Skip to content

Instantly share code, notes, and snippets.

@cmdcolin
Created December 11, 2021 23:04
Show Gist options
  • Save cmdcolin/df8e92fe3e82fb2856b5c08d90bf4a32 to your computer and use it in GitHub Desktop.
Save cmdcolin/df8e92fe3e82fb2856b5c08d90bf4a32 to your computer and use it in GitHub Desktop.
apollo 2.6.6 security scan
Using grype security scanner
https://github.com/anchore/grype
$ grype apollo-2.6.6-SNAPSHOT.war
✔ Vulnerability DB [updated]
✔ Indexed apollo-2.6.6-SNAPSHOT.war
✔ Cataloged packages [227 packages]
✔ Scanned image [292 vulnerabilities]
NAME INSTALLED FIXED-IN VULNERABILITY SEVERITY
commons-beanutils 1.8.3 1.9.2 GHSA-p66x-2cv9-qq3v High
commons-beanutils 1.8.3 1.9.4 GHSA-6phf-73q6-gh87 High
commons-beanutils 1.8.3 CVE-2014-0114 High
commons-beanutils 1.8.3 CVE-2019-10086 High
commons-codec 1.2 CVE-2013-1907 Medium
commons-codec 1.2 CVE-2013-1908 Medium
commons-collections 3.2.1 3.2.2 GHSA-6hgm-866r-3cjv High
commons-collections 3.2.1 CVE-2015-6420 High
commons-collections 3.2.1 CVE-2017-15708 Critical
commons-compress 1.18 1.19 GHSA-53x6-4x5p-rrvv High
commons-compress 1.18 1.21 GHSA-7hfm-57qf-j43q High
commons-compress 1.18 1.21 GHSA-crv7-7245-f45f High
commons-compress 1.18 1.21 GHSA-mc84-pj99-q6hh High
commons-compress 1.18 1.21 GHSA-xqfj-vm6h-2x34 High
commons-compress 1.18 CVE-2019-12402 High
commons-compress 1.18 CVE-2021-35515 High
commons-compress 1.18 CVE-2021-35516 High
commons-compress 1.18 CVE-2021-35517 High
commons-compress 1.18 CVE-2021-36090 High
commons-fileupload 1.3.1 1.3.2 GHSA-fvm3-cfvj-gxqq High
commons-fileupload 1.3.1 1.3.3 GHSA-7x9j-7223-rg5m Critical
commons-fileupload 1.3.1 CVE-2016-1000031 Critical
commons-fileupload 1.3.1 CVE-2016-3092 High
guava 18.0 24.1.1 GHSA-mvr2-9pj6-7w5j Medium
guava 18.0 30.0-jre GHSA-5mg8-w23w-74h3 Low
guava 18.0 CVE-2018-10237 Medium
guava 18.0 CVE-2020-8908 Low
guava 16.0.1 24.1.1 GHSA-mvr2-9pj6-7w5j Medium
guava 16.0.1 30.0-jre GHSA-5mg8-w23w-74h3 Low
guava 16.0.1 CVE-2018-10237 Medium
guava 16.0.1 CVE-2020-8908 Low
jackson-databind 2.4.3 2.6.7.3 GHSA-cf6r-3wgc-h863 High
jackson-databind 2.4.3 2.9.10.4 GHSA-fqwf-pjwf-7vqv Medium
jackson-databind 2.4.3 2.9.10 GHSA-f3j5-rmmp-3fc5 Critical
jackson-databind 2.4.3 2.8.11 GHSA-w3f4-3q6j-rh82 High
jackson-databind 2.4.3 2.9.10 GHSA-h822-r4r5-v8jg Critical
jackson-databind 2.4.3 2.9.10 GHSA-85cw-hj65-qqv9 Critical
jackson-databind 2.4.3 2.9.10.7 GHSA-5949-rw7g-wx7w High
jackson-databind 2.4.3 2.6.7.4 GHSA-288c-cq4h-88gq High
jackson-databind 2.4.3 2.9.9.2 GHSA-gwp4-hfv6-p7hw High
