Update dependency com.sparkjava:spark-core to v2.9.4 (master) #17
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
You have successfully remediated 38 vulnerabilities, but introduced 12 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2023-36478Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
7.5 | Not Defined | 1.456% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.53.v20231009 |
None | ||
CVE-2026-2332Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
7.4 | Not Defined | 0.019% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.60 |
None | ||
CVE-2024-13009Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
7.2 | Not Defined | 0.554% | Transitive jetty-server-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.57.v20241219 |
None | ||
CVE-2024-8184Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
5.9 | Not Defined | 1.13% | Transitive jetty-server-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.55.v20240627 |
None | ||
CVE-2023-40167Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
5.3 | Not Defined | 4.959% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.52.v20230823 |
None | ||
CVE-2023-26048Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
5.3 | Not Defined | 41.634% | Transitive jetty-server-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.51.v20230217 |
None | ||
WS-2023-0236Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-xml/9.4.48.v20220622/2c8b7ad6b64437a693cd30666f3def666aac8207/jetty-xml-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> jetty-webapp-9.4.48.v20220622.jar -> ❌ jetty-xml-9.4.48.v20220622.jar (Vulnerable Library) |
3.9 | Not Defined | Transitive jetty-xml-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.52.v20230823 |
None | |||
CVE-2025-11143Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
3.7 | Not Defined | 0.145% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive org.eclipse.jetty:jetty-http:12.0.31,org.eclipse.jetty:jetty-http:12.1.5 |
None | ||
CVE-2024-6763Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
3.7 | Not Defined | 1.074% | Transitive jetty-server-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.57.v20241219 |
None | ||
CVE-2024-6763Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
3.7 | Not Defined | 1.074% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.57.v20241219 |
None | ||
CVE-2023-26049Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.48.v20220622/8cb235e70bda0c5e97a41e7ee0ea33ee7f5bcc6a/jetty-http-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> websocket-server-9.4.48.v20220622.jar -> ❌ jetty-http-9.4.48.v20220622.jar (Vulnerable Library) |
2.4 | Not Defined | 0.371% | Transitive jetty-http-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.51.v20230217 |
None | ||
CVE-2023-26049Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.48.v20220622/b91a0641cda31c93962503b88f783602d2bd8093/jetty-server-9.4.48.v20220622.jar Dependency Hierarchy: -> spark-core-2.9.4.jar (Root Library) -> ❌ jetty-server-9.4.48.v20220622.jar (Vulnerable Library) |
2.4 | Not Defined | 0.371% | Transitive jetty-server-9.4.48.v20220622.jar |
spark-core-2.9.4.jar | Transitive 9.4.51.v20230217 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2021-28169 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-9735 | jetty-util-9.4.4.v20170414.jar |
| CVE-2026-2332 | jetty-http-9.4.4.v20170414.jar |
| CVE-2017-7658 | jetty-http-9.4.4.v20170414.jar |
| CVE-2021-28165 | jetty-server-9.4.4.v20170414.jar |
| CVE-2019-10241 | jetty-servlet-9.4.4.v20170414.jar |
| CVE-2023-26049 | jetty-http-9.4.4.v20170414.jar |
| CVE-2023-36478 | jetty-http-9.4.4.v20170414.jar |
| CVE-2024-6763 | jetty-http-9.4.4.v20170414.jar |
| CVE-2019-10241 | jetty-server-9.4.4.v20170414.jar |
| CVE-2020-27218 | jetty-server-9.4.4.v20170414.jar |
| CVE-2019-10246 | jetty-server-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-client-9.4.4.v20170414.jar |
| CVE-2023-26049 | jetty-server-9.4.4.v20170414.jar |
| CVE-2025-11143 | jetty-http-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-servlet-9.4.4.v20170414.jar |
| CVE-2021-28169 | jetty-http-9.4.4.v20170414.jar |
| CVE-2019-10241 | jetty-util-9.4.4.v20170414.jar |
| CVE-2024-6763 | jetty-server-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-http-9.4.4.v20170414.jar |
| CVE-2017-9735 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-7656 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-7657 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-12538 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-server-9.4.4.v20170414.jar |
| CVE-2024-8184 | jetty-server-9.4.4.v20170414.jar |
| CVE-2018-12545 | jetty-server-9.4.4.v20170414.jar |
| CVE-2020-27216 | jetty-webapp-9.4.4.v20170414.jar |
| WS-2023-0236 | jetty-xml-9.4.4.v20170414.jar |
| CVE-2017-7657 | jetty-http-9.4.4.v20170414.jar |
| CVE-2024-13009 | jetty-server-9.4.4.v20170414.jar |
| CVE-2017-7656 | jetty-http-9.4.4.v20170414.jar |
| CVE-2018-12536 | jetty-util-9.4.4.v20170414.jar |
| CVE-2023-26048 | jetty-server-9.4.4.v20170414.jar |
| CVE-2021-34428 | jetty-server-9.4.4.v20170414.jar |
| CVE-2022-2047 | jetty-server-9.4.4.v20170414.jar |
| CVE-2023-40167 | jetty-http-9.4.4.v20170414.jar |
| CVE-2021-28165 | jetty-io-9.4.4.v20170414.jar |
Base branch total remaining vulnerabilities: 94
Base branch commit: null
Total libraries scanned: 42
Scan token: 77b5b34fdb114153917b96b51fa43f9c