[Backport 2.6] Logback 1.4.12 in performance test project to fix CVE-2023-6378 #3811
Mend for GitHub.com / WhiteSource Security Check
failed
Dec 6, 2023 in 10m 47s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-6481Path to dependency file: /performance-test/build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.4.12/670c77fc6e71cbb24dfabc9fc125f7536ed7a4ab/logback-core-1.4.12.jar Dependency Hierarchy: -> ❌ logback-core-1.4.12.jar (Vulnerable Library) |
High | 7.1 | logback-core-1.4.12.jar | Upgrade to version: ch.qos.logback:logback-core:1.2.13,1.3.14,1.4.14 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-6378 | logback-classic-1.2.12.jar |
Base branch total remaining vulnerabilities: 7
Base branch commit: ea8e33016b55bca29b4e2f467a95a61746ee83b8
Total libraries scanned: 1050
Scan token: 6e34694d54b945838cab9eb93635c55f
Loading