Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: SolarEdge

org.flasby:solaredge:1.0-SNAPSHOT

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
j2mod-3.2.1.jarcpe:2.3:a:steve_project:steve:3.2.1:*:*:*:*:*:*:*pkg:maven/com.ghgande/j2mod@3.2.1 0Low64
jSerialComm-2.10.4.jarcpe:2.3:a:fazecast:jserialcomm:2.10.4:*:*:*:*:*:*:*pkg:maven/com.fazecast/jSerialComm@2.10.4 0Low30
jSerialComm-2.10.4.jar: jSerialComm.dll 02
jSerialComm-2.10.4.jar: jSerialComm.dll 02
jSerialComm-2.10.4.jar: jSerialComm.dll 02
jSerialComm-2.10.4.jar: jSerialComm.dll 02
jackson-core-2.18.3.jarcpe:2.3:a:fasterxml:jackson-modules-java8:2.18.3:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.3 0Low47
jackson-databind-2.17.2.jarcpe:2.3:a:fasterxml:jackson-databind:2.17.2:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.17.2:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.2 0Highest41
jamod-1.2.jarpkg:maven/net.wimpi/jamod@1.2 036
logback-core-1.5.16.jarcpe:2.3:a:qos:logback:1.5.16:*:*:*:*:*:*:*pkg:maven/ch.qos.logback/logback-core@1.5.16 0Highest39
lombok-1.18.36.jarpkg:maven/org.projectlombok/lombok@1.18.36 036
lombok-1.18.36.jar: mavenEcjBootstrapAgent.jar 07
org.eclipse.paho.client.mqttv3-1.2.5.jarcpe:2.3:a:eclipse:paho_java_client:1.2.5:*:*:*:*:*:*:*pkg:maven/org.eclipse.paho/org.eclipse.paho.client.mqttv3@1.2.5 0Highest32
rxtx-2.1.7.jarpkg:maven/org.rxtx/rxtx@2.1.7 016
slf4j-api-2.0.17.jarpkg:maven/org.slf4j/slf4j-api@2.0.17 029

Dependencies (vulnerable)

j2mod-3.2.1.jar

Description:

A Modbus TCP/UDP/Serial Master and Slave implementation

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/lib/jenkins/.m2/repository/com/ghgande/j2mod/3.2.1/j2mod-3.2.1.jar
MD5: 5bfeb9f916235bf93edbdfcdfedb5ed5
SHA1: 7c93c1e05b3c71a430b2c9363864c42292566a1b
SHA256:d33bdb39c6505c11873d0c5c90b4993626cc37ebd4abc3c5fa1aca3eab8d53e2
Referenced In Project/Scope: SolarEdge:compile
j2mod-3.2.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.flasby/solaredge@1.0-SNAPSHOT

Identifiers

jSerialComm-2.10.4.jar

Description:

A platform-independent serial communications library for Java.

License:

GNU Lesser GPL, Version 3: http://www.gnu.org/licenses/lgpl.html
Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /var/lib/jenkins/.m2/repository/com/fazecast/jSerialComm/2.10.4/jSerialComm-2.10.4.jar
MD5: 46cd1207d1d4ed59f9b41161b5927480
SHA1: c817941580159787741a85a53d1834e39b536dee
SHA256:d472dcf3668c36f61f0470b83b0f166055425cd7d743efe5e245758826552850
Referenced In Project/Scope: SolarEdge:compile
jSerialComm-2.10.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.ghgande/j2mod@3.2.1

Identifiers

jSerialComm-2.10.4.jar: jSerialComm.dll

File Path: /var/lib/jenkins/.m2/repository/com/fazecast/jSerialComm/2.10.4/jSerialComm-2.10.4.jar/Windows/aarch64/jSerialComm.dll
MD5: b17fcb28a9b23a6f8f8ae00d65c0c7f9
SHA1: cc11b605910e11f8999a8ce04e8855aff46dec9a
SHA256:e5543a6fa5ce80db261af1575b4b01691332cda5af210c1e4232bf2db41add5f
Referenced In Project/Scope: SolarEdge:compile

Identifiers

  • None

jSerialComm-2.10.4.jar: jSerialComm.dll

File Path: /var/lib/jenkins/.m2/repository/com/fazecast/jSerialComm/2.10.4/jSerialComm-2.10.4.jar/Windows/armv7/jSerialComm.dll
MD5: fe69d5d7a117f1e1247c92ed562c2da5
SHA1: 1f71cc45de9ed2c9864ac131316227e2b870210e
SHA256:84e75064b28e10d0e537f59c341477995fe2d1b7e1cb5ce5fdf7b2fa76f64873
Referenced In Project/Scope: SolarEdge:compile

Identifiers

  • None

jSerialComm-2.10.4.jar: jSerialComm.dll

File Path: /var/lib/jenkins/.m2/repository/com/fazecast/jSerialComm/2.10.4/jSerialComm-2.10.4.jar/Windows/x86/jSerialComm.dll
MD5: ab595635a9c1883659ddf76fec5a62d8
SHA1: 7bea3c61f9681f6c07352ebd5d5ea4b4ce6bb9e0
SHA256:fe4900e7ec67c9aebf9efa4ddcebc2fb82f93eb991a705e2fa32653b9889902d
Referenced In Project/Scope: SolarEdge:compile

Identifiers

  • None

jSerialComm-2.10.4.jar: jSerialComm.dll

File Path: /var/lib/jenkins/.m2/repository/com/fazecast/jSerialComm/2.10.4/jSerialComm-2.10.4.jar/Windows/x86_64/jSerialComm.dll
MD5: d499b64ac9e02976619f5f2ef4d8d417
SHA1: 1cec87fe201662319ffa654913b4d89fbc9d10d3
SHA256:500357c37ac6e7e007c5b87263200f04c067b3d363f380620551e2919ce281e8
Referenced In Project/Scope: SolarEdge:compile

