[Backport 2.x] bump logback to 1.5.16 #1004
Security Report
4 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
WS-2022-0468Path to dependency file: /core-spi/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar Dependency Hierarchy: -> framework-2.20.0-SNAPSHOT.jar (Root Library) -> opensearch-rest-client-sniffer-2.20.0-SNAPSHOT.jar -> ❌ jackson-core-2.11.4.jar (Vulnerable Library) |
7.5 | jackson-core-2.11.4.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 | None | |
WS-2022-0468Path to dependency file: /core-spi/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar Dependency Hierarchy: -> opensearch-2.20.0-SNAPSHOT.jar (Root Library) -> opensearch-core-2.20.0-SNAPSHOT.jar -> ❌ jackson-core-2.11.4.jar (Vulnerable Library) |
7.5 | jackson-core-2.11.4.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 | None | |
WS-2021-0616Path to dependency file: /core-spi/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar Dependency Hierarchy: -> framework-2.20.0-SNAPSHOT.jar (Root Library) -> opensearch-rest-client-sniffer-2.20.0-SNAPSHOT.jar -> ❌ jackson-core-2.11.4.jar (Vulnerable Library) |
5.9 | jackson-core-2.11.4.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 | None | |
WS-2021-0616Path to dependency file: /core-spi/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar Dependency Hierarchy: -> opensearch-2.20.0-SNAPSHOT.jar (Root Library) -> opensearch-core-2.20.0-SNAPSHOT.jar -> ❌ jackson-core-2.11.4.jar (Vulnerable Library) |
5.9 | jackson-core-2.11.4.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: 61c9b3bc4ed1129f392bf0625a0cc8f9228d3412
Total libraries scanned: 223
Scan token: 86a8ec33e13843f68c6a950ef4c930c7