Update dependency org.apache.calcite:calcite-core to v1.37.0 #2
Security Report
You have successfully remediated 27 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2024-7254Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar Dependency Hierarchy: -> calcite-core-1.37.0.jar (Root Library) -> calcite-linq4j-1.37.0.jar -> avatica-core-1.25.0.jar -> ❌ protobuf-java-3.21.9.jar (Vulnerable Library) |
7.5 | Transitive protobuf-java-3.21.9.jar |
calcite-core-1.37.0.jar | Transitive com.google.protobuf:protobuf-javalite:3.25.5,com.google.protobuf:protobuf-kotlin:4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-java:3.25.5,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin:4.28.2,google-protobuf - 4.27.5,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-kotlin:3.25.5,google-protobuf - 4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,google-protobuf - 3.25.5,com.google.protobuf:protobuf-kotlin-lite:3.25.5 |
None | ||
CVE-2024-57699Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar Dependency Hierarchy: -> calcite-core-1.37.0.jar (Root Library) -> json-path-2.9.0.jar -> ❌ json-smart-2.5.0.jar (Vulnerable Library) |
7.5 | Transitive json-smart-2.5.0.jar |
calcite-core-1.37.0.jar | Transitive 2.5.2 |
None | ||
CVE-2025-48924Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar Dependency Hierarchy: -> calcite-core-1.37.0.jar (Root Library) -> uzaygezen-core-0.2.jar -> ❌ commons-lang3-3.13.0.jar (Vulnerable Library) |
5.3 | Transitive commons-lang3-3.13.0.jar |
calcite-core-1.37.0.jar | Transitive 3.18.0 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2021-44832 | log4j-core-2.13.2.jar |
| CVE-2021-4104 | log4j-1.2.17.jar |
| WS-2019-0379 | commons-codec-1.12.jar |
| CVE-2023-1370 | json-smart-2.3.jar |
| CVE-2020-8908 | guava-23.0.jar |
| CVE-2025-48924 | commons-lang3-3.8.jar |
| CVE-2017-18640 | snakeyaml-1.24.jar |
| CVE-2023-26464 | log4j-1.2.17.jar |
| CVE-2025-52999 | jackson-core-2.10.0.jar |
| CVE-2022-38751 | snakeyaml-1.24.jar |
| CVE-2022-41854 | snakeyaml-1.24.jar |
| CVE-2022-38749 | snakeyaml-1.24.jar |
| CVE-2022-42004 | jackson-databind-2.10.0.jar |
| CVE-2022-38750 | snakeyaml-1.24.jar |
| CVE-2020-13956 | httpclient-4.5.9.jar |
| CVE-2022-38752 | snakeyaml-1.24.jar |
| CVE-2021-27568 | json-smart-2.3.jar |
| CVE-2022-36364 | avatica-core-1.17.0.jar |
| CVE-2021-29425 | commons-io-2.4.jar |
| CVE-2024-47554 | commons-io-2.4.jar |
| CVE-2023-51074 | json-path-2.4.0.jar |
| CVE-2020-9488 | log4j-1.2.17.jar |
| CVE-2022-39135 | calcite-core-1.26.0.jar |
| WS-2020-0287 | commons-dbcp2-2.6.0.jar |
| CVE-2019-17571 | log4j-1.2.17.jar |
| CVE-2020-9493 | log4j-1.2.17.jar |
| CVE-2022-42003 | jackson-databind-2.10.0.jar |
Base branch total remaining vulnerabilities: 38
Base branch commit: null
Total libraries scanned: 54
Scan token: b0e43ed0fc2e41968620ab5c0c916748