jackson-databind 2.4.3 2.9.9.1 GHSA-cmfg-87vq-g5g4 Medium
jackson-databind 2.4.3 2.9.9.1 GHSA-mph4-vhrx-mv67 Medium
jackson-databind 2.4.3 2.7.9.4 GHSA-qr7j-h6gg-jmgc Critical
jackson-databind 2.4.3 2.8.11 GHSA-h592-38cm-4ggp Critical
jackson-databind 2.4.3 2.8.11.1 GHSA-cggj-fvv3-cqwv Critical
jackson-databind 2.4.3 2.7.9.5 GHSA-4gq5-ch57-c2mg Critical
jackson-databind 2.4.3 2.7.9.5 GHSA-645p-88qh-w398 Critical
jackson-databind 2.4.3 2.7.9.4 GHSA-cjjf-94ff-43w7 High
jackson-databind 2.4.3 2.9.9 GHSA-5ww9-j83m-q7qx High
jackson-databind 2.4.3 2.9.9.2 GHSA-6fpp-rgj9-8rwc Critical
jackson-databind 2.4.3 2.9.10.1 GHSA-mx7p-6679-8g3q Critical
jackson-databind 2.4.3 2.9.10.1 GHSA-fmmc-742q-jg75 Critical
jackson-databind 2.4.3 2.9.10.1 GHSA-gjmw-vf9h-g25v Critical
jackson-databind 2.4.3 GHSA-gww7-p5w4-wrfv Critical
jackson-databind 2.4.3 GHSA-4w82-r329-3q67 Critical
jackson-databind 2.4.3 2.9.10.4 GHSA-q93h-jc49-78gg Critical
jackson-databind 2.4.3 2.9.10.4 GHSA-p43x-xfjf-5jhr Critical
jackson-databind 2.4.3 2.8.11 GHSA-rfx6-vp9g-rh7v Critical
jackson-databind 2.4.3 2.6.7.1 GHSA-qxxx-2pp7-5hmx Critical
jackson-databind 2.4.3 2.9.10.8 GHSA-v585-23hc-c647 High
jackson-databind 2.4.3 2.9.10.6 GHSA-h3cw-g4mq-c5x2 High
jackson-databind 2.4.3 2.9.10.8 GHSA-wh8g-3j2c-rqj5 High
jackson-databind 2.4.3 2.9.10.8 GHSA-r3gr-cxrf-hg25 High
jackson-databind 2.4.3 2.9.10.6 GHSA-qjw2-hr98-qgfh Critical
jackson-databind 2.4.3 2.9.10.8 GHSA-89qr-369f-5m5x High
jackson-databind 2.4.3 2.9.10.8 GHSA-9gph-22xh-8x98 High
jackson-databind 2.4.3 2.9.10.8 GHSA-8w26-6f25-cm9x High
jackson-databind 2.4.3 2.9.10.8 GHSA-cvm9-fjm9-3572 High
jackson-databind 2.4.3 2.9.10.8 GHSA-8c4j-34r4-xr8g High
jackson-databind 2.4.3 2.9.10.8 GHSA-m6x4-97wx-4q27 High
jackson-databind 2.4.3 2.9.10.8 GHSA-9m6f-7xcq-8vf8 High
jackson-databind 2.4.3 2.9.10.8 GHSA-f9xh-2qgp-cq57 High
jackson-databind 2.4.3 2.9.10.8 GHSA-r695-7vr9-jgc2 High
jackson-databind 2.4.3 2.9.10.8 GHSA-vfqx-33qm-g869 High
jackson-databind 2.4.3 CVE-2018-7489 Critical
jackson-databind 2.4.3 CVE-2020-35490 High
jackson-databind 2.4.3 CVE-2020-35491 High
jackson-databind 2.3.3 2.6.7.3 GHSA-cf6r-3wgc-h863 High
jackson-databind 2.3.3 2.9.10.4 GHSA-fqwf-pjwf-7vqv Medium
jackson-databind 2.3.3 2.9.10 GHSA-f3j5-rmmp-3fc5 Critical
jackson-databind 2.3.3 2.8.11 GHSA-w3f4-3q6j-rh82 High
jackson-databind 2.3.3 2.9.10 GHSA-h822-r4r5-v8jg Critical
jackson-databind 2.3.3 2.9.10 GHSA-85cw-hj65-qqv9 Critical
jackson-databind 2.3.3 2.9.10.7 GHSA-5949-rw7g-wx7w High
