Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+CVE-2021-42392 h2: Remote Code Execution in ConsoleCVE-2022-23221 h2: Loading of custom classes from remote servers through JNDICVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of serviceCVE-2023-2976 guava: insecure temporary directory creationCVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are usedCVE-2019-14900 hibernate: SQL injection issue in Hibernate ORMCVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are usedCVE-2019-14900 hibernate: SQL injection issue in Hibernate ORMCVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of serviceCVE-2016-6652 Improper Neutralization of Special Elements used in an SQL Command Pivotal Spring Data JPACVE-2019-3797 spring-data-jpa: Additional information exposure with Spring Data JPA derived queriesCVE-2019-3802 spring-data-api: potential information disclosure through maliciously crafted example value in ExampleMatcherCVE-2022-22970 springframework: DoS via data binding to multipartFile or servlet partCVE-2022-22968 Framework: Data Binding Rules VulnerabilityCVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...Your dependencies cross-checked against the OSV vulnerability database.
GHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-hwj3-m3p6-hj38 dom4j allows External Entities by default which might enable XXE attacksGHSA-36p3-wjmg-h94x Remote Code Execution in Spring FrameworkGHSA-45hx-wfhj-473x Arbitrary code execution in H2 ConsoleGHSA-h376-j262-vhq6 RCE in H2 ConsoleGHSA-hwj3-m3p6-hj38 dom4j allows External Entities by default which might enable XXE attacksGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-7g45-4rm6-3mm3 Guava vulnerable to insecure use of temporary directoryGHSA-mvr2-9pj6-7w5j Denial of Service in Google GuavaGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesGHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created filesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.