12778228377fa1d56bf593ef85733e8eSHA256: 42cdb6f5b90339253266b96caeeae520868f3588e5025792b8835c4fb4fe3160
Evidence Type Source Name Value Confidence Vendor file name urlnormalizer-regex High Vendor jar package name nutch Low Vendor jar package name net Low Vendor jar package name apache Low Product file name urlnormalizer-regex High Product jar package name nutch Low Product jar package name net Low Product jar package name urlnormalizer Low
leveldbjni-all-1.8.jar: leveldbjni.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/leveldbjni-all-1.8.jar/META-INF/native/windows32/leveldbjni.dllMD5: 551b9310a9ed358359296a89715df2f4SHA1: bba450e93688b872b3fcaa31e8457950e97d8429SHA256: 3cf3f6284f99acad369a15f0b4eca8e0dec2b0342651c519e4665570da8a68ee
Evidence Type Source Name Value Confidence Vendor file name leveldbjni High Product file name leveldbjni High
leveldbjni-all-1.8.jar: leveldbjni.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/leveldbjni-all-1.8.jar/META-INF/native/windows64/leveldbjni.dllMD5: 4b6fa20009ca1eb556e752671461a3f2SHA1: 978ca9c96c03eb220556ce5bc96c715f95a0967cSHA256: 7794f7bbc848d1a9ad98996f2c68a1cf12ac17562f646c6d7f5733404a7b5ef1
Evidence Type Source Name Value Confidence Vendor file name leveldbjni High Product file name leveldbjni High
snappy-java-1.1.1.3.jar: snappyjava.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/snappy-java-1.1.1.3.jar/org/xerial/snappy/native/Windows/x86/snappyjava.dllMD5: c35f7d232d05fd0b8440153cb4224a5aSHA1: 45b5f3fdd2bac156b8d100ce2c29ac7126454fefSHA256: 15fb95c2168bb78cf94f61bbff7fc0bb5611db9d8509dd1322a40d735c3109bc
Evidence Type Source Name Value Confidence Vendor file name snappyjava High Product file name snappyjava High
snappy-java-1.1.1.3.jar: snappyjava.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/snappy-java-1.1.1.3.jar/org/xerial/snappy/native/Windows/x86_64/snappyjava.dllMD5: eae816277d795d3397f08ad43d236576SHA1: 283068f6b5cd8bb3449867558624fe19c432d909SHA256: dfcc13605edabf70e7bec87f68bc2a1c7d06bebecd72a0d4e122eee2e695948e
Evidence Type Source Name Value Confidence Vendor file name snappyjava High Product file name snappyjava High
ehcache-core-2.6.2.jar: sizeof-agent.jarFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/ehcache-core-2.6.2.jar/net/sf/ehcache/pool/sizeof/sizeof-agent.jarMD5: 5ad919b3ac0516897bdca079c9a222a8SHA1: e86399a80ae6a6c7a563717eaa0ce9ba4708571cSHA256: 3bcd560ca5f05248db9b689244b043e9c7549e3791281631a64e5dfff15870d2
Evidence Type Source Name Value Confidence Vendor Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low Vendor pom name Ehcache Size-Of Agent High Vendor file name sizeof-agent High Vendor Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low Vendor Manifest hudson-build-number 6 Low Vendor Manifest jenkins-build-number 6 Low Vendor pom artifactid sizeof-agent Low Vendor pom url http://www.ehcache.org Highest Vendor pom groupid net.sf.ehcache Highest Vendor pom parent-artifactid ehcache-parent Low Product Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low Product pom url http://www.ehcache.org Medium Product pom name Ehcache Size-Of Agent High Product file name sizeof-agent High Product Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low Product Manifest hudson-build-number 6 Low Product pom artifactid sizeof-agent Highest Product pom groupid net.sf.ehcache Low Product pom parent-artifactid ehcache-parent Medium Product Manifest jenkins-build-number 6 Low Version Manifest jenkins-version 1.449 Medium Version Manifest hudson-version 1.449 Medium Version Manifest hudson-build-number 6 Low Version pom version 1.0.1 Highest Version Manifest jenkins-build-number 6 Low Version pom parent-version 1.0.1 Low
maven: net.sf.ehcache:sizeof-agent:1.0.1 Confidence :High jna-4.1.0.jar: jnidispatch.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jna-4.1.0.jar/com/sun/jna/w32ce-arm/jnidispatch.dllMD5: 57697cbdd321ae7d06f5da04e821f908SHA1: 67167f2b2fce8db5f9f64a372b0da54730d3ee51SHA256: 361e173e6e50cb1bf8b7fab38c1ff99686ea819e58ee30348e7756cb0418a9f6
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-4.1.0.jar: jnidispatch.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jna-4.1.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dllMD5: 06b2f1f909d2436dff20d7a668ef26a9SHA1: bd1bdda9a91f3b0d9067e323f7394bef933f81f6SHA256: e7864cb5509990ccf3f3d8a2ad1eaf41491ebb82df35408ee79957385d8355b3
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-4.1.0.jar: jnidispatch.dllFile Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/jna-4.1.0.jar/com/sun/jna/win32-x86/jnidispatch.dllMD5: 05a72ada9247aeb114a9ef01a394b6c4SHA1: 8b32cc82740fc62afdf5ea211f1ca8bb72269bbfSHA256: 12c6ecdab2cab372548ebf059548873a2f414a1b7b4389502702b7ab912f9a39