jackson-databind 2.3.3 2.6.7.4 GHSA-288c-cq4h-88gq High
jackson-databind 2.3.3 2.9.9.2 GHSA-gwp4-hfv6-p7hw High
jackson-databind 2.3.3 2.9.9.1 GHSA-cmfg-87vq-g5g4 Medium
jackson-databind 2.3.3 2.9.9.1 GHSA-mph4-vhrx-mv67 Medium
jackson-databind 2.3.3 2.7.9.4 GHSA-qr7j-h6gg-jmgc Critical
jackson-databind 2.3.3 2.8.11 GHSA-h592-38cm-4ggp Critical
jackson-databind 2.3.3 2.8.11.1 GHSA-cggj-fvv3-cqwv Critical
jackson-databind 2.3.3 2.7.9.5 GHSA-4gq5-ch57-c2mg Critical
jackson-databind 2.3.3 2.7.9.5 GHSA-645p-88qh-w398 Critical
jackson-databind 2.3.3 2.7.9.4 GHSA-cjjf-94ff-43w7 High
jackson-databind 2.3.3 2.9.9 GHSA-5ww9-j83m-q7qx High
jackson-databind 2.3.3 2.9.9.2 GHSA-6fpp-rgj9-8rwc Critical
jackson-databind 2.3.3 2.9.10.1 GHSA-mx7p-6679-8g3q Critical
jackson-databind 2.3.3 2.9.10.1 GHSA-fmmc-742q-jg75 Critical
jackson-databind 2.3.3 2.9.10.1 GHSA-gjmw-vf9h-g25v Critical
jackson-databind 2.3.3 GHSA-gww7-p5w4-wrfv Critical
jackson-databind 2.3.3 GHSA-4w82-r329-3q67 Critical
jackson-databind 2.3.3 2.9.10.4 GHSA-q93h-jc49-78gg Critical
jackson-databind 2.3.3 2.9.10.4 GHSA-p43x-xfjf-5jhr Critical
jackson-databind 2.3.3 2.8.11 GHSA-rfx6-vp9g-rh7v Critical
jackson-databind 2.3.3 2.6.7.1 GHSA-qxxx-2pp7-5hmx Critical
jackson-databind 2.3.3 2.9.10.8 GHSA-v585-23hc-c647 High
jackson-databind 2.3.3 2.9.10.6 GHSA-h3cw-g4mq-c5x2 High
jackson-databind 2.3.3 2.9.10.8 GHSA-wh8g-3j2c-rqj5 High
jackson-databind 2.3.3 2.9.10.8 GHSA-r3gr-cxrf-hg25 High
jackson-databind 2.3.3 2.9.10.6 GHSA-qjw2-hr98-qgfh Critical
jackson-databind 2.3.3 2.9.10.8 GHSA-89qr-369f-5m5x High
jackson-databind 2.3.3 2.9.10.8 GHSA-9gph-22xh-8x98 High
jackson-databind 2.3.3 2.9.10.8 GHSA-8w26-6f25-cm9x High
jackson-databind 2.3.3 2.9.10.8 GHSA-cvm9-fjm9-3572 High
jackson-databind 2.3.3 2.9.10.8 GHSA-8c4j-34r4-xr8g High
jackson-databind 2.3.3 2.9.10.8 GHSA-m6x4-97wx-4q27 High
jackson-databind 2.3.3 2.9.10.8 GHSA-9m6f-7xcq-8vf8 High
jackson-databind 2.3.3 2.9.10.8 GHSA-f9xh-2qgp-cq57 High
jackson-databind 2.3.3 2.9.10.8 GHSA-r695-7vr9-jgc2 High
jackson-databind 2.3.3 2.9.10.8 GHSA-vfqx-33qm-g869 High
jackson-databind 2.3.3 CVE-2018-7489 Critical
jackson-databind 2.3.3 CVE-2020-35490 High
jackson-databind 2.3.3 CVE-2020-35491 High
jetty-continuation 8.1.15.v20140411 CVE-2017-7656 High
jetty-continuation 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-continuation 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-continuation 8.1.15.v20140411 CVE-2017-9735 High
jetty-continuation 8.1.15.v20140411 CVE-2020-27216 High
jetty-continuation 8.1.15.v20140411 CVE-2021-28165 High
