Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.1.0Report Generated On : Tue, 4 Mar 2025 14:17:31 +0530Dependencies Scanned : 534 (213 unique)Vulnerable Dependencies : 19 Vulnerabilities Found : 89Vulnerabilities Suppressed : 0 ... NVD API Last Checked : 2025-03-04T10:03:23+0530NVD API Last Modified : 2025-03-04T04:15:15ZSummary Display:
Showing Vulnerable Dependencies (click to show all) * indicates the dependency has a known exploited vulnerability
AForge.Imaging.dllDescription:
AForge.Imaging File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AForge.Imaging.dllMD5: 5392a22226e960d4ae7e408913c49d6cSHA1: bd498279ef2e77e4b2c828d2f88f57e7941e562aSHA256: 107da9260b6d2796335b516f043b360250001feb0ae3b1c8422f90b5b9f6e282
Evidence Type Source Name Value Confidence Vendor dll namespace AForge.Imaging Highest Vendor file name AForge.Imaging High Vendor grokassembly CompanyName AForge Highest Vendor grokassembly FileDescription AForge.Imaging Low Vendor grokassembly InternalName AForge.Imaging.dll Low Vendor grokassembly OriginalFilename AForge.Imaging.dll Low Vendor grokassembly ProductName AForge.NET Medium Product dll namespace AForge.Imaging Highest Product file name AForge.Imaging High Product grokassembly CompanyName AForge Low Product grokassembly FileDescription AForge.Imaging High Product grokassembly InternalName AForge.Imaging.dll Medium Product grokassembly OriginalFilename AForge.Imaging.dll Medium Product grokassembly ProductName AForge.NET Highest Version AssemblyAnalyzer FilteredVersion 2.2.5.0 Highest Version grokassembly FileVersion 2.2.5.0 High Version grokassembly ProductVersion 2.2.5.0 Highest
AForge.Math.dllDescription:
AForge.Math File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AForge.Math.dllMD5: c69973f674d9d113411d0fa2d1dbe222SHA1: 144bfc8c0ee91956dd555940d77360f303db2a7bSHA256: a4f24c9a46705c66ff7838c3a4c61759f5ba58ee8a5b061d05340c61d790c0b7
Evidence Type Source Name Value Confidence Vendor dll namespace AForge.Math Highest Vendor file name AForge.Math High Vendor grokassembly CompanyName AForge Highest Vendor grokassembly FileDescription AForge.Math Low Vendor grokassembly InternalName AForge.Math.dll Low Vendor grokassembly OriginalFilename AForge.Math.dll Low Vendor grokassembly ProductName AForge.NET Medium Product dll namespace AForge.Math Highest Product file name AForge.Math High Product grokassembly CompanyName AForge Low Product grokassembly FileDescription AForge.Math High Product grokassembly InternalName AForge.Math.dll Medium Product grokassembly OriginalFilename AForge.Math.dll Medium Product grokassembly ProductName AForge.NET Highest Version AssemblyAnalyzer FilteredVersion 2.2.5.0 Highest Version grokassembly FileVersion 2.2.5.0 High Version grokassembly ProductVersion 2.2.5.0 Highest
AForge.dllDescription:
AForge File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AForge.dllMD5: 02c63f568e598aad85dd401d7b26e82aSHA1: 2da9ec7612835e1f69d4a93aa2d49ec9bdff7f7cSHA256: 966a474060a8aca70c73ba09d0b6fe2353035961c7107b9003ef879c010ff8da
Evidence Type Source Name Value Confidence Vendor dll namespace AForge Highest Vendor file name AForge High Vendor grokassembly CompanyName AForge Highest Vendor grokassembly FileDescription AForge Low Vendor grokassembly InternalName AForge.dll Low Vendor grokassembly OriginalFilename AForge.dll Low Vendor grokassembly ProductName AForge.NET Medium Product dll namespace AForge Highest Product file name AForge High Product grokassembly CompanyName AForge Low Product grokassembly FileDescription AForge High Product grokassembly InternalName AForge.dll Medium Product grokassembly OriginalFilename AForge.dll Medium Product grokassembly ProductName AForge.NET Highest Version AssemblyAnalyzer FilteredVersion 2.2.5.0 Highest Version grokassembly FileVersion 2.2.5.0 High Version grokassembly ProductVersion 2.2.5.0 Highest
AWSSDK.Core.dllDescription:
AWSSDK.Core
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Core Runtime File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.Core.dllMD5: 00dc2967ad312264a7ff65eea14ae002SHA1: f6908d716edcfb495fd503cfae1d72e65c64b552SHA256: 13f67e426986422b65a54e5b425425c049297f0b760723f2a61d0c502fc2a151
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon Highest Vendor file name AWSSDK.Core High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.Core Low Vendor grokassembly InternalName AWSSDK.Core.dll Low Vendor grokassembly OriginalFilename AWSSDK.Core.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Product dll namespace Amazon Highest Product file name AWSSDK.Core High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.Core High Product grokassembly InternalName AWSSDK.Core.dll Medium Product grokassembly OriginalFilename AWSSDK.Core.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Version grokassembly FileVersion 3.7.102.0 High
AWSSDK.Core:3.7.102File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.Core Medium Vendor msbuild id Core Low Product msbuild id AWSSDK.Core Highest Product msbuild id Core Medium Version msbuild version 3.7.102 Highest
AWSSDK.DynamoDBv2.dllDescription:
AWSSDK.DynamoDBv2
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Amazon DynamoDB. Amazon DynamoDB is a fast and flexible NoSQL database service for all applications that need consistent, single-digit millisecond latency at any scale. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.DynamoDBv2.dllMD5: 29997e9a4be2194e46832625e9e209b5SHA1: a647a5ef869fa711097c48fb3c7cec1f87b4f09aSHA256: 2c3a44e1231991592c24109919581c2a6b9913d87eec2ad2efca2c6683c18cf4
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon Highest Vendor file name AWSSDK.DynamoDBv2 High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.DynamoDBv2 Low Vendor grokassembly InternalName AWSSDK.DynamoDBv2.dll Low Vendor grokassembly OriginalFilename AWSSDK.DynamoDBv2.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Product dll namespace Amazon Highest Product file name AWSSDK.DynamoDBv2 High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.DynamoDBv2 High Product grokassembly InternalName AWSSDK.DynamoDBv2.dll Medium Product grokassembly OriginalFilename AWSSDK.DynamoDBv2.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Version grokassembly FileVersion 3.7.101.0 High
AWSSDK.DynamoDBv2:3.7.101File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.DynamoDBv2 Medium Vendor msbuild id DynamoDBv2 Low Product msbuild id AWSSDK.DynamoDBv2 Highest Product msbuild id DynamoDBv2 Medium Version msbuild version 3.7.101 Highest
Related Dependencies AWSSDK.DynamoDBv2:3.7.101File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AWSSDK.DynamoDBv2@3.7.101 AWSSDK.ElasticFileSystem.dllDescription:
AWSSDK.ElasticFileSystem
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Amazon Elastic File System. Amazon Elastic File System (Amazon EFS) is a file storage service for Amazon Elastic Compute Cloud (Amazon EC2) instances. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.ElasticFileSystem.dllMD5: e358d8b4ade111c5758f1a893267aa58SHA1: d786d5c6284efec7334514fb4ffd5e468a1ec2d6SHA256: 14f9b76a7bf706e97abfbb6be77bae77952087d2ec6761d10928324109a19e28
Evidence Type Source Name Value Confidence Vendor file name AWSSDK.ElasticFileSystem High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.ElasticFileSystem Low Vendor grokassembly InternalName AWSSDK.ElasticFileSystem.dll Low Vendor grokassembly OriginalFilename AWSSDK.ElasticFileSystem.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.ElasticFileSystem Medium Vendor msbuild id ElasticFileSystem Low Product file name AWSSDK.ElasticFileSystem High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.ElasticFileSystem High Product grokassembly InternalName AWSSDK.ElasticFileSystem.dll Medium Product grokassembly OriginalFilename AWSSDK.ElasticFileSystem.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Product msbuild id AWSSDK.ElasticFileSystem Highest Product msbuild id ElasticFileSystem Medium Version grokassembly FileVersion 3.7.101.9 High Version msbuild version 3.7.101.9 Highest
Related Dependencies AWSSDK.ElasticFileSystem:3.7.101.9File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AWSSDK.ElasticFileSystem@3.7.101.9 AWSSDK.ElasticFileSystem:3.7.101.9File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AWSSDK.ElasticFileSystem@3.7.101.9 AWSSDK.Extensions.NETCore.Setup.dllDescription:
AWSSDK.Extensions.NETCore.Setup
Amazon Web Services SDK for .NET extensions for .NET Core setup File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.Extensions.NETCore.Setup.dllMD5: 16c4d2168143c1802bd5f0e22a6a6e77SHA1: 4f2dd534473e60396793e3daf8e7d2c78c9749a7SHA256: de842a88c3aef72b4b5c916dee93f367226d5587d8ea929ccfb083919395ba6b
Evidence Type Source Name Value Confidence Vendor file name AWSSDK.Extensions.NETCore.Setup High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.Extensions.NETCore.Setup Low Vendor grokassembly InternalName AWSSDK.Extensions.NETCore.Setup.dll Low Vendor grokassembly OriginalFilename AWSSDK.Extensions.NETCore.Setup.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET extensions for .NET Core setup Medium Product file name AWSSDK.Extensions.NETCore.Setup High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.Extensions.NETCore.Setup High Product grokassembly InternalName AWSSDK.Extensions.NETCore.Setup.dll Medium Product grokassembly OriginalFilename AWSSDK.Extensions.NETCore.Setup.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET extensions for .NET Core setup Highest Version grokassembly FileVersion 3.7.1 High
AWSSDK.Extensions.NETCore.Setup:3.7.2File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.Extensions.NETCore.Setup Medium Vendor msbuild id Extensions Low Vendor msbuild id Extensions.NETCore.Setup Low Product msbuild id AWSSDK.Extensions.NETCore.Setup Highest Product msbuild id Extensions Medium Product msbuild id Extensions.NETCore.Setup Medium Version msbuild version 3.7.2 Highest
Related Dependencies AWSSDK.Extensions.NETCore.Setup:3.7.2File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AWSSDK.Extensions.NETCore.Setup@3.7.2 AWSSDK.Lambda.dllDescription:
AWSSDK.Lambda
The Amazon Web Services SDK for .NET (.NET Core 3.1) - AWS Lambda. AWS Lambda is a compute service that runs your code in response to events and automatically manages the compute resources for you, making it easy to build applications that respond quickly to new information. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.Lambda.dllMD5: 50936d0abb4041e73ab198a41a2effe9SHA1: 96c6ff3f15266733a97843e90a935924edac0ab9SHA256: fd646f6095085cc23761132df132a3ecfb4e4cddf9e485da4774f35a752eb60c
Evidence Type Source Name Value Confidence Vendor file name AWSSDK.Lambda High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.Lambda Low Vendor grokassembly InternalName AWSSDK.Lambda.dll Low Vendor grokassembly OriginalFilename AWSSDK.Lambda.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Product file name AWSSDK.Lambda High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.Lambda High Product grokassembly InternalName AWSSDK.Lambda.dll Medium Product grokassembly OriginalFilename AWSSDK.Lambda.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Version grokassembly FileVersion 3.7.102.0 High
AWSSDK.Lambda:3.7.102File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.Lambda Medium Vendor msbuild id Lambda Low Product msbuild id AWSSDK.Lambda Highest Product msbuild id Lambda Medium Version msbuild version 3.7.102 Highest
Related Dependencies AWSSDK.Lambda:3.7.102File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AWSSDK.Lambda@3.7.102 AWSSDK.RDS:3.7.410.21File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.RDS Medium Vendor msbuild id RDS Low Product msbuild id AWSSDK.RDS Highest Product msbuild id RDS Medium Version msbuild version 3.7.410.21 Highest
Related Dependencies AWSSDK.RDS:3.7.410.21File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/AWSSDK.RDS@3.7.410.21 AWSSDK.RDS:3.7.410.21File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/AWSSDK.RDS@3.7.410.21 AWSSDK.RDS:3.7.410.21File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/AWSSDK.RDS@3.7.410.21 AWSSDK.RDS:3.7.410.21File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/AWSSDK.RDS@3.7.410.21 AWSSDK.S3.dllDescription:
AWSSDK.S3
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Amazon Simple Storage Service. Amazon Simple Storage Service (Amazon S3), provides developers and IT teams with secure, durable, highly-scalable object storage. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.S3.dllMD5: 5a9a2f1894b19ad4053bb1f1c9944346SHA1: f545262f2195b39c4eaf573835e20415917d6109SHA256: ec14bb3bc57636812f2271a42d0ac43907e21e3ff462ed84c3b9f693652587e8
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon Highest Vendor file name AWSSDK.S3 High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.S3 Low Vendor grokassembly InternalName AWSSDK.S3.dll Low Vendor grokassembly OriginalFilename AWSSDK.S3.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.S3 Medium Vendor msbuild id S3 Low Product dll namespace Amazon Highest Product file name AWSSDK.S3 High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.S3 High Product grokassembly InternalName AWSSDK.S3.dll Medium Product grokassembly OriginalFilename AWSSDK.S3.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Product msbuild id AWSSDK.S3 Highest Product msbuild id S3 Medium Version grokassembly FileVersion 3.7.101.30 High Version msbuild version 3.7.101.30 Highest
