Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: jTrust Library

be.fedict.jtrust:jtrust-lib:2.1.0

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
bcpkix-jdk15on-1.70.jarcpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.70:*:*:*:*:*:*:*pkg:maven/org.bouncycastle/bcpkix-jdk15on@1.70 0Low66
bcprov-jdk15on-1.70.jarcpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.70:*:*:*:*:*:*:*
cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.70:*:*:*:*:*:*:*
cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.70:*:*:*:*:*:*:*
cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.70:*:*:*:*:*:*:*
cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.70:*:*:*:*:*:*:*
pkg:maven/org.bouncycastle/bcprov-jdk15on@1.70 0Low60
bcutil-jdk15on-1.70.jarcpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.70:*:*:*:*:*:*:*pkg:maven/org.bouncycastle/bcutil-jdk15on@1.70 0Low50
commons-codec-1.15.jarpkg:maven/commons-codec/commons-codec@1.15 0108
commons-io-2.11.0.jarcpe:2.3:a:apache:commons_io:2.11.0:*:*:*:*:*:*:*pkg:maven/commons-io/commons-io@2.11.0 0Highest123
httpclient5-5.2.1.jarcpe:2.3:a:apache:httpclient:5.2.1:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1 0Highest30
httpcore5-5.2.jarpkg:maven/org.apache.httpcomponents.core5/httpcore5@5.2 030
httpcore5-h2-5.2.jarpkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.2 030
slf4j-api-1.7.36.jarpkg:maven/org.slf4j/slf4j-api@1.7.36 029

Dependencies

bcpkix-jdk15on-1.70.jar

Description:

The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /Users/fcorneli/.m2/repository/org/bouncycastle/bcpkix-jdk15on/1.70/bcpkix-jdk15on-1.70.jar
MD5: 2c383f50d41937eae4fd32c35d8668cd
SHA1: f81e5af49571a9d5a109a88f239a73ce87055417
SHA256:e5b9cb821df57f70b0593358e89c0e8d7266515da9d088af6c646f63d433c07c
Referenced In Project/Scope: jTrust Library:compile
bcpkix-jdk15on-1.70.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers

bcprov-jdk15on-1.70.jar

Description:

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 and up.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /Users/fcorneli/.m2/repository/org/bouncycastle/bcprov-jdk15on/1.70/bcprov-jdk15on-1.70.jar
MD5: 1809d0449a6374279c01fdd3be26cd92
SHA1: 4636a0d01f74acaf28082fb62b317f1080118371
SHA256:8f3c20e3e2d565d26f33e8d4857a37d0d7f8ac39b62a7026496fcab1bdac30d4
Referenced In Project/Scope: jTrust Library:compile
bcprov-jdk15on-1.70.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers

  • pkg:maven/org.bouncycastle/bcprov-jdk15on@1.70  (Confidence:High)
  • cpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.70:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.70:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.70:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.70:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.70:*:*:*:*:*:*:*  (Confidence:Low)  

bcutil-jdk15on-1.70.jar

Description:

The Bouncy Castle Java APIs for ASN.1 extension and utility APIs used to support bcpkix and bctls. This jar contains APIs for JDK 1.5 and up.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /Users/fcorneli/.m2/repository/org/bouncycastle/bcutil-jdk15on/1.70/bcutil-jdk15on-1.70.jar
MD5: 805173dfb0891331dbe69d0e53371af4
SHA1: 54280e7195a7430d7911ded93fc01e07300b9526
SHA256:52dc5551b0257666526c5095424567fed7dc7b00d2b1ba7bd52298411112b1d0
Referenced In Project/Scope: jTrust Library:compile
bcutil-jdk15on-1.70.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.bouncycastle/bcpkix-jdk15on@1.70

Identifiers

commons-codec-1.15.jar

Description:

     The Apache Commons Codec package contains simple encoder and decoders for
     various formats such as Base64 and Hexadecimal.  In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/fcorneli/.m2/repository/commons-codec/commons-codec/1.15/commons-codec-1.15.jar
MD5: 303baf002ce6d382198090aedd9d79a2
SHA1: 49d94806b6e3dc933dacbd8acb0fdbab8ebd1e5d
SHA256:b3e9f6d63a790109bf0d056611fbed1cf69055826defeb9894a71369d246ed63
Referenced In Project/Scope: jTrust Library:compile
commons-codec-1.15.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers

commons-io-2.11.0.jar

Description:

The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/fcorneli/.m2/repository/commons-io/commons-io/2.11.0/commons-io-2.11.0.jar
MD5: 3b4b7ccfaeceeac240b804839ee1a1ca
SHA1: a2503f302b11ebde7ebc3df41daebe0e4eea3689
SHA256:961b2f6d87dbacc5d54abf45ab7a6e2495f89b75598962d8c723cea9bc210908
Referenced In Project/Scope: jTrust Library:compile
commons-io-2.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers

httpclient5-5.2.1.jar

Description:

Apache HttpComponents Client

File Path: /Users/fcorneli/.m2/repository/org/apache/httpcomponents/client5/httpclient5/5.2.1/httpclient5-5.2.1.jar
MD5: fbbefc687f2e0c55b34b77edf53d486a
SHA1: 0c900514d3446d9ce5d9dbd90c21192048125440
SHA256:9355f3876baf82fec13ced22c12b62d57536230836406d359459128e4f73ed51
Referenced In Project/Scope: jTrust Library:compile
httpclient5-5.2.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers

httpcore5-5.2.jar

Description:

Apache HttpComponents HTTP/1.1 core components

File Path: /Users/fcorneli/.m2/repository/org/apache/httpcomponents/core5/httpcore5/5.2/httpcore5-5.2.jar
MD5: 3a40241f9a99cf063f347dfb73c5c4e8
SHA1: ab7d251b8dfa3f2878f1eefbcca0e1fc0ebeba27
SHA256:293321cbf594d79ea8a0cb0214f75f146d17f088be17ad5ce11c2fe864df124c
Referenced In Project/Scope: jTrust Library:compile
httpcore5-5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1

Identifiers

httpcore5-h2-5.2.jar

Description:

Apache HttpComponents HTTP/2 Core Components

File Path: /Users/fcorneli/.m2/repository/org/apache/httpcomponents/core5/httpcore5-h2/5.2/httpcore5-h2-5.2.jar
MD5: 272112133e0dd0559efdd8f5e615a344
SHA1: 698bd8c759ccc7fd7398f3179ff45d0e5a7ccc16
SHA256:5a087fb8c619979d492a83546f351ddadf32b28cc6a32923229f3fc777171578
Referenced In Project/Scope: jTrust Library:compile
httpcore5-h2-5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1

Identifiers

slf4j-api-1.7.36.jar

Description:

The slf4j API

File Path: /Users/fcorneli/.m2/repository/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jar
MD5: 872da51f5de7f3923da4de871d57fd85
SHA1: 6c62681a2f655b49963a5983b8b0950a6120ae14
SHA256:d3ef575e3e4979678dc01bf1dcce51021493b4d11fb7f1be8ad982877c16a1c0
Referenced In Project/Scope: jTrust Library:compile
slf4j-api-1.7.36.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/be.fedict.jtrust/jtrust-lib@2.1.0

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.