Update dependency mysql:mysql-connector-java to v8 #5
Security Report
You have successfully remediated 10 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2023-22102Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/8.0.28/mysql-connector-java-8.0.28.jar Dependency Hierarchy: -> ❌ mysql-connector-java-8.0.28.jar (Vulnerable Library) |
8.3 | mysql-connector-java-8.0.28.jar | Upgrade to version: com.mysql:mysql-connector-j:8.2.0 | None | ||
CVE-2022-3509Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.11.4/protobuf-java-3.11.4.jar Dependency Hierarchy: -> mysql-connector-java-8.0.28.jar (Root Library) -> ❌ protobuf-java-3.11.4.jar (Vulnerable Library) |
7.5 | protobuf-java-3.11.4.jar | Upgrade to version: com.google.protobuf:protobuf-java:3.16.3,3.19.6,3.20.3,3.21.7 | None | ||
CVE-2022-3171Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.11.4/protobuf-java-3.11.4.jar Dependency Hierarchy: -> mysql-connector-java-8.0.28.jar (Root Library) -> ❌ protobuf-java-3.11.4.jar (Vulnerable Library) |
7.5 | protobuf-java-3.11.4.jar | Upgrade to version: com.google.protobuf:protobuf-java:3.16.3,3.19.6,3.20.3,3.21.7;com.google.protobuf:protobuf-javalite:3.16.3,3.19.6,3.20.3,3.21.7;com.google.protobuf:protobuf-kotlin:3.19.6,3.20.3,3.21.7;com.google.protobuf:protobuf-kotlin-lite:3.19.6,3.20.3,3.21.7;google-protobuf - 3.19.6,3.20.3,3.21.7 | None | ||
CVE-2021-22569Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.11.4/protobuf-java-3.11.4.jar Dependency Hierarchy: -> mysql-connector-java-8.0.28.jar (Root Library) -> ❌ protobuf-java-3.11.4.jar (Vulnerable Library) |
5.5 | protobuf-java-3.11.4.jar | Upgrade to version: com.google.protobuf:protobuf-java:3.16.1,3.18.2,3.19.2; com.google.protobuf:protobuf-kotlin:3.18.2,3.19.2; google-protobuf - 3.19.2 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-22102 | mysql-connector-java-5.1.25.jar |
CVE-2019-2692 | mysql-connector-java-5.1.25.jar |
CVE-2020-2875 | mysql-connector-java-5.1.25.jar |
CVE-2017-3523 | mysql-connector-java-5.1.25.jar |
CVE-2015-2575 | mysql-connector-java-5.1.25.jar |
CVE-2017-3589 | mysql-connector-java-5.1.25.jar |
CVE-2020-2934 | mysql-connector-java-5.1.25.jar |
CVE-2017-3586 | mysql-connector-java-5.1.25.jar |
CVE-2022-21363 | mysql-connector-java-5.1.25.jar |
CVE-2020-2933 | mysql-connector-java-5.1.25.jar |
Base branch total remaining vulnerabilities: 62
Base branch commit: 5b8ed4e3a8b0defc42d5ba86d3aab1fbc4b73e0c
Total libraries scanned: 37
Scan token: 405dcf75b15f4dab8bdaefe4077264d1