Related Dependencies AWSSDK.S3:3.7.101.30File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AWSSDK.S3@3.7.101.30 AWSSDK.S3:3.7.101.30File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AWSSDK.S3@3.7.101.30 AWSSDK.S3:3.7.101.30File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj pkg:nuget/AWSSDK.S3@3.7.101.30 AWSSDK.SimpleNotificationService.dllDescription:
AWSSDK.SimpleNotificationService
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Amazon Simple Notification Service. Amazon Simple Notification Service (Amazon SNS) is a fast, flexible, fully managed push messaging service. Amazon SNS makes it simple and cost-effective to push notifications to Apple, Google, Fire OS, and Windows devices, as well as Android devices in China with Baidu Cloud Push. You can also use SNS to push notifications to internet connected smart devices, as well as other distributed services. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.SimpleNotificationService.dllMD5: 36224fbf51e7f3e36c83102e42228bffSHA1: 256abac1a7fd68fea2672b78b5f3c35612183610SHA256: afdb16eb3575d50f2e0dc6fa059044a64606faeb8bc4d0b354f83d4407965447
Evidence Type Source Name Value Confidence Vendor file name AWSSDK.SimpleNotificationService High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.SimpleNotificationService Low Vendor grokassembly InternalName AWSSDK.SimpleNotificationService.dll Low Vendor grokassembly OriginalFilename AWSSDK.SimpleNotificationService.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.SimpleNotificationService Medium Vendor msbuild id SimpleNotificationService Low Product file name AWSSDK.SimpleNotificationService High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.SimpleNotificationService High Product grokassembly InternalName AWSSDK.SimpleNotificationService.dll Medium Product grokassembly OriginalFilename AWSSDK.SimpleNotificationService.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Product msbuild id AWSSDK.SimpleNotificationService Highest Product msbuild id SimpleNotificationService Medium Version grokassembly FileVersion 3.7.100.33 High Version msbuild version 3.7.100.33 Highest
Related Dependencies AWSSDK.SimpleNotificationService:3.7.100.33File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AWSSDK.SimpleNotificationService@3.7.100.33 AWSSDK.SimpleSystemsManagement.dllDescription:
AWSSDK.SimpleSystemsManagement
The Amazon Web Services SDK for .NET (.NET Core 3.1) - Amazon Simple Systems Manager (SSM). Amazon EC2 Simple Systems Manager (SSM) enables you to manage a number of administrative and configuration tasks on your instances. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AWSSDK.SimpleSystemsManagement.dllMD5: b5b9ccdfc12e633a6218812d1c08b9a9SHA1: 30ebe8eda97bab97939d5bbbca0e9ce93e1d5200SHA256: 7f0bcb1a29ef15e0f51f2f9e23f2522d3cb300f2f6043c377de5db56c2244676
Evidence Type Source Name Value Confidence Vendor file name AWSSDK.SimpleSystemsManagement High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription AWSSDK.SimpleSystemsManagement Low Vendor grokassembly InternalName AWSSDK.SimpleSystemsManagement.dll Low Vendor grokassembly OriginalFilename AWSSDK.SimpleSystemsManagement.dll Low Vendor grokassembly ProductName Amazon Web Services SDK for .NET Medium Vendor msbuild id AWSSDK Medium Vendor msbuild id AWSSDK.SimpleSystemsManagement Medium Vendor msbuild id SimpleSystemsManagement Low Product file name AWSSDK.SimpleSystemsManagement High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription AWSSDK.SimpleSystemsManagement High Product grokassembly InternalName AWSSDK.SimpleSystemsManagement.dll Medium Product grokassembly OriginalFilename AWSSDK.SimpleSystemsManagement.dll Medium Product grokassembly ProductName Amazon Web Services SDK for .NET Highest Product msbuild id AWSSDK.SimpleSystemsManagement Highest Product msbuild id SimpleSystemsManagement Medium Version grokassembly FileVersion 3.7.102.13 High Version msbuild version 3.7.102.13 Highest
Related Dependencies AWSSDK.SimpleSystemsManagement:3.7.102.13File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AWSSDK.SimpleSystemsManagement@3.7.102.13 Amazon.Lambda.APIGatewayEvents.dllDescription:
Amazon.Lambda.APIGatewayEvents
Lambda event interfaces for API Gateway event source. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.APIGatewayEvents.dllMD5: f8d722d4fed53b617ca27ede8b0fd007SHA1: ffbad6f0caadfb7b523b15c4ee0a387f3838d1e7SHA256: 4c2b8a366f500679241b8b7621a51db521ab235a34dd3daaea6be1fb5beb6a01
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.APIGatewayEvents Highest Vendor file name Amazon.Lambda.APIGatewayEvents High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription Amazon.Lambda.APIGatewayEvents Low Vendor grokassembly InternalName Amazon.Lambda.APIGatewayEvents.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.APIGatewayEvents.dll Low Vendor grokassembly ProductName Amazon Web Services Lambda Interface for .NET Medium Product dll namespace Amazon.Lambda.APIGatewayEvents Highest Product file name Amazon.Lambda.APIGatewayEvents High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription Amazon.Lambda.APIGatewayEvents High Product grokassembly InternalName Amazon.Lambda.APIGatewayEvents.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.APIGatewayEvents.dll Medium Product grokassembly ProductName Amazon Web Services Lambda Interface for .NET Highest Version grokassembly FileVersion 1.2.0.0 High
Amazon.Lambda.APIGatewayEvents:2.5.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.APIGatewayEvents Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.APIGatewayEvents Low Product msbuild id Amazon.Lambda.APIGatewayEvents Highest Product msbuild id Lambda Medium Product msbuild id Lambda.APIGatewayEvents Medium Version msbuild version 2.5.0 Highest
Amazon.Lambda.ApplicationLoadBalancerEvents.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.ApplicationLoadBalancerEvents.dllMD5: ae75d9f69d0372ed9f5670b7dda6d289SHA1: 577796cab594dc7e43ce3f7a0c3002d9017cf789SHA256: 92d056aee57a68fb73e5d4844d6b8a31b5b357a348ec8410530efe0f8925621f
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.ApplicationLoadBalancerEvents Highest Vendor file name Amazon.Lambda.ApplicationLoadBalancerEvents High Vendor grokassembly InternalName Amazon.Lambda.ApplicationLoadBalancerEvents.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.ApplicationLoadBalancerEvents.dll Low Product dll namespace Amazon.Lambda.ApplicationLoadBalancerEvents Highest Product file name Amazon.Lambda.ApplicationLoadBalancerEvents High Product grokassembly InternalName Amazon.Lambda.ApplicationLoadBalancerEvents.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.ApplicationLoadBalancerEvents.dll Medium Version grokassembly FileVersion 0.0.0.0 High
Amazon.Lambda.AspNetCoreServer.dllDescription:
Amazon.Lambda.AspNetCoreServer
Amazon.Lambda.AspNetCoreServer makes it easy to run ASP.NET Core Web API applications as AWS Lambda functions. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.AspNetCoreServer.dllMD5: b6e9fbf73d48d201535da0ef8ecf35c2SHA1: 4e0e057749837317e3d8b1eada133652341e80d5SHA256: 8794296e91da57a7b7387722a6ecea43a77e4cde06fe153b490a3af63af225fa
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.AspNetCoreServer Highest Vendor file name Amazon.Lambda.AspNetCoreServer High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription Amazon.Lambda.AspNetCoreServer Low Vendor grokassembly InternalName Amazon.Lambda.AspNetCoreServer.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.AspNetCoreServer.dll Low Vendor grokassembly ProductName Amazon Web Services Lambda Interface for .NET Medium Product dll namespace Amazon.Lambda.AspNetCoreServer Highest Product file name Amazon.Lambda.AspNetCoreServer High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription Amazon.Lambda.AspNetCoreServer High Product grokassembly InternalName Amazon.Lambda.AspNetCoreServer.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.AspNetCoreServer.dll Medium Product grokassembly ProductName Amazon Web Services Lambda Interface for .NET Highest Version grokassembly FileVersion 2.0.4 High
Amazon.Lambda.AspNetCoreServer:7.3.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.AspNetCoreServer Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.AspNetCoreServer Low Product msbuild id Amazon.Lambda.AspNetCoreServer Highest Product msbuild id Lambda Medium Product msbuild id Lambda.AspNetCoreServer Medium Version msbuild version 7.3.0 Highest
Amazon.Lambda.Core.dllDescription:
Amazon.Lambda.Core
Core interfaces for Lambda. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.Core.dllMD5: e3ff649709a36002a8caeba1c2b6a63cSHA1: 8a0d532bd5dd292dd8b5572c81a0af48a30cd5ceSHA256: d3fd1d761d03288299dfb5bc5fbb9650c360e815176828704ed683d056ffa249
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.Core Highest Vendor file name Amazon.Lambda.Core High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription Amazon.Lambda.Core Low Vendor grokassembly InternalName Amazon.Lambda.Core.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.Core.dll Low Vendor grokassembly ProductName Amazon Web Services Lambda Interface for .NET Medium Product dll namespace Amazon.Lambda.Core Highest Product file name Amazon.Lambda.Core High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription Amazon.Lambda.Core High Product grokassembly InternalName Amazon.Lambda.Core.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.Core.dll Medium Product grokassembly ProductName Amazon Web Services Lambda Interface for .NET Highest Version grokassembly FileVersion 1.0.0.0 High
Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.Core Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.Core Low Product msbuild id Amazon.Lambda.Core Highest Product msbuild id Lambda Medium Product msbuild id Lambda.Core Medium Version msbuild version 2.1.0 Highest
Related Dependencies Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Core:2.1.0File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj pkg:nuget/Amazon.Lambda.Core@2.1.0 Amazon.Lambda.Logging.AspNetCore.dllDescription:
Amazon.Lambda.Logging.AspNetCore
ASP.NET Core logging support for Lambda. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.Logging.AspNetCore.dllMD5: 9482935b3e88a8679c51b76bad324279SHA1: 680ec56a97395d0c0f61bd550e0d2df20621e7c6SHA256: 770e5dfc23757a239061d5748dd0a2af820160cb84d793766cc2cabb6f4eeaf4
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.Logging.AspNetCore Highest Vendor file name Amazon.Lambda.Logging.AspNetCore High Vendor grokassembly CompanyName Amazon.com, Inc Highest Vendor grokassembly FileDescription Amazon.Lambda.Logging.AspNetCore Low Vendor grokassembly InternalName Amazon.Lambda.Logging.AspNetCore.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.Logging.AspNetCore.dll Low Vendor grokassembly ProductName Amazon Web Services Lambda Interface for .NET Medium Product dll namespace Amazon.Lambda.Logging.AspNetCore Highest Product file name Amazon.Lambda.Logging.AspNetCore High Product grokassembly CompanyName Amazon.com, Inc Low Product grokassembly FileDescription Amazon.Lambda.Logging.AspNetCore High Product grokassembly InternalName Amazon.Lambda.Logging.AspNetCore.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.Logging.AspNetCore.dll Medium Product grokassembly ProductName Amazon Web Services Lambda Interface for .NET Highest Version grokassembly FileVersion 2.0.0.0 High
Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.SNSEvents Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.SNSEvents Low Product msbuild id Amazon.Lambda.SNSEvents Highest Product msbuild id Lambda Medium Product msbuild id Lambda.SNSEvents Medium Version msbuild version 2.0.0 Highest
Related Dependencies Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csproj pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 Amazon.Lambda.SNSEvents:2.0.0File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.Serialization.Json Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.Serialization.Json Low Product msbuild id Amazon.Lambda.Serialization.Json Highest Product msbuild id Lambda Medium Product msbuild id Lambda.Serialization.Json Medium Version msbuild version 2.1.0 Highest
Related Dependencies Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.Json:2.1.0File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/Amazon.Lambda.Serialization.Json@2.1.0 Amazon.Lambda.Serialization.SystemTextJson.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Amazon.Lambda.Serialization.SystemTextJson.dllMD5: c1cd7fd3b07a4af7815bfe8015a2284eSHA1: e2f3299ec806001aa2e171aa0d957e2a7d287903SHA256: a0a68396c58029c206feeedc15f088307eba9b36185eee9707c127be84988a68
Evidence Type Source Name Value Confidence Vendor dll namespace Amazon.Lambda.Serialization.SystemTextJson Highest Vendor file name Amazon.Lambda.Serialization.SystemTextJson High Vendor grokassembly InternalName Amazon.Lambda.Serialization.SystemTextJson.dll Low Vendor grokassembly OriginalFilename Amazon.Lambda.Serialization.SystemTextJson.dll Low Product dll namespace Amazon.Lambda.Serialization.SystemTextJson Highest Product file name Amazon.Lambda.Serialization.SystemTextJson High Product grokassembly InternalName Amazon.Lambda.Serialization.SystemTextJson.dll Medium Product grokassembly OriginalFilename Amazon.Lambda.Serialization.SystemTextJson.dll Medium Version grokassembly FileVersion 0.0.0.0 High