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
avro-1.8.1.jar (shaded: org.apache.avro:avro-guava-dependencies:1.8.1)Description:
Temporary artifact of guava dependencies File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/avro-1.8.1.jar/META-INF/maven/org.apache.avro/avro-guava-dependencies/pom.xmlMD5: f702a593866e70ed9e6c08f9c2c4b43bSHA1: 5cbe97248c4abd46b0f0ad1f9f6df89d6adcd844SHA256: 2bc58482748755d249fa47f0a7c0ecc211ae2c8888f8d8e1c756f6c510bfcf92
Evidence Type Source Name Value Confidence Vendor pom groupid apache.avro Highest Vendor pom parent-artifactid avro-parent Low Vendor pom description Temporary artifact of guava dependencies Medium Vendor pom url http://avro.apache.org Highest Vendor pom artifactid avro-guava-dependencies Low Vendor pom parent-groupid org.apache.avro Medium Vendor pom name Apache Avro Guava Dependencies High Product pom groupid apache.avro Low Product pom artifactid avro-guava-dependencies Highest Product pom description Temporary artifact of guava dependencies Medium Product pom parent-artifactid avro-parent Medium Product pom url http://avro.apache.org Medium Product pom parent-groupid org.apache.avro Low Product pom name Apache Avro Guava Dependencies High Version pom version 1.8.1 Highest
maven: org.apache.avro:avro-guava-dependencies:1.8.1 Confidence :High jackson-dataformat-yaml-2.2.3.jar (shaded: org.yaml:snakeyaml:1.10)Description:
YAML 1.1 parser and emitter for Java License:
Apache License Version 2.0: LICENSE.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/jackson-dataformat-yaml-2.2.3.jar/META-INF/maven/org.yaml/snakeyaml/pom.xml
MD5: 6110aafa6505696f38b74815a7b9dee1
SHA1: d903ee39e4fefb9feedeef5072b5b1865d8dac59
SHA256: 676deb1361bfbc306f8114067307b48a0d07849111decb96396fe9e3818b55a6
Evidence Type Source Name Value Confidence Vendor pom description YAML 1.1 parser and emitter for Java Medium Vendor pom groupid yaml Highest Vendor pom artifactid snakeyaml Low Vendor pom url http://www.snakeyaml.org Highest Vendor pom name SnakeYAML High Product pom description YAML 1.1 parser and emitter for Java Medium Product pom name SnakeYAML High Product pom groupid yaml Low Product pom artifactid snakeyaml Highest Product pom url http://www.snakeyaml.org Medium Version pom version 1.10 Highest
maven: org.yaml:snakeyaml:1.10 Confidence :High plexus-utils-1.5.6.jar (shaded: org.codehaus.plexus:plexus-interpolation:1.0)File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/plexus-utils-1.5.6.jar/META-INF/maven/org.codehaus.plexus/plexus-interpolation/pom.xmlMD5: 61795135733295c9aa438fda7b923db8SHA1: 1074eabfbcbfb0decfe6f9ed0541668e114b9311SHA256: 0749c012cf2271d466eb9aef9acc2e84c38a2a94d545e7108fd15302b21a1b82
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom artifactid plexus-interpolation Low Vendor pom parent-artifactid plexus Low Vendor pom name Plexus Interpolation API High Vendor pom groupid codehaus.plexus Highest Product pom artifactid plexus-interpolation Highest Product pom parent-artifactid plexus Medium Product pom groupid codehaus.plexus Low Product pom name Plexus Interpolation API High Product pom parent-groupid org.codehaus.plexus Low Version pom version 1.0 Highest Version pom parent-version 1.0 Low
maven: org.codehaus.plexus:plexus-interpolation:1.0 Confidence :High Suppressed Vulnerabilitiestika-core-1.10.jar Description:
This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also
includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/lib/tika-core-1.10.jar
MD5: 9fccc95cc1ef109c339a89215a26cbf9
SHA1: feeac0d2758775b721b5c3e700ce8e4f5c0d9eb2
SHA256: $enc.html($dependency.Sha255sum)
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl http://tika.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.tika.core Medium Vendor pom parent-artifactid tika-parent Low Vendor pom parent-groupid org.apache.tika Medium Vendor pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name tika-core High Vendor Manifest Implementation-Vendor-Id org.apache.tika Medium Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Apache Tika core High Vendor pom groupid apache.tika Highest Vendor manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Vendor pom organization url http://www.apache.org Medium Vendor pom url http://tika.apache.org/ Highest Vendor pom artifactid tika-core Low Product Manifest bundle-docurl http://tika.apache.org/ Low Product Manifest bundle-symbolicname org.apache.tika.core Medium Product pom organization name The Apache Software Foundation Low Product pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Product pom groupid apache.tika Low Product file name tika-core High Product pom artifactid tika-core Highest Product pom parent-groupid org.apache.tika Low Product pom url http://tika.apache.org/ Medium Product pom name Apache Tika core High Product pom organization url http://www.apache.org Low Product Manifest Implementation-Title Apache Tika core High Product manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low Product Manifest specification-title Apache Tika core Medium Product pom parent-artifactid tika-parent Medium Product Manifest Bundle-Name Apache Tika core Medium Version Manifest Implementation-Version 1.10 High Version pom version 1.10 Highest Version file version 1.10 Highest
