You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
34
34
severity="warning"
35
35
/>
36
36
<error
37
37
source="vulnerability_medium"
38
38
line="1"
39
-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
39
+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
Copy file name to clipboardExpand all lines: docs/multiple-tests/pattern-vulnerability-critical/results.xml
+4-4Lines changed: 4 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -43,13 +43,13 @@
43
43
<error
44
44
source="vulnerability_critical"
45
45
line="14"
46
-
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 1.15.0)"
46
+
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)"
47
47
severity="error"
48
48
/>
49
49
<error
50
50
source="vulnerability_critical"
51
51
line="14"
52
-
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: Axios is a promise based HTTP client for the browser and Node.js. Prio ...) (update to 1.15.0)"
52
+
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)"
53
53
severity="error"
54
54
/>
55
55
</file>
@@ -58,13 +58,13 @@
58
58
<error
59
59
source="vulnerability_critical"
60
60
line="5"
61
-
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 1.15.0)"
61
+
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)"
62
62
severity="error"
63
63
/>
64
64
<error
65
65
source="vulnerability_critical"
66
66
line="5"
67
-
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: Axios is a promise based HTTP client for the browser and Node.js. Prio ...) (update to 1.15.0)"
67
+
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)"
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
246
246
severity="warning"
247
247
/>
248
248
<error
249
249
source="vulnerability_medium"
250
250
line="1"
251
-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
251
+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
273
273
severity="warning"
274
274
/>
275
275
<error
276
276
source="vulnerability_medium"
277
277
line="14"
278
-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
278
+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
0 commit comments