Amazon.Lambda.Serialization.SystemTextJson:2.3.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Amazon Medium Vendor msbuild id Amazon.Lambda.Serialization.SystemTextJson Medium Vendor msbuild id Lambda Low Vendor msbuild id Lambda.Serialization.SystemTextJson Low Product msbuild id Amazon.Lambda.Serialization.SystemTextJson Highest Product msbuild id Lambda Medium Product msbuild id Lambda.Serialization.SystemTextJson Medium Version msbuild version 2.3.0 Highest
Related Dependencies Amazon.Lambda.Serialization.SystemTextJson:2.3.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Amazon.Lambda.Serialization.SystemTextJson@2.3.0 Apitron.PDF.Rasterizer.dllDescription:
Apitron.PDF.Rasterizer
Render and save PDF pages into images of various formats File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Apitron.PDF.Rasterizer.dllMD5: b8c1384361581e764f7bd600f61b3febSHA1: 08cea2861dab9f13518817b82a4ea0101289707bSHA256: 37f493427a1363581c3dadca97ea5ce43ac1969446b7b783465e41af12250257
Evidence Type Source Name Value Confidence Vendor dll namespace Apitron.PDF.Rasterizer Highest Vendor file name Apitron.PDF.Rasterizer High Vendor grokassembly CompanyName Apitron LTD. Highest Vendor grokassembly FileDescription Apitron.PDF.Rasterizer Low Vendor grokassembly InternalName Apitron.PDF.Rasterizer.dll Low Vendor grokassembly OriginalFilename Apitron.PDF.Rasterizer.dll Low Vendor grokassembly ProductName Apitron.PDF.Rasterizer Medium Product dll namespace Apitron.PDF.Rasterizer Highest Product file name Apitron.PDF.Rasterizer High Product grokassembly CompanyName Apitron LTD. Low Product grokassembly FileDescription Apitron.PDF.Rasterizer High Product grokassembly InternalName Apitron.PDF.Rasterizer.dll Medium Product grokassembly OriginalFilename Apitron.PDF.Rasterizer.dll Medium Product grokassembly ProductName Apitron.PDF.Rasterizer Highest Version AssemblyAnalyzer FilteredVersion 3.0.170.0 Highest Version grokassembly FileVersion 3.0.170.0 High Version grokassembly ProductVersion 3.0.170.0 Highest
Apitron.PDF.Rasterizer:3.0.170File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Apitron Medium Vendor msbuild id Apitron.PDF.Rasterizer Medium Vendor msbuild id PDF Low Vendor msbuild id PDF.Rasterizer Low Product msbuild id Apitron.PDF.Rasterizer Highest Product msbuild id PDF Medium Product msbuild id PDF.Rasterizer Medium Version msbuild version 3.0.170 Highest
AspectInjector:2.6.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AspectInjector Medium Vendor msbuild id AspectInjector Low Product msbuild id AspectInjector Highest Version msbuild version 2.6.0 Highest
AuditLogHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csprojMD5: c2f6cc7c43adcf7582f77408078c39efSHA1: ea875fee6ab10af16d4ede0e3574c70a0017e004SHA256: 27dbb084a19cb12ca53ba4ab78d0936b234b58b2ca844ead672c1118739de191
Evidence Type Source Name Value Confidence Vendor file name AuditLogHandler High Product file name AuditLogHandler High
AuditLogHandler.dllDescription:
AuditLogHandler File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\bin\Debug\net6.0\AuditLogHandler.dllMD5: 4201b311eae4e62257adbcd4d0a8fbd8SHA1: 944a8d53beaf4314b896ee9c8b04ff1ed96e7264SHA256: a8b98eb971d5f87bc0dc3813fc239f08f7330fb60d0992dd2742915aa98efa4f
Evidence Type Source Name Value Confidence Vendor dll namespace AuditLogHandler Highest Vendor file name AuditLogHandler High Vendor grokassembly CompanyName AuditLogHandler Highest Vendor grokassembly FileDescription AuditLogHandler Low Vendor grokassembly InternalName AuditLogHandler.dll Low Vendor grokassembly OriginalFilename AuditLogHandler.dll Low Vendor grokassembly ProductName AuditLogHandler Medium Product dll namespace AuditLogHandler Highest Product file name AuditLogHandler High Product grokassembly CompanyName AuditLogHandler Low Product grokassembly FileDescription AuditLogHandler High Product grokassembly InternalName AuditLogHandler.dll Medium Product grokassembly OriginalFilename AuditLogHandler.dll Medium Product grokassembly ProductName AuditLogHandler Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies AuditLogHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\obj\Debug\net6.0\AuditLogHandler.dll MD5: 4201b311eae4e62257adbcd4d0a8fbd8 SHA1: 944a8d53beaf4314b896ee9c8b04ff1ed96e7264 SHA256: a8b98eb971d5f87bc0dc3813fc239f08f7330fb60d0992dd2742915aa98efa4f AuditLogHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\obj\Debug\net6.0\ref\AuditLogHandler.dll MD5: 6da4adeb67e2e3bb836da330db408293 SHA1: 7089b538345110254600070481b9eec7522cf725 SHA256: 847dfe411037f8dda9d22a9a8cbe56b6954afdd1f17cb30435d839bcf604fed4 pkg:generic/AuditLogHandler@1.0.0 AuditLogHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\obj\Debug\net6.0\refint\AuditLogHandler.dll MD5: 6da4adeb67e2e3bb836da330db408293 SHA1: 7089b538345110254600070481b9eec7522cf725 SHA256: 847dfe411037f8dda9d22a9a8cbe56b6954afdd1f17cb30435d839bcf604fed4 AuditLogSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\AuditLogSwagger.jsMD5: 063fa0c8fde3db026a0aefc498c00ccfSHA1: 6591dfac7441e6873717f8d5f6f2c99cff195aa1SHA256: 5f6f6f6286243ff7ecded0972396ab7dc768124f1cdf001192c989fab250261f
Evidence Type Source Name Value Confidence
AutoMapper.Extensions.Microsoft.DependencyInjection.dllDescription:
AutoMapper.Extensions.Microsoft.DependencyInjection
AutoMapper extensions for ASP.NET Core File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AutoMapper.Extensions.Microsoft.DependencyInjection.dllMD5: 40eb6d80e26942da883a8ef16d87a173SHA1: d037ce1ffb0ca9ada212215ad6ae4af6d68fc199SHA256: 120c4d32a9120eebd6d2a7c9e75070cf31cdc85833eba050b031cad579e16547
Evidence Type Source Name Value Confidence Vendor file name AutoMapper.Extensions.Microsoft.DependencyInjection High Vendor grokassembly CompanyName Jimmy Bogard Highest Vendor grokassembly FileDescription AutoMapper.Extensions.Microsoft.DependencyInjection Low Vendor grokassembly InternalName AutoMapper.Extensions.Microsoft.DependencyInjection.dll Low Vendor grokassembly OriginalFilename AutoMapper.Extensions.Microsoft.DependencyInjection.dll Low Vendor grokassembly ProductName AutoMapper.Extensions.Microsoft.DependencyInjection Medium Vendor msbuild id AutoMapper Medium Vendor msbuild id AutoMapper.Extensions.Microsoft.DependencyInjection Medium Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Microsoft.DependencyInjection Low Product file name AutoMapper.Extensions.Microsoft.DependencyInjection High Product grokassembly CompanyName Jimmy Bogard Low Product grokassembly FileDescription AutoMapper.Extensions.Microsoft.DependencyInjection High Product grokassembly InternalName AutoMapper.Extensions.Microsoft.DependencyInjection.dll Medium Product grokassembly OriginalFilename AutoMapper.Extensions.Microsoft.DependencyInjection.dll Medium Product grokassembly ProductName AutoMapper.Extensions.Microsoft.DependencyInjection Highest Product msbuild id AutoMapper.Extensions.Microsoft.DependencyInjection Highest Product msbuild id Extensions Medium Product msbuild id Extensions.Microsoft.DependencyInjection Medium Version AssemblyAnalyzer FilteredVersion 12.0.0 Highest Version msbuild version 12.0.0 Highest
Related Dependencies AutoMapper.Extensions.Microsoft.DependencyInjection:12.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AutoMapper.Extensions.Microsoft.DependencyInjection@12.0.0 AutoMapper.dllDescription:
AutoMapper
A convention-based object-object mapper. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AutoMapper.dllMD5: 0a62f2c108330913cadaa41819f8920fSHA1: bbb059b1604d7c07ed21c054846fed3f5395ef74SHA256: 2d35a628d53d8ba7c11d55be303d18e2c685f57cfbb2e9d75d8ebd90c9475cdb
Evidence Type Source Name Value Confidence Vendor dll namespace AutoMapper Highest Vendor file name AutoMapper High Vendor grokassembly CompanyName Jimmy Bogard Highest Vendor grokassembly FileDescription AutoMapper Low Vendor grokassembly InternalName AutoMapper.dll Low Vendor grokassembly OriginalFilename AutoMapper.dll Low Vendor grokassembly ProductName AutoMapper Medium Vendor msbuild id AutoMapper Medium Vendor msbuild id AutoMapper Low Product dll namespace AutoMapper Highest Product file name AutoMapper High Product grokassembly CompanyName Jimmy Bogard Low Product grokassembly FileDescription AutoMapper High Product grokassembly InternalName AutoMapper.dll Medium Product grokassembly OriginalFilename AutoMapper.dll Medium Product grokassembly ProductName AutoMapper Highest Product msbuild id AutoMapper Highest Version AssemblyAnalyzer FilteredVersion 12.0.0 Highest Version msbuild version 12.0.0 Highest
Related Dependencies AutoMapper:12.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AutoMapper@12.0.0 AwsParameterStore.Microsoft.Extensions.Configuration.dllDescription:
AwsParameterStore.Microsoft.Extensions.Configuration
AWS Systems Manager Parameter Store configuration provider implementation for Microsoft.Extensions.Configuration. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\AwsParameterStore.Microsoft.Extensions.Configuration.dllMD5: 6cff4cd5f4718297b37aa5e5bdc12d3bSHA1: c45342ce39b8ea74491f13ab6382a1b479a7ad60SHA256: 903a0610bba31e40d1031e08d2a51354754f06c542678e587fbedab222def010
Evidence Type Source Name Value Confidence Vendor dll namespace AwsParameterStore.Microsoft.Extensions.Configuration Highest Vendor dll namespace Microsoft.Extensions.Configuration Highest Vendor file name AwsParameterStore.Microsoft.Extensions.Configuration High Vendor grokassembly CompanyName Hossam Barakat Highest Vendor grokassembly FileDescription AwsParameterStore.Microsoft.Extensions.Configuration Low Vendor grokassembly InternalName AwsParameterStore.Microsoft.Extensions.Configuration.dll Low Vendor grokassembly OriginalFilename AwsParameterStore.Microsoft.Extensions.Configuration.dll Low Vendor grokassembly ProductName AwsParameterStore.Microsoft.Extensions.Configuration Medium Vendor msbuild id AwsParameterStore Medium Vendor msbuild id AwsParameterStore.Microsoft.Extensions.Configuration Medium Vendor msbuild id Microsoft Low Vendor msbuild id Microsoft.Extensions.Configuration Low Product dll namespace AwsParameterStore.Microsoft.Extensions.Configuration Highest Product dll namespace Microsoft.Extensions.Configuration Highest Product file name AwsParameterStore.Microsoft.Extensions.Configuration High Product grokassembly CompanyName Hossam Barakat Low Product grokassembly FileDescription AwsParameterStore.Microsoft.Extensions.Configuration High Product grokassembly InternalName AwsParameterStore.Microsoft.Extensions.Configuration.dll Medium Product grokassembly OriginalFilename AwsParameterStore.Microsoft.Extensions.Configuration.dll Medium Product grokassembly ProductName AwsParameterStore.Microsoft.Extensions.Configuration Highest Product msbuild id AwsParameterStore.Microsoft.Extensions.Configuration Highest Product msbuild id Microsoft Medium Product msbuild id Microsoft.Extensions.Configuration Medium Version AssemblyAnalyzer FilteredVersion 0.7.0 Highest Version grokassembly ProductVersion 0.7.0 Highest Version msbuild version 0.7.0 Highest
Related Dependencies AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 BatchUploadSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\BatchUploadSwagger.jsMD5: 0ba802c5e9a2c3a18dfbd4e96f3fb4c3SHA1: cc7877f37a32c01adc028a31591b0f7b332d5ffeSHA256: 370205041a1fd62f2ec14a29c6337d8bdad41afa37ff15c6dd1ff61e218b0116
Evidence Type Source Name Value Confidence
CommentSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\CommentSwagger.jsMD5: ddd138dcbfc44a91b374e56c5c66dbfaSHA1: 412f68a3a8e05a96acece5a7dc16e952a5c74467SHA256: fae9fa9c4615e702bd51a67dbf21e29da5541acf464fdb53d669341ae3f6149c
Evidence Type Source Name Value Confidence
CrawlerSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\CrawlerSwagger.jsMD5: 37e6b9d585086a26c4de326ae7366642SHA1: 415409c0c7237557dd88d474dcfe6deb0ad6dde7SHA256: 32bd15b2abaf66bfc6b47d238444af8095cb846160288e81a8d15acdb49fd145
Evidence Type Source Name Value Confidence
Docnet.Core.dllDescription:
Docnet.Core
DocNET is a fast PDF editing and reading library for modern .NET applications. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Docnet.Core.dllMD5: db4497e39a2dc9dafcbdca0ba7a991b7SHA1: 07e764bfb2fdfc8d9c3dc7e20a4abe4a39ce97e6SHA256: 220bd97b553816dab1e6e662410d357aaf0f9758f2554300196371ea1564ae45
Evidence Type Source Name Value Confidence Vendor dll namespace Docnet.Core Highest Vendor file name Docnet.Core High Vendor grokassembly CompanyName Modestas Petravicius Highest Vendor grokassembly FileDescription Docnet.Core Low Vendor grokassembly InternalName Docnet.Core.dll Low Vendor grokassembly OriginalFilename Docnet.Core.dll Low Vendor grokassembly ProductName DocNet Medium Product dll namespace Docnet.Core Highest Product file name Docnet.Core High Product grokassembly CompanyName Modestas Petravicius Low Product grokassembly FileDescription Docnet.Core High Product grokassembly InternalName Docnet.Core.dll Medium Product grokassembly OriginalFilename Docnet.Core.dll Medium Product grokassembly ProductName DocNet Highest Version AssemblyAnalyzer FilteredVersion 2.4.0 Highest
Docnet.Core:2.4.0-alpha.6File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Core Low Vendor msbuild id Docnet Medium Vendor msbuild id Docnet.Core Medium Product msbuild id Core Medium Product msbuild id Docnet.Core Highest Version msbuild version 2.4.0-alpha.6 Highest
DocumentTypeSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\DocumentTypeSwagger.jsMD5: 0b6f5e6873cdcff5ef99648073a72598SHA1: b032b37029526d94f0c4a125d1c1adc24848831aSHA256: 95ff71a8f88d4841e1bc3eaf305976bfa20e76438b94f95ffb00c3198e22aa70
Evidence Type Source Name Value Confidence
DynamicFlowSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\DynamicFlowSwagger.jsMD5: 5e0124528e9f3f05387a16295725ef0eSHA1: d02f8398fd48c56e39a918af48923768ec942973SHA256: 109119ca97df0b5d3aaab4a6d26468772f9961236081edb55fb2398f4b16ae6d
Evidence Type Source Name Value Confidence
ESignSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\ESignSwagger.jsMD5: 6b99e5f9f5176dd20da30b0b36aad9fbSHA1: dfa2ebe6b0c73e706430413efd91ffbbfdbc5154SHA256: ac725eddd3e9271debfd10942234a61dc68bd1c9fb2f7094673d26d9f49b9757
Evidence Type Source Name Value Confidence
EncryptAccountNumberHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csprojMD5: 6db9ded26504e62cc145c1f17e235918SHA1: a09f223786334d04e2197025b286d00849d34edfSHA256: b62a6e422c643176685eabb715b07206c5ac845c5983b4f17043844a537415ea
Evidence Type Source Name Value Confidence Vendor file name EncryptAccountNumberHandler High Product file name EncryptAccountNumberHandler High
EntityEncryptionKeySwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\EntityEncryptionKeySwagger.jsMD5: c31ae3a93ce71cfb99cc3ffa2b6b46d5SHA1: c3b645b0837eb22819a4dbdaceea189b7b8981b0SHA256: d3b1c510bb19862997cb25bd67b18c5dbedc6e077888b8d01abbe5b7bceeb80f
Evidence Type Source Name Value Confidence
FeatureSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\FeatureSwagger.jsMD5: 18d2ff4e4b1f71c897895ce5d90bc9bcSHA1: 52c8bf27fa489cb0265060142cd9958b54cbce5eSHA256: 40cfc7db2dfba44abea27ad39eac70df90d3bf66add86d119fbcdaf21d4abe1c
Evidence Type Source Name Value Confidence
FluentValidation.AspNetCore.dllDescription:
FluentValidation.AspNetCore
AspNetCore integration for FluentValidation File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\FluentValidation.AspNetCore.dllMD5: 96d46b48b71daf9b244c9befb9c7c9d6SHA1: ab4017564c320bd6c3857c5b02ce40451b98f3faSHA256: 622cc69a0552ecd0b7a5803d214a97ea08239d223876d1cebdb6299e9593ba37
Evidence Type Source Name Value Confidence Vendor dll namespace FluentValidation.AspNetCore Highest Vendor file name FluentValidation.AspNetCore High Vendor grokassembly CompanyName Jeremy Skinner Highest Vendor grokassembly FileDescription FluentValidation.AspNetCore Low Vendor grokassembly InternalName FluentValidation.AspNetCore.dll Low Vendor grokassembly OriginalFilename FluentValidation.AspNetCore.dll Low Vendor grokassembly ProductName FluentValidation.AspNetCore Medium Vendor msbuild id AspNetCore Low Vendor msbuild id FluentValidation Medium Vendor msbuild id FluentValidation.AspNetCore Medium Product dll namespace FluentValidation.AspNetCore Highest Product file name FluentValidation.AspNetCore High Product grokassembly CompanyName Jeremy Skinner Low Product grokassembly FileDescription FluentValidation.AspNetCore High Product grokassembly InternalName FluentValidation.AspNetCore.dll Medium Product grokassembly OriginalFilename FluentValidation.AspNetCore.dll Medium Product grokassembly ProductName FluentValidation.AspNetCore Highest Product msbuild id AspNetCore Medium Product msbuild id FluentValidation.AspNetCore Highest Version AssemblyAnalyzer FilteredVersion 11.2.2 Highest Version msbuild version 11.2.2 Highest
Related Dependencies FluentValidation.AspNetCore:11.2.2File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/FluentValidation.AspNetCore@11.2.2 FluentValidation.DependencyInjectionExtensions.dllDescription:
FluentValidation.DependencyInjectionExtensions
Dependency injection extensions for FluentValidation File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\FluentValidation.DependencyInjectionExtensions.dllMD5: 18d114b8af98663d7f0a68af2d0e32ffSHA1: 78b5b600ff1807b03dea83b69996b785d112fbe6SHA256: 05171796692031bfdb1e0b0e3b206fad95d4eede2f9b5f2371ca826ed813b3f9
Evidence Type Source Name Value Confidence Vendor dll namespace FluentValidation Highest Vendor file name FluentValidation.DependencyInjectionExtensions High Vendor grokassembly CompanyName Jeremy Skinner Highest Vendor grokassembly FileDescription FluentValidation.DependencyInjectionExtensions Low Vendor grokassembly InternalName FluentValidation.DependencyInjectionExtensions.dll Low Vendor grokassembly OriginalFilename FluentValidation.DependencyInjectionExtensions.dll Low Vendor grokassembly ProductName FluentValidation.DependencyInjectionExtensions Medium Vendor msbuild id DependencyInjectionExtensions Low Vendor msbuild id FluentValidation Medium Vendor msbuild id FluentValidation.DependencyInjectionExtensions Medium Product dll namespace FluentValidation Highest Product file name FluentValidation.DependencyInjectionExtensions High Product grokassembly CompanyName Jeremy Skinner Low Product grokassembly FileDescription FluentValidation.DependencyInjectionExtensions High Product grokassembly InternalName FluentValidation.DependencyInjectionExtensions.dll Medium Product grokassembly OriginalFilename FluentValidation.DependencyInjectionExtensions.dll Medium Product grokassembly ProductName FluentValidation.DependencyInjectionExtensions Highest Product msbuild id DependencyInjectionExtensions Medium Product msbuild id FluentValidation.DependencyInjectionExtensions Highest Version AssemblyAnalyzer FilteredVersion 11.4.0 Highest Version msbuild version 11.4.0 Highest
Related Dependencies FluentValidation.DependencyInjectionExtensions:11.4.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/FluentValidation.DependencyInjectionExtensions@11.4.0 FluentValidation.dllDescription:
FluentValidation
A validation library for .NET that uses a fluent interface to construct strongly-typed validation rules. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\FluentValidation.dllMD5: 262044fd88a7410be4496a910b3312b2SHA1: 90a6ac423f1d7c4d1bbf7ffd8de0f4dec3bb54dfSHA256: 2715554650a612d7cfacaa7ca72a74632be6e11025f23aeff53f4549e7ce6c46
Evidence Type Source Name Value Confidence Vendor dll namespace FluentValidation Highest Vendor file name FluentValidation High Vendor grokassembly CompanyName Jeremy Skinner Highest Vendor grokassembly FileDescription FluentValidation Low Vendor grokassembly InternalName FluentValidation.dll Low Vendor grokassembly OriginalFilename FluentValidation.dll Low Vendor grokassembly ProductName FluentValidation Medium Product dll namespace FluentValidation Highest Product file name FluentValidation High Product grokassembly CompanyName Jeremy Skinner Low Product grokassembly FileDescription FluentValidation High Product grokassembly InternalName FluentValidation.dll Medium Product grokassembly OriginalFilename FluentValidation.dll Medium Product grokassembly ProductName FluentValidation Highest Version AssemblyAnalyzer FilteredVersion 11.4.0 Highest
FluentValidation:11.8.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id FluentValidation Medium Vendor msbuild id FluentValidation Low Product msbuild id FluentValidation Highest Version msbuild version 11.8.1 Highest
Related Dependencies FluentValidation:11.8.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/FluentValidation@11.8.1 FormDataSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\FormDataSwagger.jsMD5: 456245c6ffcfdf8fd22f7e8e5bc18997SHA1: 7b177c1ac437e0ec293e47043d3707cc35a9a6bdSHA256: 54a6afad050e6acaa60463fcda00f6fafb3ee91d422b151f8dbbd4dd4e320e8e
Evidence Type Source Name Value Confidence
FormSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\FormSwagger.jsMD5: 9979cd823a7ff58c4fdf1ccf9506a3f3SHA1: ad321939e57ded66ab9086df2ae0b87634e8b0d2SHA256: 13c99896e7dfedde67b5e2e10c54243eba1be6de4774186b2ecef0096d4184be
Evidence Type Source Name Value Confidence
Hashids.net.dllDescription:
Hashids.net
Generate YouTube-like hashes from one or many numbers. Use hashids when you do not want to expose your database ids to the user. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Hashids.net.dllMD5: 5d1689f2e4d893290b8a90b464e95beaSHA1: d4bcf419c9ba3256243f904d489be5c4fb1bdc72SHA256: ac19cd5e5239dd7c1b21fefad505b965eac63a105306ce2a43a98f8df2d742c4
Evidence Type Source Name Value Confidence Vendor file name Hashids.net High Vendor grokassembly CompanyName Markus Ullmark Highest Vendor grokassembly FileDescription Hashids.net Low Vendor grokassembly InternalName Hashids.net.dll Low Vendor grokassembly OriginalFilename Hashids.net.dll Low Vendor grokassembly ProductName Hashids.net Medium Vendor msbuild id Hashids Medium Vendor msbuild id Hashids.net Medium Vendor msbuild id net Low Product file name Hashids.net High Product grokassembly CompanyName Markus Ullmark Low Product grokassembly FileDescription Hashids.net High Product grokassembly InternalName Hashids.net.dll Medium Product grokassembly OriginalFilename Hashids.net.dll Medium Product grokassembly ProductName Hashids.net Highest Product msbuild id Hashids.net Highest Product msbuild id net Medium Version AssemblyAnalyzer FilteredVersion 1.6.1 Highest Version grokassembly ProductVersion 1.6.1 Highest Version msbuild version 1.6.1 Highest
Related Dependencies Hashids.net:1.6.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Hashids.net@1.6.1 HeadlessChromium.Puppeteer.Lambda.Dotnet:1.1.0.96File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id HeadlessChromium Medium Vendor msbuild id HeadlessChromium.Puppeteer.Lambda.Dotnet Medium Vendor msbuild id Puppeteer Low Vendor msbuild id Puppeteer.Lambda.Dotnet Low Product msbuild id HeadlessChromium.Puppeteer.Lambda.Dotnet Highest Product msbuild id Puppeteer Medium Product msbuild id Puppeteer.Lambda.Dotnet Medium Version msbuild version 1.1.0.96 Highest
CVE-2011-1797 suppress
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2017-7000 suppress
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2015-1205 suppress
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-1346 suppress
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
Humanizer.dllDescription:
Humanizer
A micro-framework that turns your normal strings, type names, enum fields, date fields ETC into a human friendly format File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Humanizer.dllMD5: b23ec3bf471a12c288f2a46b428bd013SHA1: 766c5bf33247f5d399f410873f4640c35fbc885eSHA256: 15e988ab3e8d84900ae90549eb399aac452d55edf0109e06fa1a9b227ddfd4c4
Evidence Type Source Name Value Confidence Vendor dll namespace Humanizer Highest Vendor file name Humanizer High Vendor grokassembly CompanyName Mehdi Khalili, Claire Novotny Highest Vendor grokassembly FileDescription Humanizer Low Vendor grokassembly InternalName Humanizer.dll Low Vendor grokassembly OriginalFilename Humanizer.dll Low Vendor grokassembly ProductName Humanizer (netstandard2.0) Medium Product dll namespace Humanizer Highest Product file name Humanizer High Product grokassembly CompanyName Mehdi Khalili, Claire Novotny Low Product grokassembly FileDescription Humanizer High Product grokassembly InternalName Humanizer.dll Medium Product grokassembly OriginalFilename Humanizer.dll Medium Product grokassembly ProductName Humanizer (netstandard2.0) Highest Version AssemblyAnalyzer FilteredVersion 2.8.26 Highest
KybReportDocumentSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\KybReportDocumentSwagger.jsMD5: e1f305c3f59692b8c7a297cf97318b78SHA1: 1c63940faa0da33f8d1b8517650b8b84c6fef989SHA256: 383b6e0029a732be0a1dafa9c66495572a7bb6523a9bdf7d07a58bdbd3a25dd0
Evidence Type Source Name Value Confidence
KybRiskSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\KybRiskSwagger.jsMD5: b5df0d9b8a45bd27ff64e1bc299d9b53SHA1: 904a2fc5ce3045608eef77ac87f1c9b3ca86a589SHA256: 3a13684fb623b2aa0fbadb4c44291ee8c43a089c0d9bda9edd70c135b075f95f
Evidence Type Source Name Value Confidence
KycDetails.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\KycDetails.jsMD5: 135b1bd087541b878c732c2eac1c4af2SHA1: 9630fa8958fcbcc919a521c35fc058307a4b76a0SHA256: 90fc2db17906346a3bc28689256eb956d7b0a3d729f13532b44f2d7675743e2e
Evidence Type Source Name Value Confidence
Lumigo.DotNET:1.0.51File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id DotNET Low Vendor msbuild id Lumigo Medium Vendor msbuild id Lumigo.DotNET Medium Product msbuild id DotNET Medium Product msbuild id Lumigo.DotNET Highest Version msbuild version 1.0.51 Highest
Related Dependencies Lumigo.DotNET:1.0.51File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Lumigo.DotNET@1.0.51 Lumigo.DotNET:1.0.51File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/Lumigo.DotNET@1.0.51 MaskAadhaarHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csprojMD5: d9d2aa286978072835f4fe2711370094SHA1: 0fa20fb08396cf1f7e422a2b87fc88abd04e8e63SHA256: 732943662e16de6cdb249c592e43056e04f39279721f70cfebbf0557384b9938
Evidence Type Source Name Value Confidence Vendor file name MaskAadhaarHandler High Product file name MaskAadhaarHandler High
MasterSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\MasterSwagger.jsMD5: 1f63daeaed5ef4a02f4bed0e9cdc5ce1SHA1: 0376b04f45fc78ab76328aed620abab3ea4df783SHA256: ed32316f2779fb78d15ecd7ba6b0dc9f9429c97e09837eaea132ece03edd1b20
Evidence Type Source Name Value Confidence
MenuSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\MenuSwagger.jsMD5: 423b532f63e820019889cce77c43d07bSHA1: 8fe7ad36ad494269d7083a2ad47de207272690faSHA256: 5a76971b6e4286ea79f574de3a1f07dbfef9a6cecdb999c70425e31d03e425bb
Evidence Type Source Name Value Confidence
MerchantFormSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\MerchantFormSwagger.jsMD5: 8cc806bb2e9aecee282c43161f3092a1SHA1: aeee9f51610c77d7c7ea295250ebba975abb4f18SHA256: 2e203f8316cc12ebd87605169ebda27a0c5af5c42fbeb8d69d19345e364d0101
Evidence Type Source Name Value Confidence
MerchantManagement.API.Tests.csprojFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\MerchantManagement.API.Tests.csprojMD5: 0128b18af34d9b65eeb74921152b35acSHA1: e99f70319a3a68d2e747f1ad946e80e83b66c8dcSHA256: 43c090d01b805e726d69b9e1f8ddaa6f62272ce69424fa1eb4be730631ccb061
Evidence Type Source Name Value Confidence Vendor file name MerchantManagement.API.Tests High Product file name MerchantManagement.API.Tests High
MerchantManagement.API.Tests.dllDescription:
MerchantManagement.API.Tests File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\MerchantManagement.API.Tests.dllMD5: a30e415fa9bd03dab0b9b7804943acc7SHA1: 21fb7840c88f4cd27a2426b4f76bd82342480f4aSHA256: 7e570c724eb5643b70d36e7f99650d0cdaccdc1fbaf2d1eb8290979fbfcc84e3
Evidence Type Source Name Value Confidence Vendor dll namespace MerchantManagement.API.Tests Highest Vendor file name MerchantManagement.API.Tests High Vendor grokassembly CompanyName MerchantManagement.API.Tests Highest Vendor grokassembly FileDescription MerchantManagement.API.Tests Low Vendor grokassembly InternalName MerchantManagement.API.Tests.dll Low Vendor grokassembly OriginalFilename MerchantManagement.API.Tests.dll Low Vendor grokassembly ProductName MerchantManagement.API.Tests Medium Product dll namespace MerchantManagement.API.Tests Highest Product file name MerchantManagement.API.Tests High Product grokassembly CompanyName MerchantManagement.API.Tests Low Product grokassembly FileDescription MerchantManagement.API.Tests High Product grokassembly InternalName MerchantManagement.API.Tests.dll Medium Product grokassembly OriginalFilename MerchantManagement.API.Tests.dll Medium Product grokassembly ProductName MerchantManagement.API.Tests Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies MerchantManagement.API.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\obj\Debug\net6.0\MerchantManagement.API.Tests.dll MD5: a30e415fa9bd03dab0b9b7804943acc7 SHA1: 21fb7840c88f4cd27a2426b4f76bd82342480f4a SHA256: 7e570c724eb5643b70d36e7f99650d0cdaccdc1fbaf2d1eb8290979fbfcc84e3 MerchantManagement.API.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\obj\Debug\net6.0\ref\MerchantManagement.API.Tests.dll MD5: a009f7aeab1fe5b828c06184c4ceb862 SHA1: 08257b6cf7c5b949ff3e07218daeffad74cb30a6 SHA256: ba315c86b19eb25c73f72a6e7925f1e53ca29fa6ea3aa922d66f3d0f01069459 pkg:generic/MerchantManagement.API.Tests@1.0.0 MerchantManagement.API.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\obj\Debug\net6.0\refint\MerchantManagement.API.Tests.dll MD5: a009f7aeab1fe5b828c06184c4ceb862 SHA1: 08257b6cf7c5b949ff3e07218daeffad74cb30a6 SHA256: ba315c86b19eb25c73f72a6e7925f1e53ca29fa6ea3aa922d66f3d0f01069459 MerchantManagement.API.csprojFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csprojMD5: d33cad2e5b370c655a416a82c5814782SHA1: 538375e0f2a4360dd7c32c648208f5eb18128800SHA256: ec8353cf104bfa9bb173e96c484be607d2cd965de3692fbe388d1ccfddd7227d
Evidence Type Source Name Value Confidence Vendor file name MerchantManagement.API High Product file name MerchantManagement.API High
MerchantManagement.API.dllDescription:
MerchantManagement.API File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\MerchantManagement.API.dllMD5: d130c0eb9dfe9f6cf1f3e972281aba90SHA1: 9b930cf264ada6221bdcbc13873529bf296e675eSHA256: 1f9338ce2d27678996fdbc5c6050cc4dccfb75a912153f798ceefc24d462eb85
Evidence Type Source Name Value Confidence Vendor dll namespace MerchantManagement.API Highest Vendor file name MerchantManagement.API High Vendor grokassembly CompanyName MerchantManagement.API Highest Vendor grokassembly FileDescription MerchantManagement.API Low Vendor grokassembly InternalName MerchantManagement.API.dll Low Vendor grokassembly OriginalFilename MerchantManagement.API.dll Low Vendor grokassembly ProductName MerchantManagement.API Medium Product dll namespace MerchantManagement.API Highest Product file name MerchantManagement.API High Product grokassembly CompanyName MerchantManagement.API Low Product grokassembly FileDescription MerchantManagement.API High Product grokassembly InternalName MerchantManagement.API.dll Medium Product grokassembly OriginalFilename MerchantManagement.API.dll Medium Product grokassembly ProductName MerchantManagement.API Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies MerchantManagement.API.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\obj\Debug\net6.0\MerchantManagement.API.dll MD5: d130c0eb9dfe9f6cf1f3e972281aba90 SHA1: 9b930cf264ada6221bdcbc13873529bf296e675e SHA256: 1f9338ce2d27678996fdbc5c6050cc4dccfb75a912153f798ceefc24d462eb85 MerchantManagement.API.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\obj\Debug\net6.0\ref\MerchantManagement.API.dll MD5: 5e1d3c3f4f4f5be8393d1dcc6c946550 SHA1: d7ac459c9fc9e7959ae911537cf6784c971ba9d3 SHA256: 111403ac5efb9f8241fe4c0af266f268fe230cbff9237253401fa5a8d332dbae pkg:generic/MerchantManagement.API@1.0.0 MerchantManagement.API.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\obj\Debug\net6.0\refint\MerchantManagement.API.dll MD5: 5e1d3c3f4f4f5be8393d1dcc6c946550 SHA1: d7ac459c9fc9e7959ae911537cf6784c971ba9d3 SHA256: 111403ac5efb9f8241fe4c0af266f268fe230cbff9237253401fa5a8d332dbae MerchantManagement.API.exeFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\MerchantManagement.API.exeMD5: daa7db51a5413cb5a35f8780759b7afbSHA1: 5393f131f0321dec4a516d634b802f7922f2cb89SHA256: 5100cc5e0954b7163a8f83c66837a28f5515c6ebb87077a7803f43865b5b54cf
Evidence Type Source Name Value Confidence Vendor file name MerchantManagement.API High Product file name MerchantManagement.API High
Related Dependencies apphost.exeFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\obj\Debug\net6.0\apphost.exe MD5: daa7db51a5413cb5a35f8780759b7afb SHA1: 5393f131f0321dec4a516d634b802f7922f2cb89 SHA256: 5100cc5e0954b7163a8f83c66837a28f5515c6ebb87077a7803f43865b5b54cf MerchantManagement.Tests.csprojFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\MerchantManagement.Tests.csprojMD5: acec50919e37a44f9060d8417b80f85fSHA1: d32f75466caf1efb63d6578227cae804a528e54bSHA256: a34749c1b2ca0d04074eecb6be5c28576474db39101a47f9bb77dbe1d7fc74e3
Evidence Type Source Name Value Confidence Vendor file name MerchantManagement.Tests High Product file name MerchantManagement.Tests High
MerchantManagement.Tests.dllDescription:
MerchantManagement.Tests File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\MerchantManagement.Tests.dllMD5: 82b7042e376c78e3bb7e61625303662fSHA1: c14185b92a776f3df190182c60a42a015e904ad2SHA256: 5e432fc7e58c1c97e765bd0db25961ecdb56662347cc058f890a10f74e058159
Evidence Type Source Name Value Confidence Vendor dll namespace MerchantManagement.Tests Highest Vendor file name MerchantManagement.Tests High Vendor grokassembly CompanyName MerchantManagement.Tests Highest Vendor grokassembly FileDescription MerchantManagement.Tests Low Vendor grokassembly InternalName MerchantManagement.Tests.dll Low Vendor grokassembly OriginalFilename MerchantManagement.Tests.dll Low Vendor grokassembly ProductName MerchantManagement.Tests Medium Product dll namespace MerchantManagement.Tests Highest Product file name MerchantManagement.Tests High Product grokassembly CompanyName MerchantManagement.Tests Low Product grokassembly FileDescription MerchantManagement.Tests High Product grokassembly InternalName MerchantManagement.Tests.dll Medium Product grokassembly OriginalFilename MerchantManagement.Tests.dll Medium Product grokassembly ProductName MerchantManagement.Tests Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies MerchantManagement.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\obj\Debug\net6.0\MerchantManagement.Tests.dll MD5: 82b7042e376c78e3bb7e61625303662f SHA1: c14185b92a776f3df190182c60a42a015e904ad2 SHA256: 5e432fc7e58c1c97e765bd0db25961ecdb56662347cc058f890a10f74e058159 MerchantManagement.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\obj\Debug\net6.0\ref\MerchantManagement.Tests.dll MD5: c7cc25a393437327f1ed36e51816e35f SHA1: 70f4512f3a64d14b593784f1dc68ec43c8549608 SHA256: 3d34ce0713f3baa6b48c64466579fb9bf0418be56ef6df17e4f89b85b4204a88 pkg:generic/MerchantManagement.Tests@1.0.0 MerchantManagement.Tests.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\obj\Debug\net6.0\refint\MerchantManagement.Tests.dll MD5: c7cc25a393437327f1ed36e51816e35f SHA1: 70f4512f3a64d14b593784f1dc68ec43c8549608 SHA256: 3d34ce0713f3baa6b48c64466579fb9bf0418be56ef6df17e4f89b85b4204a88 MerchantManagement.csprojFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csprojMD5: 73ec0897f2b988e29c0a03e9086677f7SHA1: 9181fe01cd45fd6b104d49e4a173f08c2567584bSHA256: 9284df64f6a149d7687a28a37380fda3f5795210e5463dd9f12b388a10dedfb7
Evidence Type Source Name Value Confidence Vendor file name MerchantManagement High Product file name MerchantManagement High
MerchantManagement.dllDescription:
MerchantManagement File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\bin\Debug\net6.0\MerchantManagement.dllMD5: 36fcdc8f3f2bbb671015436f9f119aa5SHA1: 105b771dbd07d91f59c358213b01f443d082f625SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea
Evidence Type Source Name Value Confidence Vendor dll namespace MerchantManagement Highest Vendor file name MerchantManagement High Vendor grokassembly CompanyName MerchantManagement Highest Vendor grokassembly FileDescription MerchantManagement Low Vendor grokassembly InternalName MerchantManagement.dll Low Vendor grokassembly OriginalFilename MerchantManagement.dll Low Vendor grokassembly ProductName MerchantManagement Medium Product dll namespace MerchantManagement Highest Product file name MerchantManagement High Product grokassembly CompanyName MerchantManagement Low Product grokassembly FileDescription MerchantManagement High Product grokassembly InternalName MerchantManagement.dll Medium Product grokassembly OriginalFilename MerchantManagement.dll Medium Product grokassembly ProductName MerchantManagement Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\obj\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\obj\Debug\net6.0\ref\MerchantManagement.dll MD5: 6592ba259691f930e3d0bff0df0e3bf3 SHA1: 21a556e4bd920ae4922cf3a0d365a992975dde99 SHA256: d6fe1ea161b05e99752a0e3eeac460aca19bb67f1373bdaf7b047ace3e628608 pkg:generic/MerchantManagement@1.0.0 MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\obj\Debug\net6.0\refint\MerchantManagement.dll MD5: 6592ba259691f930e3d0bff0df0e3bf3 SHA1: 21a556e4bd920ae4922cf3a0d365a992975dde99 SHA256: d6fe1ea161b05e99752a0e3eeac460aca19bb67f1373bdaf7b047ace3e628608 MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantManagement.dllFile Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\bin\Debug\net6.0\MerchantManagement.dll MD5: 36fcdc8f3f2bbb671015436f9f119aa5 SHA1: 105b771dbd07d91f59c358213b01f443d082f625 SHA256: 16d26c9125ea86def3b488bcd2a7d2b57775cd93d9b7689387fb73eab78c6fea MerchantRiskSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\MerchantRiskSwagger.jsMD5: 2e32c6895336adbcf2cf727a13f02b88SHA1: d8ce9615c697e42ee20283de2e52d2f726bd0c88SHA256: 057997e57438f07f477223c434b1a5721dddab82f6e071b22f897a4c12a7193e
Evidence Type Source Name Value Confidence
MerchantSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\MerchantSwagger.jsMD5: 8eaf4ebbee12920da451a252ead3283eSHA1: 8b785125ccc1014a3956954cdcabe64d6c67ab9dSHA256: 9879b55e5e94680e44b73fc5ace0445a9ffd82df03670d60d57c513b958e71e8
Evidence Type Source Name Value Confidence
Microsoft.AspNetCore.Http:2.2.2File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AspNetCore Low Vendor msbuild id AspNetCore.Http Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.AspNetCore.Http Medium Product msbuild id AspNetCore Medium Product msbuild id AspNetCore.Http Medium Product msbuild id Microsoft.AspNetCore.Http Highest Version msbuild version 2.2.2 Highest
CVE-2020-1045 (OSSINDEX) suppress
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p>
<p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p>
<p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>
Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2020-1045 for details CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:*:Microsoft.AspNetCore.Http:2.2.2:*:*:*:*:*:*:* Microsoft.AspNetCore.JsonPatch.dllDescription:
Microsoft.AspNetCore.JsonPatch
ASP.NET Core support for JSON PATCH. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.AspNetCore.JsonPatch.dllMD5: 73a35e9f29f35b38a6752073eeae3315SHA1: d0a539a0e36cc7cf47875eb93d2d8b23c194b193SHA256: d75f74d9a540b2b947b3604ec6faa611313dc2e127bedb58607f8feef2d4d525
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.AspNetCore.JsonPatch Highest Vendor file name Microsoft.AspNetCore.JsonPatch High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.AspNetCore.JsonPatch Low Vendor grokassembly InternalName Microsoft.AspNetCore.JsonPatch.dll Low Vendor grokassembly OriginalFilename Microsoft.AspNetCore.JsonPatch.dll Low Vendor grokassembly ProductName Microsoft ASP.NET Core Medium Product dll namespace Microsoft.AspNetCore.JsonPatch Highest Product file name Microsoft.AspNetCore.JsonPatch High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.AspNetCore.JsonPatch High Product grokassembly InternalName Microsoft.AspNetCore.JsonPatch.dll Medium Product grokassembly OriginalFilename Microsoft.AspNetCore.JsonPatch.dll Medium Product grokassembly ProductName Microsoft ASP.NET Core Highest Version AssemblyAnalyzer FilteredVersion 6.0.11 Highest