Suppressed Vulnerabilities CVE-2018-1335 suppressed
Severity:High CVSS Score: 9.3 CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Notes: only applies to tika-server < 1.18
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18. Vulnerable Software & Versions: (show all )
tika-parsers-1.10.jar Description:
Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/tika-parsers-1.10.jar
MD5: d1eb2e0d4f4f74f72cde7fb2b0ec8242
SHA1: a8c3c882eaadbf26e9c3195ae19650a45de183a3
SHA256: $enc.html($dependency.Sha255sum)
Evidence Type Source Name Value Confidence Vendor manifest Bundle-Description Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. Low Vendor Manifest bundle-docurl http://tika.apache.org/ Low Vendor pom parent-artifactid tika-parent Low Vendor pom parent-groupid org.apache.tika Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache.tika Medium Vendor Manifest bundle-symbolicname org.apache.tika.parsers Medium Vendor pom artifactid tika-parsers Low Vendor pom organization name The Apache Software Foundation High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.tika Highest Vendor pom organization url http://www.apache.org Medium Vendor pom url http://tika.apache.org/ Highest Vendor pom name Apache Tika parsers High Vendor file name tika-parsers High Product manifest Bundle-Description Apache Tika is a toolkit for detecting and extracting metadata and structured text content from various documents using existing parser libraries. Low Product Manifest bundle-docurl http://tika.apache.org/ Low Product Manifest Implementation-Title Apache Tika parsers High Product pom organization name The Apache Software Foundation Low Product Manifest specification-title Apache Tika parsers Medium Product pom groupid apache.tika Low Product Manifest bundle-symbolicname org.apache.tika.parsers Medium Product pom parent-groupid org.apache.tika Low Product pom url http://tika.apache.org/ Medium Product pom organization url http://www.apache.org Low Product pom artifactid tika-parsers Highest Product pom name Apache Tika parsers High Product pom parent-artifactid tika-parent Medium Product file name tika-parsers High Product Manifest Bundle-Name Apache Tika parsers Medium Version Manifest Implementation-Version 1.10 High Version pom version 1.10 Highest Version file version 1.10 Highest
Suppressed Vulnerabilities CVE-2018-1335 suppressed
Severity:High CVSS Score: 9.3 CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Notes: only applies to tika-server < 1.18
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18. Vulnerable Software & Versions: (show all )
vorbis-java-tika-0.6.jar File Path: /mnt/data/wastl/proj/crawler/nutch/git/2.x/build/plugins/parse-tika/vorbis-java-tika-0.6.jarMD5: 9906a3a825381c64756962ebe99df47bSHA1: be5b08ff4c45632975646f286a1d13e325bec59aSHA256: $enc.html($dependency.Sha255sum)
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid vorbis-java-parent Low Vendor pom groupid gagravarr Highest Vendor pom name Apache Tika plugin for Ogg, Vorbis and FLAC High Vendor pom url Gagravarr/VorbisJava Highest Vendor jar package name gagravarr Low Vendor pom parent-groupid org.gagravarr Medium Vendor jar package name tika Low Vendor pom artifactid vorbis-java-tika Low Vendor file name vorbis-java-tika High Product pom name Apache Tika plugin for Ogg, Vorbis and FLAC High Product pom groupid gagravarr Low Product pom url Gagravarr/VorbisJava High Product pom parent-artifactid vorbis-java-parent Medium Product jar package name tika Low Product pom parent-groupid org.gagravarr Low Product pom artifactid vorbis-java-tika Highest Product file name vorbis-java-tika High Version pom version 0.6 Highest Version file version 0.6 Highest
Suppressed Vulnerabilities CVE-2018-1335 suppressed
Severity:High CVSS Score: 9.3 CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Notes: only applies to tika-server < 1.18
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18. Vulnerable Software & Versions: (show all )