jetty-continuation 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-continuation 8.1.15.v20140411 CVE-2021-34428 Low
jetty-http 8.1.15.v20140411 CVE-2017-7656 High
jetty-http 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-http 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-http 8.1.15.v20140411 CVE-2017-9735 High
jetty-http 8.1.15.v20140411 CVE-2020-27216 High
jetty-http 8.1.15.v20140411 CVE-2021-28165 High
jetty-http 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-http 8.1.15.v20140411 CVE-2021-34428 Low
jetty-io 8.1.15.v20140411 9.4.39 GHSA-26vr-8j45-3r4w High
jetty-io 8.1.15.v20140411 CVE-2017-7656 High
jetty-io 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-io 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-io 8.1.15.v20140411 CVE-2017-9735 High
jetty-io 8.1.15.v20140411 CVE-2020-27216 High
jetty-io 8.1.15.v20140411 CVE-2021-28165 High
jetty-io 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-io 8.1.15.v20140411 CVE-2021-34428 Low
jetty-security 8.1.15.v20140411 CVE-2017-7656 High
jetty-security 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-security 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-security 8.1.15.v20140411 CVE-2017-9735 High
jetty-security 8.1.15.v20140411 CVE-2020-27216 High
jetty-security 8.1.15.v20140411 CVE-2021-28165 High
jetty-security 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-security 8.1.15.v20140411 CVE-2021-34428 Low
jetty-server 8.1.15.v20140411 9.4.41 GHSA-m6cp-vxjx-65j6 Low
jetty-server 8.1.15.v20140411 9.2.27.v20190403 GHSA-7vx9-xjhr-rw6h Medium
jetty-server 8.1.15.v20140411 9.2.25.v20180606 GHSA-vgg8-72f2-qm23 Critical
jetty-server 8.1.15.v20140411 9.2.9.v20150224 GHSA-ghgj-3xqr-6jfm High
jetty-server 8.1.15.v20140411 9.2.28.v20190418 GHSA-xc67-hjx6-cgg6 Medium
jetty-server 8.1.15.v20140411 9.3.24.v20180605 GHSA-84q7-p226-4x5w High
jetty-server 8.1.15.v20140411 CVE-2017-7656 High
jetty-server 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-server 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-server 8.1.15.v20140411 CVE-2017-9735 High
jetty-server 8.1.15.v20140411 CVE-2020-27216 High
jetty-server 8.1.15.v20140411 CVE-2021-28165 High
jetty-server 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-server 8.1.15.v20140411 CVE-2021-34428 Low
jetty-servlet 8.1.15.v20140411 CVE-2017-7656 High
jetty-servlet 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-servlet 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-servlet 8.1.15.v20140411 CVE-2017-9735 High