Related Dependencies Microsoft.AspNetCore.Authentication.JwtBearer.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.AspNetCore.Authentication.JwtBearer.dll MD5: 0dc661bfe5a96cf81642e61dd4491145 SHA1: 116b9441e33953df1dd4bee3ccd3a4c9dad3c3d2 SHA256: bfbf72a1e4388397e1bfa1ad8a9e146ccb0d6fb3c2f6be86c3603c2ea2069468 pkg:generic/Microsoft.AspNetCore.Authentication.JwtBearer@6.0.11 Microsoft.AspNetCore.Authentication.JwtBearer:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.AspNetCore.Authentication.JwtBearer@6.0.11 Microsoft.AspNetCore.Mvc.NewtonsoftJson.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.AspNetCore.Mvc.NewtonsoftJson.dll MD5: edf6af232002fb2b91ed1fcd7e04a0d7 SHA1: 83ed019d7847a677e2e627ceaa386516b8117b5f SHA256: 44803878309ced348655fdb029767a3f4baaadee99371a002462625b7d00d073 pkg:generic/Microsoft.AspNetCore.Mvc.NewtonsoftJson@6.0.11 Microsoft.AspNetCore.Mvc.NewtonsoftJson:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.AspNetCore.Mvc.NewtonsoftJson@6.0.11 Microsoft.AspNetCore.Mvc.Versioning.dllDescription:
Microsoft ASP.NET Core API Versioning
A service API versioning library for Microsoft ASP.NET Core. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.AspNetCore.Mvc.Versioning.dllMD5: 0e90a8bbe8b215e93239c9ed8e32758eSHA1: 5ce23dfc4666461757fc6bc05fe5c1c59701f3dbSHA256: 81e1ef6edfd0b2058054817ec92a1234856ccb65c639b428a25c21cab0124153
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft Highest Vendor dll namespace Microsoft.AspNetCore.Mvc Highest Vendor dll namespace Microsoft.AspNetCore.Mvc.Versioning Highest Vendor file name Microsoft.AspNetCore.Mvc.Versioning High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft ASP.NET Core API Versioning Low Vendor grokassembly InternalName Microsoft.AspNetCore.Mvc.Versioning.dll Low Vendor grokassembly OriginalFilename Microsoft.AspNetCore.Mvc.Versioning.dll Low Vendor grokassembly ProductName Microsoft.AspNetCore.Mvc.Versioning Medium Product dll namespace Microsoft Highest Product dll namespace Microsoft.AspNetCore.Mvc Highest Product dll namespace Microsoft.AspNetCore.Mvc.Versioning Highest Product file name Microsoft.AspNetCore.Mvc.Versioning High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft ASP.NET Core API Versioning High Product grokassembly InternalName Microsoft.AspNetCore.Mvc.Versioning.dll Medium Product grokassembly OriginalFilename Microsoft.AspNetCore.Mvc.Versioning.dll Medium Product grokassembly ProductName Microsoft.AspNetCore.Mvc.Versioning Highest Version grokassembly FileVersion 5.0.7710.5690 High
Microsoft.AspNetCore.Mvc.Versioning:5.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id AspNetCore Low Vendor msbuild id AspNetCore.Mvc.Versioning Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.AspNetCore.Mvc.Versioning Medium Product msbuild id AspNetCore Medium Product msbuild id AspNetCore.Mvc.Versioning Medium Product msbuild id Microsoft.AspNetCore.Mvc.Versioning Highest Version msbuild version 5.0.0 Highest
Microsoft.DotNet.InternalAbstractions.dllDescription:
Abstractions for making code that uses file system and environment testable. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.DotNet.InternalAbstractions.dllMD5: eafc60cf6f13766c9ab96f5b23457252SHA1: 8f8d4c9a0b1f700bc2ad8134b3200ce0683e95b9SHA256: afd22ba2a118645e049e27d65164c97125e416934d1cbd16fa0f231d0fe68f5b
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.DotNet.InternalAbstractions Highest Vendor file name Microsoft.DotNet.InternalAbstractions High Vendor grokassembly InternalName Microsoft.DotNet.InternalAbstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.DotNet.InternalAbstractions.dll Low Product dll namespace Microsoft.DotNet.InternalAbstractions Highest Product file name Microsoft.DotNet.InternalAbstractions High Product grokassembly InternalName Microsoft.DotNet.InternalAbstractions.dll Medium Product grokassembly OriginalFilename Microsoft.DotNet.InternalAbstractions.dll Medium Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Microsoft.EntityFrameworkCore.Abstractions.dllDescription:
Microsoft.EntityFrameworkCore.Abstractions
Provides abstractions and attributes that are used to configure Entity Framework Core File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.EntityFrameworkCore.Abstractions.dllMD5: 86b1d7511868631ac5a699abfad28641SHA1: b7705d526a2d2297231b463509727590fcef3dd8SHA256: 5fa213113051002988514ca4a25df91d4a8166d7b8ae6b49de419895d7acc1e1
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.EntityFrameworkCore Highest Vendor file name Microsoft.EntityFrameworkCore.Abstractions High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.EntityFrameworkCore.Abstractions Low Vendor grokassembly InternalName Microsoft.EntityFrameworkCore.Abstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Abstractions.dll Low Vendor grokassembly ProductName Microsoft Entity Framework Core Medium Product dll namespace Microsoft.EntityFrameworkCore Highest Product file name Microsoft.EntityFrameworkCore.Abstractions High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.EntityFrameworkCore.Abstractions High Product grokassembly InternalName Microsoft.EntityFrameworkCore.Abstractions.dll Medium Product grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Abstractions.dll Medium Product grokassembly ProductName Microsoft Entity Framework Core Highest Version AssemblyAnalyzer FilteredVersion 6.0.11 Highest Version grokassembly ProductVersion 6.0.11 Highest
Microsoft.EntityFrameworkCore.Design.dllDescription:
Microsoft.EntityFrameworkCore.Design
Shared design-time components for Entity Framework Core tools. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.EntityFrameworkCore.Design.dllMD5: 51a38607025ad2914325af5a10300b82SHA1: 777820dffc3fe6cbc517986c2ab85657ee90f8abSHA256: da325c2ad641b9b4c7d1dca0bb8653edd7d40e5bf48892578aae372ecf140f94
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.EntityFrameworkCore Highest Vendor dll namespace Microsoft.EntityFrameworkCore.Design Highest Vendor file name Microsoft.EntityFrameworkCore.Design High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.EntityFrameworkCore.Design Low Vendor grokassembly InternalName Microsoft.EntityFrameworkCore.Design.dll Low Vendor grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Design.dll Low Vendor grokassembly ProductName Microsoft Entity Framework Core Medium Vendor msbuild id EntityFrameworkCore Low Vendor msbuild id EntityFrameworkCore.Design Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.EntityFrameworkCore.Design Medium Product dll namespace Microsoft.EntityFrameworkCore Highest Product dll namespace Microsoft.EntityFrameworkCore.Design Highest Product file name Microsoft.EntityFrameworkCore.Design High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.EntityFrameworkCore.Design High Product grokassembly InternalName Microsoft.EntityFrameworkCore.Design.dll Medium Product grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Design.dll Medium Product grokassembly ProductName Microsoft Entity Framework Core Highest Product msbuild id EntityFrameworkCore Medium Product msbuild id EntityFrameworkCore.Design Medium Product msbuild id Microsoft.EntityFrameworkCore.Design Highest Version AssemblyAnalyzer FilteredVersion 6.0.11 Highest Version grokassembly ProductVersion 6.0.11 Highest Version msbuild version 6.0.11 Highest
Related Dependencies Microsoft.EntityFrameworkCore.Design:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.EntityFrameworkCore.Design@6.0.11 Microsoft.EntityFrameworkCore.Design:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Microsoft.EntityFrameworkCore.Design@6.0.11 Microsoft.EntityFrameworkCore.Relational.dllDescription:
Microsoft.EntityFrameworkCore.Relational
Shared Entity Framework Core components for relational database providers. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.EntityFrameworkCore.Relational.dllMD5: 7fc88f8521204fb8dd3d88fccfc95019SHA1: 0355e8588fe03caf93c7b8c62e2d00f1c6466b6cSHA256: 9fdf3e18c8652204ad369c4fd3ebf6daa789c2f3c2cdac6583030007c32a95d2
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.EntityFrameworkCore Highest Vendor file name Microsoft.EntityFrameworkCore.Relational High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.EntityFrameworkCore.Relational Low Vendor grokassembly InternalName Microsoft.EntityFrameworkCore.Relational.dll Low Vendor grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Relational.dll Low Vendor grokassembly ProductName Microsoft Entity Framework Core Medium Vendor msbuild id EntityFrameworkCore Low Vendor msbuild id EntityFrameworkCore.Relational Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.EntityFrameworkCore.Relational Medium Product dll namespace Microsoft.EntityFrameworkCore Highest Product file name Microsoft.EntityFrameworkCore.Relational High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.EntityFrameworkCore.Relational High Product grokassembly InternalName Microsoft.EntityFrameworkCore.Relational.dll Medium Product grokassembly OriginalFilename Microsoft.EntityFrameworkCore.Relational.dll Medium Product grokassembly ProductName Microsoft Entity Framework Core Highest Product msbuild id EntityFrameworkCore Medium Product msbuild id EntityFrameworkCore.Relational Medium Product msbuild id Microsoft.EntityFrameworkCore.Relational Highest Version AssemblyAnalyzer FilteredVersion 6.0.11 Highest Version grokassembly ProductVersion 6.0.11 Highest Version msbuild version 6.0.11 Highest
Related Dependencies Microsoft.EntityFrameworkCore.Relational:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.EntityFrameworkCore.Relational@6.0.11 Microsoft.EntityFrameworkCore.Relational:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Microsoft.EntityFrameworkCore.Relational@6.0.11 Microsoft.EntityFrameworkCore.dllDescription:
Microsoft.EntityFrameworkCore
Entity Framework Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations. EF Core works with SQL Server, Azure SQL Database, SQLite, Azure Cosmos DB, MySQL, PostgreSQL, and other databases through a provider plugin API.
Commonly Used Types:
Microsoft.EntityFrameworkCore.DbContext
Microsoft.EntityFrameworkCore.DbSet
File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.EntityFrameworkCore.dllMD5: 73146811272dc2b5353b3cb9b3e26caaSHA1: 42708abdcb5d9b477ecebfc4be5f29776b860c5bSHA256: da96237f5b353adb2fe4162101668df82453e96d0d82ffecf61bc24c19b18738
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.EntityFrameworkCore Highest Vendor file name Microsoft.EntityFrameworkCore High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.EntityFrameworkCore Low Vendor grokassembly InternalName Microsoft.EntityFrameworkCore.dll Low Vendor grokassembly OriginalFilename Microsoft.EntityFrameworkCore.dll Low Vendor grokassembly ProductName Microsoft Entity Framework Core Medium Vendor msbuild id EntityFrameworkCore Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.EntityFrameworkCore Medium Product dll namespace Microsoft.EntityFrameworkCore Highest Product file name Microsoft.EntityFrameworkCore High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.EntityFrameworkCore High Product grokassembly InternalName Microsoft.EntityFrameworkCore.dll Medium Product grokassembly OriginalFilename Microsoft.EntityFrameworkCore.dll Medium Product grokassembly ProductName Microsoft Entity Framework Core Highest Product msbuild id EntityFrameworkCore Medium Product msbuild id Microsoft.EntityFrameworkCore Highest Version AssemblyAnalyzer FilteredVersion 6.0.11 Highest Version grokassembly ProductVersion 6.0.11 Highest Version msbuild version 6.0.11 Highest
Related Dependencies Microsoft.EntityFrameworkCore:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.EntityFrameworkCore@6.0.11 Microsoft.EntityFrameworkCore:6.0.11File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Microsoft.EntityFrameworkCore@6.0.11 Microsoft.Extensions.Caching.Memory.dllDescription:
Microsoft.Extensions.Caching.Memory
In-memory cache implementation of Microsoft.Extensions.Caching.Memory.IMemoryCache. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Caching.Memory.dllMD5: 4b05e228ce48e5aa53361feb8d30398aSHA1: d71b874fee66d6f8bf003b97869050f466c28db7SHA256: 68e25eb71dab3eea401ac5e0d8d0912f9a7eff17733325126e69f6e2dc567d0c
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Caching.Memory Highest Vendor file name Microsoft.Extensions.Caching.Memory High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Caching.Memory Low Vendor grokassembly InternalName Microsoft.Extensions.Caching.Memory.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Caching.Memory.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Caching.Memory Highest Product file name Microsoft.Extensions.Caching.Memory High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Caching.Memory High Product grokassembly InternalName Microsoft.Extensions.Caching.Memory.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Caching.Memory.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version AssemblyAnalyzer FilteredVersion 6.0.2 Highest
Microsoft.Extensions.Configuration.Abstractions.dllDescription:
Microsoft.Extensions.Configuration.Abstractions
Abstractions of key-value pair based configuration.
