gitsafehub
github.com/seratch/spring-jersey-archetype ↗

seratch/spring-jersey-archetype

scanned 2026-08-13 · git eeb4649
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies45Known OSS vulnerabilities46Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 45 found · 6 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiver
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
  • Serious CVE-2017-5929 logback: Serialization vulnerability in SocketServer and ServerSocketReceiver
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
  • Serious CVE-2015-1832 Derby: XXE attack possible by using XmlVTI and the XML datatype
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2015-1832). Fix: Update that package to its patched version.
  • Serious CVE-2022-46337 A cleverly devised username might bypass LDAP authentication checks. I ...
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-46337). Fix: Update that package to its patched version.
  • Serious CVE-2022-22965 spring-framework: RCE via Data Binding on JDK 9+
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious CVE-2016-1000027 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-6378 logback: serialization vulnerability in logback receiver
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2023-6378). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-6378 logback: serialization vulnerability in logback receiver
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2023-6378). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-42550 logback: remote code execution through JNDI call from within its configuration file
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2021-42550). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-12798 logback-core: arbitrary code execution via JaninoEventEvaluator
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-12798). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-11226 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2025-11226). Fix: Update that package to its patched version.
  • Worth fixing CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1313). Fix: Update that package to its patched version.
  • Worth fixing CVE-2014-3558 Validator: JSM bypass via ReflectionHelper
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2014-3558). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2020-10693). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2023-1932). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2025-35036). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-22970 springframework: DoS via data binding to multipartFile or servlet part
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22970). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-22968 Framework: Data Binding Rules Vulnerability
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22968). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-38820 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-38820). Fix: Update that package to its patched version.
  • Worth fixing CVE-2015-5211 Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4 ...
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2015-5211). Fix: Update that package to its patched version.
  • Worth fixing CVE-2016-5007 spring: Path matching inconsistency
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2016-5007). Fix: Update that package to its patched version.
  • Worth fixing CVE-2018-1272 spring-framework: Multipart content pollution
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1272). Fix: Update that package to its patched version.
  • Worth fixing CVE-2014-3578 Framework: Directory traversal
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2014-3578). Fix: Update that package to its patched version.
  • Worth fixing CVE-2018-1257 spring-framework: ReDoS Attack with spring-messaging
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1257). Fix: Update that package to its patched version.
  • Worth fixing CVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
    spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1271). Fix: Update that package to its patched version.
… 20 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 46 found · 6 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted Data
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
  • Serious GHSA-rcjc-c4pj-xxrp Apache Derby: LDAP injection vulnerability in authenticator
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-46337). Fix: Update that package to its patched version.
  • Serious GHSA-wr69-g62g-2r9h Improper Restriction of XML External Entity Reference in Apace Derby
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2015-1832). Fix: Update that package to its patched version.
  • Serious GHSA-36p3-wjmg-h94x Remote Code Execution in Spring Framework
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
  • Serious GHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methods
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
  • Serious GHSA-vmfg-rjjm-rjrj QOS.ch Logback vulnerable to Deserialization of Untrusted Data
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2017-5929). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vmq6-5m68-f53m logback serialization vulnerability
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2023-6378). Fix: Update that package to its patched version.
  • Worth fixing GHSA-42xw-p62x-hwcf Improper Access Control in Apache Derby
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1313). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7v6m-28jr-rg84 Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2025-35036). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rmrm-75hp-phr2 Improper Input Validation in Hibernate Validator
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2020-10693). Fix: Update that package to its patched version.
  • Worth fixing GHSA-x83m-pf6f-pf9g hibernate-validator Cross-site Scripting vulnerability
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2023-1932). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hh26-6xwr-ggv7 Denial of service in Spring Framework
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22970). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match Exception
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-38820). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g5mm-vmx4-3rg7 Improper handling of case sensitivity in Spring Framework
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2022-22968). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4487-x383-qpph Possible privilege escalation in org.springframework:spring-core
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1272). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8crv-49fr-2h6j Spring Security and Spring Framework may not recognize certain paths that should be protected
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2016-5007). Fix: Update that package to its patched version.
  • Worth fixing GHSA-g8hw-794c-4j9g Path Traversal in org.springframework:spring-core
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1271). Fix: Update that package to its patched version.
  • Worth fixing GHSA-pgf9-h69p-pcgf Files or Directories Accessible to External Parties in org.springframework:spring-core
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2015-5211). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rcpf-vj53-7h2m Denial of Service in org.springframework:spring-core
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2018-1257). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2rmj-mq67-h97g Spring Framework DoS via conditional HTTP request
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-38809). Fix: Update that package to its patched version.
  • Worth fixing GHSA-2wrp-6fg6-hmc5 Spring Framework URL Parsing with Host Validation
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-22262). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match Exception
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-38820). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6v7w-535j-rq5m Pivotal Spring Framework DoS Attack with XML Input
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2015-3192). Fix: Update that package to its patched version.
  • Worth fixing GHSA-ccgv-vj62-xf9h Spring Web vulnerable to Open Redirect or Server Side Request Forgery
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-22243). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hgjh-9rj2-g67j Spring Framework URL Parsing with Host Validation Vulnerability
    /workdirs/scan-fd7a76c6-ac16-4abf-a06f-51242bfb70e0/spring-jersey/pom.xml
    A package you depend on has a known security hole (CVE-2024-22259). Fix: Update that package to its patched version.
… 21 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.