Your dependencies cross-checked against the OSV vulnerability database.
-
Worth fixing GHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2024-47554). Fix: Update that package to its patched version.
-
Worth fixing GHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IO
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2021-29425). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2020-15250). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-7j4h-8wpf-rqfh Missing XML Validation in Apache Xerces2
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2013-4002). Fix: Update that package to its patched version.
-
Worth fixing GHSA-h65f-jvqw-m9fj Infinite Loop in Apache Xerces Java
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2022-23437). Fix: Update that package to its patched version.
-
Worth fixing GHSA-vmqm-g3vh-847m Denial of service in Apache Xerces2
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2012-0881). Fix: Update that package to its patched version.
-
Worth fixing GHSA-w4jq-qh47-hvjq Improper Input Validation in Xerces
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/core/pom.xml
A package you depend on has a known security hole (CVE-2020-14338). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/uiapps/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-osgi-annotations/uiapps/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2024-47554). Fix: Update that package to its patched version.
-
Worth fixing GHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IO
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2021-29425). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2020-15250). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-7j4h-8wpf-rqfh Missing XML Validation in Apache Xerces2
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2013-4002). Fix: Update that package to its patched version.
-
Worth fixing GHSA-h65f-jvqw-m9fj Infinite Loop in Apache Xerces Java
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2022-23437). Fix: Update that package to its patched version.
-
Worth fixing GHSA-vmqm-g3vh-847m Denial of service in Apache Xerces2
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2012-0881). Fix: Update that package to its patched version.
-
Worth fixing GHSA-w4jq-qh47-hvjq Improper Input Validation in Xerces
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/core/pom.xml
A package you depend on has a known security hole (CVE-2020-14338). Fix: Update that package to its patched version.
-
Worth fixing GHSA-78wr-2p64-hpwj Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/second/pom.xml
A package you depend on has a known security hole (CVE-2024-47554). Fix: Update that package to its patched version.
-
Worth fixing GHSA-gwrp-pvrq-jmwv Path Traversal and Improper Input Validation in Apache Commons IO
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/second/pom.xml
A package you depend on has a known security hole (CVE-2021-29425). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/second/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.
-
Worth fixing GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/second/pom.xml
A package you depend on has a known security hole (CVE-2020-15250). Fix: Update that package to its patched version.
-
Worth fixing GHSA-j288-q9x7-2f5v Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
/workdirs/scan-cdc49bac-83cc-442f-b30e-2510e17a7660/.atomist/templates/test-projects/multimodule-two-bundles/second/pom.xml
A package you depend on has a known security hole (CVE-2025-48924). Fix: Update that package to its patched version.