Commonly Used Types:
Microsoft.Extensions.Configuration.IConfiguration
Microsoft.Extensions.Configuration.IConfigurationBuilder
Microsoft.Extensions.Configuration.IConfigurationProvider
Microsoft.Extensions.Configuration.IConfigurationRoot
Microsoft.Extensions.Configuration.IConfigurationSection File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Configuration.Abstractions.dllMD5: 5edcf3dccef856711d35e0afdbdf6d0cSHA1: fefe0a4870d36814a45f8e9c63530f1963cd6c0cSHA256: 893f042b8bea61e3e56091ee6167af61bc38a39d35cb1d0f9b222aae4493146a
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Configuration Highest Vendor file name Microsoft.Extensions.Configuration.Abstractions High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Configuration.Abstractions Low Vendor grokassembly InternalName Microsoft.Extensions.Configuration.Abstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Configuration.Abstractions.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Configuration Highest Product file name Microsoft.Extensions.Configuration.Abstractions High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Configuration.Abstractions High Product grokassembly InternalName Microsoft.Extensions.Configuration.Abstractions.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Configuration.Abstractions.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.Configuration.Binder.dllDescription:
Microsoft.Extensions.Configuration.Binder
Functionality to bind an object to data in configuration providers for Microsoft.Extensions.Configuration. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Configuration.Binder.dllMD5: db18ebb0ad92f4d11f37dced9e4157f1SHA1: 16236c199d1d88cd3048c723d13d821acef918f5SHA256: 59d14c4b98f6ed5b44512667ebaa71afe60f950483b5815d8c7604086445b03a
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Configuration Highest Vendor file name Microsoft.Extensions.Configuration.Binder High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Configuration.Binder Low Vendor grokassembly InternalName Microsoft.Extensions.Configuration.Binder.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Configuration.Binder.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Configuration Highest Product file name Microsoft.Extensions.Configuration.Binder High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Configuration.Binder High Product grokassembly InternalName Microsoft.Extensions.Configuration.Binder.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Configuration.Binder.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.Configuration.EnvironmentVariables.dllDescription:
Microsoft.Extensions.Configuration.EnvironmentVariables
Environment variables configuration provider implementation for Microsoft.Extensions.Configuration. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Configuration.EnvironmentVariables.dllMD5: 08f52a0ff6e9a3602259930674f95c5eSHA1: 4fd2e59545e6c845f8f9de6ce8fc4540acf1aa25SHA256: 94fb00fe869f78b572e8564d2700b143f392a5ab7c110e8c81981d5edbf632f7
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Configuration Highest Vendor dll namespace Microsoft.Extensions.Configuration.EnvironmentVariables Highest Vendor file name Microsoft.Extensions.Configuration.EnvironmentVariables High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Configuration.EnvironmentVariables Low Vendor grokassembly InternalName Microsoft.Extensions.Configuration.EnvironmentVariables.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Configuration.EnvironmentVariables.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Configuration Highest Product dll namespace Microsoft.Extensions.Configuration.EnvironmentVariables Highest Product file name Microsoft.Extensions.Configuration.EnvironmentVariables High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Configuration.EnvironmentVariables High Product grokassembly InternalName Microsoft.Extensions.Configuration.EnvironmentVariables.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Configuration.EnvironmentVariables.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version AssemblyAnalyzer FilteredVersion 6.0.2 Highest
Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Configuration.EnvironmentVariables Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Configuration.EnvironmentVariables Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Configuration.EnvironmentVariables Medium Product msbuild id Microsoft.Extensions.Configuration.EnvironmentVariables Highest Version msbuild version 6.0.1 Highest
Related Dependencies Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 Microsoft.Extensions.Configuration.Json:6.0.0File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Configuration.Json Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Configuration.Json Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Configuration.Json Medium Product msbuild id Microsoft.Extensions.Configuration.Json Highest Version msbuild version 6.0.0 Highest
Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Configuration.Json Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Configuration.Json Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Configuration.Json Medium Product msbuild id Microsoft.Extensions.Configuration.Json Highest Version msbuild version 7.0.0 Highest
Related Dependencies Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\AuditLogHandler\AuditLogHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.Json@7.0.0 Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.Json@7.0.0 Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.Json@7.0.0 Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.Json@7.0.0 Microsoft.Extensions.Configuration.Json:7.0.0File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration.Json@7.0.0 Microsoft.Extensions.Configuration.UserSecrets.dllDescription:
Microsoft.Extensions.Configuration.UserSecrets
User secrets configuration provider implementation for Microsoft.Extensions.Configuration. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Configuration.UserSecrets.dllMD5: f9255c8f30ac81d4693d1ddce2f59a07SHA1: b1be780e5f10dadd9bb1965739722e15a67a7171SHA256: cdb02893f9a9e822f8646836ec9e25c3c538a56872225f98a6b495103938eba8
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Configuration Highest Vendor dll namespace Microsoft.Extensions.Configuration.UserSecrets Highest Vendor file name Microsoft.Extensions.Configuration.UserSecrets High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Configuration.UserSecrets Low Vendor grokassembly InternalName Microsoft.Extensions.Configuration.UserSecrets.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Configuration.UserSecrets.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Configuration Highest Product dll namespace Microsoft.Extensions.Configuration.UserSecrets Highest Product file name Microsoft.Extensions.Configuration.UserSecrets High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Configuration.UserSecrets High Product grokassembly InternalName Microsoft.Extensions.Configuration.UserSecrets.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Configuration.UserSecrets.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version AssemblyAnalyzer FilteredVersion 6.0.2 Highest
Microsoft.Extensions.Configuration:7.0.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Configuration Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Configuration Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Configuration Medium Product msbuild id Microsoft.Extensions.Configuration Highest Version msbuild version 7.0.0 Highest
Related Dependencies Microsoft.Extensions.Configuration:7.0.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration@7.0.0 Microsoft.Extensions.Configuration:7.0.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration@7.0.0 Microsoft.Extensions.Configuration:7.0.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/Microsoft.Extensions.Configuration@7.0.0 Microsoft.Extensions.DependencyInjection.Abstractions.dllDescription:
Microsoft.Extensions.DependencyInjection.Abstractions
Abstractions for dependency injection.
Commonly Used Types:
Microsoft.Extensions.DependencyInjection.IServiceCollection File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.DependencyInjection.Abstractions.dllMD5: 6c8655836651933ffa4c253b5fa72939SHA1: b75730d6c1ef5e0ca6d7f7a1a5ee540aee940836SHA256: 087813b2f9350b8c2d31e5bc9a5410fab198fadac87bb1269f41de6e6ad7ee62
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.DependencyInjection Highest Vendor file name Microsoft.Extensions.DependencyInjection.Abstractions High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.DependencyInjection.Abstractions Low Vendor grokassembly InternalName Microsoft.Extensions.DependencyInjection.Abstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.DependencyInjection.Abstractions.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.DependencyInjection Highest Product file name Microsoft.Extensions.DependencyInjection.Abstractions High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.DependencyInjection.Abstractions High Product grokassembly InternalName Microsoft.Extensions.DependencyInjection.Abstractions.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.DependencyInjection.Abstractions.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.DependencyInjection.dllDescription:
Microsoft.Extensions.DependencyInjection
Default implementation of dependency injection for Microsoft.Extensions.DependencyInjection. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.DependencyInjection.dllMD5: d73fb559b01aca341a7750ddf3f6d6ebSHA1: 5f62514899132aed440854e599b742683bcea1d5SHA256: f8fe8bedbedefe0fab7e68c48f508d486b42258e16c09572886d7293507bdad6
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.DependencyInjection Highest Vendor file name Microsoft.Extensions.DependencyInjection High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.DependencyInjection Low Vendor grokassembly InternalName Microsoft.Extensions.DependencyInjection.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.DependencyInjection.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.DependencyInjection Highest Product file name Microsoft.Extensions.DependencyInjection High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.DependencyInjection High Product grokassembly InternalName Microsoft.Extensions.DependencyInjection.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.DependencyInjection.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.DependencyInjection:7.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.DependencyInjection Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.DependencyInjection Medium Product msbuild id Extensions Medium Product msbuild id Extensions.DependencyInjection Medium Product msbuild id Microsoft.Extensions.DependencyInjection Highest Version msbuild version 7.0.0 Highest
Microsoft.Extensions.DependencyModel.dllDescription:
Abstractions for reading `.deps` files. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.DependencyModel.dllMD5: c99274e8d8276563d8cefa3870b54b75SHA1: 90a1325a25bad7ca88b80305599f9027981c900bSHA256: c9eb87d14a9d170badcbce407888c2a565f1f216deaa6d615d1e741c4b62c10b
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.DependencyModel Highest Vendor file name Microsoft.Extensions.DependencyModel High Vendor grokassembly InternalName Microsoft.Extensions.DependencyModel.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.DependencyModel.dll Low Product dll namespace Microsoft.Extensions.DependencyModel Highest Product file name Microsoft.Extensions.DependencyModel High Product grokassembly InternalName Microsoft.Extensions.DependencyModel.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.DependencyModel.dll Medium Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Microsoft.Extensions.Hosting.dllDescription:
Microsoft.Extensions.Hosting
Hosting and startup infrastructures for applications. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Hosting.dllMD5: d57f28ca156b8bc37e4547751443bfb1SHA1: a1132e597ba1f2796de1e4ed2d6a0d929af195d5SHA256: 327b4c2e65a9f1d546d2d70443bb654eb25675a8d3ea2e098c81e7b53f7a4bbd
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Hosting Highest Vendor file name Microsoft.Extensions.Hosting High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Hosting Low Vendor grokassembly InternalName Microsoft.Extensions.Hosting.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Hosting.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Hosting Highest Product file name Microsoft.Extensions.Hosting High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Hosting High Product grokassembly InternalName Microsoft.Extensions.Hosting.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Hosting.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version AssemblyAnalyzer FilteredVersion 6.0.2 Highest
Microsoft.Extensions.Hosting:6.0.1File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Hosting Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Hosting Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Hosting Medium Product msbuild id Microsoft.Extensions.Hosting Highest Version msbuild version 6.0.1 Highest
Related Dependencies Microsoft.Extensions.Hosting:6.0.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Microsoft.Extensions.Hosting@6.0.1 Microsoft.Extensions.Logging.Abstractions.dllDescription:
Microsoft.Extensions.Logging.Abstractions
Logging abstractions for Microsoft.Extensions.Logging.