jetty-servlet 8.1.15.v20140411 CVE-2020-27216 High
jetty-servlet 8.1.15.v20140411 CVE-2021-28165 High
jetty-servlet 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-servlet 8.1.15.v20140411 CVE-2021-34428 Low
jetty-util 8.1.15.v20140411 CVE-2017-7656 High
jetty-util 8.1.15.v20140411 CVE-2017-7657 Critical
jetty-util 8.1.15.v20140411 CVE-2017-7658 Critical
jetty-util 8.1.15.v20140411 CVE-2017-9735 High
jetty-util 8.1.15.v20140411 CVE-2020-27216 High
jetty-util 8.1.15.v20140411 CVE-2021-28165 High
jetty-util 8.1.15.v20140411 CVE-2021-28169 Medium
jetty-util 8.1.15.v20140411 CVE-2021-34428 Low
log4j 1.2.17 GHSA-2qrg-x229-3v8q Critical
log4j 1.2.17 CVE-2019-17571 Critical
log4j 1.2.17 CVE-2020-9488 Low
postgresql 9.4.1212 CVE-2017-8806 Medium
postgresql 9.4.1212 CVE-2018-1058 High
postgresql 9.4.1212 CVE-2018-1115 Critical
postgresql 9.4.1212 CVE-2019-9193 High
postgresql 9.4.1212 CVE-2020-25694 High
postgresql 9.4.1212 CVE-2020-25695 High
postgresql 9.4.1212 CVE-2021-3393 Medium
protobuf-java 2.5.0 CVE-2015-5237 High
quartz 2.1.6 2.3.2 GHSA-9qcf-c26r-x5rf Critical
shiro-core 1.2.2 1.4.2 GHSA-r679-m633-g7wc Medium
shiro-core 1.2.2 1.6.0 GHSA-2vgm-wxr3-6w2j High
shiro-core 1.2.2 1.5.2 GHSA-26gr-cvq3-qxgf Critical
shiro-core 1.2.2 1.5.3 GHSA-72w9-fcj5-3fcg Critical
shiro-core 1.2.2 1.8.0 GHSA-f6jp-j6w3-w9hm Medium
shiro-core 1.2.2 CVE-2014-0074 High
shiro-core 1.2.2 CVE-2016-4437 High
shiro-core 1.2.2 CVE-2019-12422 High
shiro-core 1.2.2 CVE-2020-11989 Critical
shiro-core 1.2.2 CVE-2020-13933 High
shiro-core 1.2.2 CVE-2020-17510 Critical
shiro-core 1.2.2 CVE-2020-17523 Critical
shiro-core 1.2.2 CVE-2020-1957 Critical
shiro-core 1.2.2 CVE-2021-41303 Critical
shiro-ehcache 1.2.2 CVE-2014-0074 High
shiro-ehcache 1.2.2 CVE-2016-4437 High
shiro-ehcache 1.2.2 CVE-2019-12422 High
shiro-ehcache 1.2.2 CVE-2020-11989 Critical
shiro-ehcache 1.2.2 CVE-2020-13933 High
shiro-ehcache 1.2.2 CVE-2020-17510 Critical
shiro-ehcache 1.2.2 CVE-2020-17523 Critical
shiro-ehcache 1.2.2 CVE-2020-1957 Critical
shiro-ehcache 1.2.2 CVE-2021-41303 Critical
shiro-quartz 1.2.2 CVE-2014-0074 High
shiro-quartz 1.2.2 CVE-2016-4437 High
shiro-quartz 1.2.2 CVE-2019-12422 High
shiro-quartz 1.2.2 CVE-2020-11989 Critical
shiro-quartz 1.2.2 CVE-2020-13933 High
shiro-quartz 1.2.2 CVE-2020-17510 Critical
shiro-quartz 1.2.2 CVE-2020-17523 Critical
shiro-quartz 1.2.2 CVE-2020-1957 Critical
shiro-quartz 1.2.2 CVE-2021-41303 Critical
shiro-spring 1.2.2 1.7.0 GHSA-7cj4-gj8m-m2f7 Critical
shiro-spring 1.2.2 CVE-2014-0074 High