Identifiers

  • None

jackson-core-2.18.3.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/lib/jenkins/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.18.3/jackson-core-2.18.3.jar
MD5: b36e17ef5ba214242b700f8e621e6f12
SHA1: 78f80c259268200e588aa204dd97ecf09b76916e
SHA256:056bc4d3e5e53ce821450fa97b3f9e0f8dde125cf6da6884353bb1f09582e1d9
Referenced In Project/Scope: SolarEdge:compile
jackson-core-2.18.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.2

Identifiers

jackson-databind-2.17.2.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/lib/jenkins/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.17.2/jackson-databind-2.17.2.jar
MD5: 3e1ff7c1f0fda885946619a47ef9d5de
SHA1: e6deb029e5901e027c129341fac39e515066b68c
SHA256:c04993f33c0f845342653784f14f38373d005280e6359db5f808701cfae73c0c
Referenced In Project/Scope: SolarEdge:compile
jackson-databind-2.17.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.flasby/solaredge@1.0-SNAPSHOT

Identifiers

jamod-1.2.jar

Description:

        jamod is an object oriented implementation of the Modbus protocol, realized 100% in Java. It allows to quickly
        realize master and slave applications in various transport flavors (IP and serial).
    

License:

Apache 2 Style License: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/lib/jenkins/.m2/repository/net/wimpi/jamod/1.2/jamod-1.2.jar
MD5: ac632e9abca35ec6aef76b2e855e4813
SHA1: fbc12201cf6682f2635a270948f2fe305cb747f7
SHA256:1e69937fe17a3758df89adcba2852cac2da8e891878e5a4a739873c2e5390fbf
Referenced In Project/Scope: SolarEdge:compile
jamod-1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.flasby/solaredge@1.0-SNAPSHOT

Identifiers

logback-core-1.5.16.jar

Description:

logback-core module

License:

http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /var/lib/jenkins/.m2/repository/ch/qos/logback/logback-core/1.5.16/logback-core-1.5.16.jar
MD5: e850016bab60c8adb79242bcc4bb50e4
SHA1: 4f17700f046900aea2fadf115e2d67fec921f7fd
SHA256:f15e206b98ca25294506d2dadfe5ce2a6da9df9cf7c85d8e7191f99a422df3c9
Referenced In Project/Scope: SolarEdge:compile
logback-core-1.5.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/ch.qos.logback/logback-classic@1.5.16

Identifiers

lombok-1.18.36.jar

Description:

Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: /var/lib/jenkins/.m2/repository/org/projectlombok/lombok/1.18.36/lombok-1.18.36.jar
MD5: 92c08153ae16c161c8cc2cc8185d2724
SHA1: 5a30490a6e14977d97d9c73c924c1f1b5311ea95
SHA256:73b6b05b6a2d365b700bab08d30f94de9d336490bc0acce5b6181fef48cbf18e
Referenced In Project/Scope: SolarEdge:provided
lombok-1.18.36.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.flasby/solaredge@1.0-SNAPSHOT

Identifiers

lombok-1.18.36.jar: mavenEcjBootstrapAgent.jar

File Path: /var/lib/jenkins/.m2/repository/org/projectlombok/lombok/1.18.36/lombok-1.18.36.jar/lombok/launch/mavenEcjBootstrapAgent.jar
MD5: 27467519bf9615b24cad3b003c4353a9
SHA1: 37d92e0a726a67883ab94bee27c6f292e6318dcd
SHA256:9566d0706d6245cac3cdd9db6d1d81551aa3e727febcf64452c6db9701c40037
Referenced In Project/Scope: SolarEdge:provided

Identifiers

  • None

org.eclipse.paho.client.mqttv3-1.2.5.jar

File Path: /var/lib/jenkins/.m2/repository/org/eclipse/paho/org.eclipse.paho.client.mqttv3/1.2.5/org.eclipse.paho.client.mqttv3-1.2.5.jar
MD5: eb09d20835460ad2de7b6d46e77ad113
SHA1: 1546cfc794449c39ad569853843a930104fdc297
SHA256:59914287adac506a28d5e8172eed262a22605f3df4d426b9d92f41dae2448185
Referenced In Project/Scope: SolarEdge:compile
org.eclipse.paho.client.mqttv3-1.2.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.flasby/solaredge@1.0-SNAPSHOT

Identifiers

rxtx-2.1.7.jar

Description:

RXTX is a native lib providing serial and parallel communication for the Java Development Toolkit (JDK).

License:

GNU Lesser General Public License as published by the Free Software Foundation; either version 2.1 of the License, or (at your option) any later version.: http://www.fsf.org/licensing/licenses/lgpl.html
File Path: /var/lib/jenkins/.m2/repository/org/rxtx/rxtx/2.1.7/rxtx-2.1.7.jar
MD5: f94e90a2030310fc882f814b8f7eccc6
SHA1: e96c946be1e6537378fd532d2742b523df2725a4
SHA256:80c06c307be9c54ecf02cf10db921f42f1809087e85f2f1f772a80b282f326cc
Referenced In Project/Scope: SolarEdge:compile
rxtx-2.1.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.wimpi/jamod@1.2

Identifiers

slf4j-api-2.0.17.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: /var/lib/jenkins/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256:7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: SolarEdge:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.ghgande/j2mod@3.2.1

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.