Update dependency org.hibernate:hibernate-validator to v6 (main) - #249
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle,sbt,php. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
gradle
/tmp/ws-scm/comms-router/test/demo-helper/play-helper/build.gradle
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | failed running mend init script (mendDeps): NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED FAILURE: Build failed with an exception. * Where: Build file '/tmp/ws-scm/comms-router/test/demo-helper/play-helper/build.gradle' line: 2 * What went wrong: Plugin [id: 'play'] was not found in any o... |
https://vonagecc.jfrog.io/artifactory
| Step | Level | Description | Details |
|---|---|---|---|
| Checking registry connectivity | ⚠Warn | Problem occurred while connecting to the private registry host server, private registry returned 401 - Unauthorized | {"errors":[{"code":"UNAUTHORIZED","message":"Invalid token, parse"}]} |
https://vonagecc.jfrog.io/artifactory/maven
| Step | Level | Description | Details |
|---|---|---|---|
| Checking registry connectivity | ⚠Warn | Problem occurred while connecting to the private registry host server, private registry returned 401 - Unauthorized | {"errors":[{"code":"UNAUTHORIZED","message":"Invalid token, parse"}]} |
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2020-10693Path to dependency file: /core-interface/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.0.Alpha1/hibernate-validator-6.0.0.Alpha1.jar Dependency Hierarchy: -> ❌ hibernate-validator-6.0.0.Alpha1.jar (Vulnerable Library) |
5.3 | Not Defined | 0.094% | Direct hibernate-validator-6.0.0.Alpha1.jar |
hibernate-validator-6.0.0.Alpha1.jar | 6.0.20.Final | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-35036 | hibernate-validator-5.4.1.Final.jar |
| CVE-2020-10693 | hibernate-validator-5.4.1.Final.jar |
Base branch total remaining vulnerabilities: 198
Base branch commit: 4e5656db54be4b22481fe3774c2caeba51bac190
Total libraries scanned: 235
Scan token: f3a35f76fa554083a39eb1ecaf9fe0ef