shiro-spring 1.2.2 CVE-2016-4437 High
shiro-spring 1.2.2 CVE-2019-12422 High
shiro-spring 1.2.2 CVE-2020-11989 Critical
shiro-spring 1.2.2 CVE-2020-13933 High
shiro-spring 1.2.2 CVE-2020-17510 Critical
shiro-spring 1.2.2 CVE-2020-17523 Critical
shiro-spring 1.2.2 CVE-2020-1957 Critical
shiro-spring 1.2.2 CVE-2021-41303 Critical
shiro-web 1.2.2 CVE-2014-0074 High
shiro-web 1.2.2 CVE-2016-4437 High
shiro-web 1.2.2 CVE-2019-12422 High
shiro-web 1.2.2 CVE-2020-11989 Critical
shiro-web 1.2.2 CVE-2020-13933 High
shiro-web 1.2.2 CVE-2020-17510 Critical
shiro-web 1.2.2 CVE-2020-17523 Critical
shiro-web 1.2.2 CVE-2020-1957 Critical
shiro-web 1.2.2 CVE-2021-41303 Critical
spring-security-core 3.0.7.RELEASE 4.2.16 GHSA-2ppp-9496-p23q Medium
spring-security-core 3.0.7.RELEASE 3.2.10 GHSA-v35c-49j6-q8hq High
spring-security-core 3.0.7.RELEASE 4.1.1 GHSA-8crv-49fr-2h6j High
spring-security-core 3.0.7.RELEASE 3.1.7 GHSA-wmv4-5w76-vp9g Critical
spring-security-web 3.0.7.RELEASE 5.2.9 GHSA-gq28-h5vg-8prx High
tomcat-jdbc 7.0.70 CVE-2012-5568 Medium
tomcat-jdbc 7.0.70 CVE-2016-0762 Medium
tomcat-jdbc 7.0.70 CVE-2016-5018 High
tomcat-jdbc 7.0.70 CVE-2016-5388 High
tomcat-jdbc 7.0.70 CVE-2016-5425 High
tomcat-jdbc 7.0.70 CVE-2016-6325 High
tomcat-jdbc 7.0.70 CVE-2016-6794 Medium
tomcat-jdbc 7.0.70 CVE-2016-6796 High
tomcat-jdbc 7.0.70 CVE-2016-6797 High
tomcat-jdbc 7.0.70 CVE-2016-6816 High
tomcat-jdbc 7.0.70 CVE-2016-8735 Critical
tomcat-jdbc 7.0.70 CVE-2016-8745 High
tomcat-jdbc 7.0.70 CVE-2017-12615 High
tomcat-jdbc 7.0.70 CVE-2017-12616 High
tomcat-jdbc 7.0.70 CVE-2017-12617 High
tomcat-jdbc 7.0.70 CVE-2017-5647 High
tomcat-jdbc 7.0.70 CVE-2017-5648 Critical
tomcat-jdbc 7.0.70 CVE-2017-5664 High
tomcat-jdbc 7.0.70 CVE-2017-7674 Medium
tomcat-jdbc 7.0.70 CVE-2018-11784 Medium
tomcat-jdbc 7.0.70 CVE-2018-1304 Medium
tomcat-jdbc 7.0.70 CVE-2018-1305 Medium
tomcat-jdbc 7.0.70 CVE-2018-1336 High
tomcat-jdbc 7.0.70 CVE-2018-8014 Critical
tomcat-jdbc 7.0.70 CVE-2018-8034 High
tomcat-jdbc 7.0.70 CVE-2019-0221 Medium
tomcat-jdbc 7.0.70 CVE-2019-0232 High
tomcat-jdbc 7.0.70 CVE-2019-12418 High
tomcat-jdbc 7.0.70 CVE-2019-17563 High
tomcat-jdbc 7.0.70 CVE-2020-13935 High
tomcat-jdbc 7.0.70 CVE-2020-1935 Medium
tomcat-jdbc 7.0.70 CVE-2020-1938 Critical
tomcat-jdbc 7.0.70 CVE-2020-8022 High
tomcat-jdbc 7.0.70 CVE-2020-9484 High
tomcat-jdbc 7.0.70 CVE-2021-24122 Medium
tomcat-jdbc 7.0.70 CVE-2021-25329 High
tomcat-jdbc 7.0.70 CVE-2021-30640 Medium
xz 1.8 CVE-2015-4035 High
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment