Find, fix and prevent vulnerabilities in your code.
high severity
new
- Vulnerable module: org.apache.httpcomponents.client5:httpclient5
- Introduced through: io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 and io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1
Detailed paths
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › io.dropwizard.metrics:metrics-httpclient5@4.2.28 › org.apache.httpcomponents.client5:httpclient5@5.4.1
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.apache.httpcomponents.client5:httpclient5@5.4.1Remediation: Upgrade to io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1.
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.apache.httpcomponents.client5:httpclient5@5.4.1Remediation: Upgrade to io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1.
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.apache.httpcomponents.client5:httpclient5-fluent@5.4.1 › org.apache.httpcomponents.client5:httpclient5@5.4.1Remediation: Upgrade to io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1.
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.apache.httpcomponents.client5:httpclient5-fluent@5.4.1 › org.apache.httpcomponents.client5:httpclient5@5.4.1Remediation: Upgrade to io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1.
…and 2 more
Overview
org.apache.httpcomponents.client5:httpclient5 is a HttpClient component of the Apache HttpComponents project.
Affected versions of this package are vulnerable to Improper Certificate Validation due to a bug in the validation logic of the Public Suffix List, which allows attackers to manipulate cookie management and host name verification, leading to unauthorized access or information disclosure.
Remediation
Upgrade org.apache.httpcomponents.client5:httpclient5
to version 5.4.3 or higher.
References
medium severity
- Module: ch.qos.logback:logback-classic
- Introduced through: org.springframework.boot:spring-boot-starter-actuator@3.4.5, org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 and others
Detailed paths
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-actuator@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-validation@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-web@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › org.springframework.boot:spring-boot-starter-actuator@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-client@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-web@3.4.5 › org.springframework.boot:spring-boot-starter-json@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-embedding-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-image-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-tool@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-retry@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18
…and 11 more
Dual license: EPL-1.0, LGPL-2.1
medium severity
- Module: ch.qos.logback:logback-core
- Introduced through: org.springframework.boot:spring-boot-starter-actuator@3.4.5, org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 and others
Detailed paths
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-actuator@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-validation@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-web@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-actuator@1.1.1 › org.springframework.boot:spring-boot-starter-actuator@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › io.github.springboot-addons:spring-boot-starter-httpclient5-resilience4j@1.1.1 › io.github.springboot-addons:spring-boot-starter-httpclient5@1.1.1 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-client@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.boot:spring-boot-starter-web@3.4.5 › org.springframework.boot:spring-boot-starter-json@3.4.5 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-embedding-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-image-observation@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-tool@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-retry@1.0.0-M7 › org.springframework.boot:spring-boot-starter@3.4.5 › org.springframework.boot:spring-boot-starter-logging@3.4.5 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
…and 11 more
Dual license: EPL-1.0, LGPL-2.1
medium severity
- Module: junit:junit
- Introduced through: org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7
Detailed paths
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-client@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-embedding-observation@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-image-observation@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-tool@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-observation@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-retry@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
…and 7 more
EPL-1.0 license
low severity
- Vulnerable module: junit:junit
- Introduced through: org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7
Detailed paths
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-client@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-embedding-observation@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-image-observation@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-tool@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-chat-observation@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-retry@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
-
Introduced through: pacphi/spring-ai-openrouter-example@pacphi/spring-ai-openrouter-example#92ec4bc8a3b39581f872ec2a04cd55704a5d98aa › org.springframework.ai:spring-ai-starter-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-autoconfigure-model-openai@1.0.0-M7 › org.springframework.ai:spring-ai-openai@1.0.0-M7 › org.springframework.ai:spring-ai-retry@1.0.0-M7 › org.springframework.ai:spring-ai-client-chat@1.0.0-M7 › org.springframework.ai:spring-ai-model@1.0.0-M7 › org.antlr:ST4@4.3.4 › org.antlr:antlr-runtime@3.5.3 › junit:junit@4.13
…and 7 more
Overview
junit:junit is an unit testing framework for Java
Affected versions of this package are vulnerable to Information Exposure. The JUnit4 test rule TemporaryFolder
contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system.
Note: This vulnerability does not allow other users to overwrite the contents of these directories or files. This only affects Unix like systems.
Remediation
Upgrade junit:junit
to version 4.13.1 or higher.