Commonly Used Types:
Microsoft.Extensions.Logging.ILogger
Microsoft.Extensions.Logging.ILoggerFactory
Microsoft.Extensions.Logging.ILogger<TCategoryName>
Microsoft.Extensions.Logging.LogLevel
Microsoft.Extensions.Logging.Logger<T>
Microsoft.Extensions.Logging.LoggerMessage
Microsoft.Extensions.Logging.Abstractions.NullLogger File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Logging.Abstractions.dllMD5: 5127ddc4377a4fec97eac8e991477d00SHA1: eb1c84da67d382390397e30fe801a38944bcf48cSHA256: b4bf70c7e2aa5ea0090e13817b895339259cc435dd16d8bd32ce4ebd85de4a3c
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Logging Highest Vendor dll namespace Microsoft.Extensions.Logging.Abstractions Highest Vendor file name Microsoft.Extensions.Logging.Abstractions High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Logging.Abstractions Low Vendor grokassembly InternalName Microsoft.Extensions.Logging.Abstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Logging.Abstractions.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Logging Highest Product dll namespace Microsoft.Extensions.Logging.Abstractions Highest Product file name Microsoft.Extensions.Logging.Abstractions High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Logging.Abstractions High Product grokassembly InternalName Microsoft.Extensions.Logging.Abstractions.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Logging.Abstractions.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.Logging.Console:6.0.0File Path: D:\Onboarding\MerchantManagement\src\EncryptAccountNumberHandler\EncryptAccountNumberHandler.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Logging.Console Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Logging.Console Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Logging.Console Medium Product msbuild id Microsoft.Extensions.Logging.Console Highest Version msbuild version 6.0.0 Highest
Related Dependencies Microsoft.Extensions.Logging.Console:6.0.0File Path: D:\Onboarding\MerchantManagement\src\MaskAadhaarHandler\MaskAadhaarHandler.csproj pkg:nuget/Microsoft.Extensions.Logging.Console@6.0.0 Microsoft.Extensions.Logging.Console:6.0.0File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csproj pkg:nuget/Microsoft.Extensions.Logging.Console@6.0.0 Microsoft.Extensions.Logging.Console:6.0.0File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csproj pkg:nuget/Microsoft.Extensions.Logging.Console@6.0.0 Microsoft.Extensions.Logging.dllDescription:
Microsoft.Extensions.Logging
Logging infrastructure default implementation for Microsoft.Extensions.Logging. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Logging.dllMD5: 3f6480b7c509fc21aaf73c32b9ff7aa8SHA1: c623ba7aaf28dfe6b54fc0ad43c6eba912c6b336SHA256: 6833a9076b9a4bb4195c87cdac7ccf4b99b86d1fc848a08e074d668d1e03530e
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Logging Highest Vendor file name Microsoft.Extensions.Logging High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Logging Low Vendor grokassembly InternalName Microsoft.Extensions.Logging.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Logging.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Logging Highest Product file name Microsoft.Extensions.Logging High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Logging High Product grokassembly InternalName Microsoft.Extensions.Logging.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Logging.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.Logging:7.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Logging Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Logging Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Logging Medium Product msbuild id Microsoft.Extensions.Logging Highest Version msbuild version 7.0.0 Highest
Microsoft.Extensions.Options.ConfigurationExtensions.dllDescription:
Microsoft.Extensions.Options.ConfigurationExtensions
Provides additional configuration specific functionality related to Options. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Options.ConfigurationExtensions.dllMD5: cfe09d5db428f456541ba4caa6888b66SHA1: d52da1aa9b011f1206ee6440e2a2a245c8b76118SHA256: 3c227ac499857cc556a02feaa843f2a711521cb324290a6a2b230227e42db48c
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Options Highest Vendor file name Microsoft.Extensions.Options.ConfigurationExtensions High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Options.ConfigurationExtensions Low Vendor grokassembly InternalName Microsoft.Extensions.Options.ConfigurationExtensions.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Options.ConfigurationExtensions.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Options Highest Product file name Microsoft.Extensions.Options.ConfigurationExtensions High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Options.ConfigurationExtensions High Product grokassembly InternalName Microsoft.Extensions.Options.ConfigurationExtensions.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Options.ConfigurationExtensions.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.Options.ConfigurationExtensions:7.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Extensions Low Vendor msbuild id Extensions.Options.ConfigurationExtensions Low Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.Extensions.Options.ConfigurationExtensions Medium Product msbuild id Extensions Medium Product msbuild id Extensions.Options.ConfigurationExtensions Medium Product msbuild id Microsoft.Extensions.Options.ConfigurationExtensions Highest Version msbuild version 7.0.0 Highest
Microsoft.Extensions.Options.dllDescription:
Microsoft.Extensions.Options
Provides a strongly typed way of specifying and accessing settings using dependency injection. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Options.dllMD5: 2cde060200f09d54a11200f693d84bc9SHA1: f65c6baa8a36cbb5b28249177fd74fa1279cfd1cSHA256: 792765a31e12260bf7aa7630d10e40dd9f2e140ffb5678237a2055266b478112
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Options Highest Vendor file name Microsoft.Extensions.Options High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Options Low Vendor grokassembly InternalName Microsoft.Extensions.Options.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Options.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Options Highest Product file name Microsoft.Extensions.Options High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Options High Product grokassembly InternalName Microsoft.Extensions.Options.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Options.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.Extensions.PlatformAbstractions.dllDescription:
Abstractions that unify behavior and API across .NET Framework, .NET Core and Mono File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.PlatformAbstractions.dllMD5: 3c36c3780dcf26fb7ab7d3504f0d5d3fSHA1: 685de73dd75d717f47d035f017c4e81a44c4c884SHA256: dd9a5cf0a9baf3bb42dfca15a0f62c25ba3563abd2acf3d36eaab0730853c503
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.PlatformAbstractions Highest Vendor file name Microsoft.Extensions.PlatformAbstractions High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly InternalName Microsoft.Extensions.PlatformAbstractions.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.PlatformAbstractions.dll Low Vendor grokassembly ProductName Microsoft .NET Extensions Medium Product dll namespace Microsoft.Extensions.PlatformAbstractions Highest Product file name Microsoft.Extensions.PlatformAbstractions High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly InternalName Microsoft.Extensions.PlatformAbstractions.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.PlatformAbstractions.dll Medium Product grokassembly ProductName Microsoft .NET Extensions Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest
Microsoft.Extensions.Primitives.dllDescription:
Microsoft.Extensions.Primitives
Primitives shared by framework extensions. Commonly used types include:
Commonly Used Types:
Microsoft.Extensions.Primitives.IChangeToken
Microsoft.Extensions.Primitives.StringValues
Microsoft.Extensions.Primitives.StringSegment File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Extensions.Primitives.dllMD5: 3ba07a6760be077504734e9c0be0cce3SHA1: a51acea6a9183d6c73dcedb5b0536f2a5efd5f43SHA256: 8578454489a439d5debd8a8ca9844b3b38076563eaf195cc5ed4bd27a8c54ea3
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Extensions.Primitives Highest Vendor file name Microsoft.Extensions.Primitives High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Extensions.Primitives Low Vendor grokassembly InternalName Microsoft.Extensions.Primitives.dll Low Vendor grokassembly OriginalFilename Microsoft.Extensions.Primitives.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Extensions.Primitives Highest Product file name Microsoft.Extensions.Primitives High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Extensions.Primitives High Product grokassembly InternalName Microsoft.Extensions.Primitives.dll Medium Product grokassembly OriginalFilename Microsoft.Extensions.Primitives.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 7.0.22.51805 High
Microsoft.IdentityModel.JsonWebTokens.dllDescription:
Microsoft.IdentityModel.JsonWebTokens
Includes types that provide support for creating, serializing and validating JSON Web Tokens. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.JsonWebTokens.dllMD5: 0187f56b73780b36b83c3787cac39953SHA1: 67d1738858e0c7fb8e6d8cdae698dcf9e34230daSHA256: 4d4f7892ed7eb6198aaed5ca324fc0d4c9ff223df3058aace759ea19b42263bc
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.IdentityModel.JsonWebTokens Highest Vendor file name Microsoft.IdentityModel.JsonWebTokens High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly FileDescription Microsoft.IdentityModel.JsonWebTokens Low Vendor grokassembly InternalName Microsoft.IdentityModel.JsonWebTokens.dll Low Vendor grokassembly OriginalFilename Microsoft.IdentityModel.JsonWebTokens.dll Low Vendor grokassembly ProductName Microsoft IdentityModel Medium Product dll namespace Microsoft.IdentityModel.JsonWebTokens Highest Product file name Microsoft.IdentityModel.JsonWebTokens High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly FileDescription Microsoft.IdentityModel.JsonWebTokens High Product grokassembly InternalName Microsoft.IdentityModel.JsonWebTokens.dll Medium Product grokassembly OriginalFilename Microsoft.IdentityModel.JsonWebTokens.dll Medium Product grokassembly ProductName Microsoft IdentityModel Highest Version AssemblyAnalyzer FilteredVersion 6.25.1.31130 Highest Version grokassembly FileVersion 6.25.1.31130 High
pkg:generic/Microsoft.IdentityModel.JsonWebTokens@6.25.1.31130 (Confidence :Medium)cpe:2.3:a:identitymodel_project:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:json_web_token_project:json_web_token:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identity_model:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-21319 suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:2.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
Microsoft.IdentityModel.Protocols.OpenIdConnect.dllDescription:
Microsoft.IdentityModel.Protocols.OpenIdConnect
Includes types that provide support for OpenIdConnect protocol. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.Protocols.OpenIdConnect.dllMD5: ab12a0ce21d3730ec7ea182768bb2409SHA1: ee9583a42b18271a689db29ceeb490a320bd1f25SHA256: b2df04680ace444416b01964474905373d941b7ef5d3e760ac9b736c57cd46aa
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.IdentityModel.Protocols.OpenIdConnect Highest Vendor file name Microsoft.IdentityModel.Protocols.OpenIdConnect High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly FileDescription Microsoft.IdentityModel.Protocols.OpenIdConnect Low Vendor grokassembly InternalName Microsoft.IdentityModel.Protocols.OpenIdConnect.dll Low Vendor grokassembly OriginalFilename Microsoft.IdentityModel.Protocols.OpenIdConnect.dll Low Vendor grokassembly ProductName Microsoft IdentityModel Medium Product dll namespace Microsoft.IdentityModel.Protocols.OpenIdConnect Highest Product file name Microsoft.IdentityModel.Protocols.OpenIdConnect High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly FileDescription Microsoft.IdentityModel.Protocols.OpenIdConnect High Product grokassembly InternalName Microsoft.IdentityModel.Protocols.OpenIdConnect.dll Medium Product grokassembly OriginalFilename Microsoft.IdentityModel.Protocols.OpenIdConnect.dll Medium Product grokassembly ProductName Microsoft IdentityModel Highest Version AssemblyAnalyzer FilteredVersion 6.10.0.20330 Highest Version grokassembly FileVersion 6.10.0.20330 High
CVE-2024-21319 suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:2.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
Microsoft.IdentityModel.Protocols.dllDescription:
Microsoft.IdentityModel.Protocols
Provides base protocol support for OpenIdConnect and WsFederation. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.Protocols.dllMD5: c62f64528e559335cee713043e7f02e8SHA1: 25c730accdd56220ca490f44d56589fd33c9d935SHA256: a8cc77e6c4cad2813d43b51f5316f09548fb2ee488ea72d3f4240e12bb117cf9
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.IdentityModel.Protocols Highest Vendor file name Microsoft.IdentityModel.Protocols High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly FileDescription Microsoft.IdentityModel.Protocols Low Vendor grokassembly InternalName Microsoft.IdentityModel.Protocols.dll Low Vendor grokassembly OriginalFilename Microsoft.IdentityModel.Protocols.dll Low Vendor grokassembly ProductName Microsoft IdentityModel Medium Product dll namespace Microsoft.IdentityModel.Protocols Highest Product file name Microsoft.IdentityModel.Protocols High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly FileDescription Microsoft.IdentityModel.Protocols High Product grokassembly InternalName Microsoft.IdentityModel.Protocols.dll Medium Product grokassembly OriginalFilename Microsoft.IdentityModel.Protocols.dll Medium Product grokassembly ProductName Microsoft IdentityModel Highest Version AssemblyAnalyzer FilteredVersion 6.10.0.20330 Highest Version grokassembly FileVersion 6.10.0.20330 High
pkg:generic/Microsoft.IdentityModel.Protocols@6.10.0.20330 (Confidence :Medium)cpe:2.3:a:identitymodel_project:identitymodel:6.10.0:20330:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identity_model:6.10.0:20330:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identitymodel:6.10.0:20330:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-21319 suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:2.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
Microsoft.IdentityModel.Tokens.dllDescription:
Microsoft.IdentityModel.Tokens
Includes types that provide support for SecurityTokens, Cryptographic operations: Signing, Verifying Signatures, Encryption. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.Tokens.dllMD5: 33f6c18917dac746452a4313f3944a5cSHA1: e992402bf99012501cb7a129a0a52db0a28a3dceSHA256: 09e3f0990e0710dbdf3d09bf8f3e29fcd3d15d1a6145662e4ebfb20d93bb59b8
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.IdentityModel.Tokens Highest Vendor file name Microsoft.IdentityModel.Tokens High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly FileDescription Microsoft.IdentityModel.Tokens Low Vendor grokassembly InternalName Microsoft.IdentityModel.Tokens.dll Low Vendor grokassembly OriginalFilename Microsoft.IdentityModel.Tokens.dll Low Vendor grokassembly ProductName Microsoft IdentityModel Medium Product dll namespace Microsoft.IdentityModel.Tokens Highest Product file name Microsoft.IdentityModel.Tokens High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly FileDescription Microsoft.IdentityModel.Tokens High Product grokassembly InternalName Microsoft.IdentityModel.Tokens.dll Medium Product grokassembly OriginalFilename Microsoft.IdentityModel.Tokens.dll Medium Product grokassembly ProductName Microsoft IdentityModel Highest Version AssemblyAnalyzer FilteredVersion 6.25.1.31130 Highest Version grokassembly FileVersion 6.25.1.31130 High
Related Dependencies Microsoft.IdentityModel.Abstractions.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.Abstractions.dll MD5: 26a17ac7a68d199113bc321827f069f0 SHA1: ea485fbf93837dab059818eabb091dcee8a2cd95 SHA256: a3b5f5a0d87a286b8e198b541148558df7d5ca96bbafed2cc60583ae3312f3ea pkg:generic/Microsoft.IdentityModel.Abstractions@6.25.1.31130 Microsoft.IdentityModel.Logging.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.IdentityModel.Logging.dll MD5: 72e747f26db700df00234843a085eeb9 SHA1: bb03e99f99f179e1a5ca34fb73facb97b2e44309 SHA256: 9f8c0fa0a70968cb833ec202901a17bcb85d4d4aa4d46623c5aa95d73cc57fa9 pkg:generic/Microsoft.IdentityModel.Logging@6.25.1.31130 pkg:generic/Microsoft.IdentityModel.Tokens@6.25.1.31130 (Confidence :Medium)cpe:2.3:a:identitymodel_project:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identity_model:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-21319 suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:2.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
Microsoft.NET.Test.Sdk:16.11.0File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\MerchantManagement.Tests.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Microsoft Medium Vendor msbuild id Microsoft.NET.Test.Sdk Medium Vendor msbuild id NET Low Vendor msbuild id NET.Test.Sdk Low Product msbuild id Microsoft.NET.Test.Sdk Highest Product msbuild id NET Medium Product msbuild id NET.Test.Sdk Medium Version msbuild version 16.11.0 Highest
Related Dependencies Microsoft.NET.Test.Sdk:16.11.0File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\MerchantManagement.API.Tests.csproj pkg:nuget/Microsoft.NET.Test.Sdk@16.11.0 Microsoft.TestPlatform.CrossPlatEngine.dllDescription:
Microsoft.TestPlatform.CrossPlatEngine File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CrossPlatEngine.dllMD5: 81c806d391cbbb115bd7c3057ad072e7SHA1: 602b423ee14a267625e4d36063b86acfad08b12cSHA256: c3f39f643bec30b8af31337cb357999c82cd980ceb5a2ec25b6d49936006805e
Evidence Type Source Name Value Confidence Vendor file name Microsoft.TestPlatform.CrossPlatEngine High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.TestPlatform.CrossPlatEngine Low Vendor grokassembly InternalName Microsoft.TestPlatform.CrossPlatEngine.dll Low Vendor grokassembly OriginalFilename Microsoft.TestPlatform.CrossPlatEngine.dll Low Vendor grokassembly ProductName Microsoft.VisualStudio.TestPlatform.CrossPlatEngine Medium Product dll namespace Microsoft.VisualStudio.TestPlatform.CrossPlatEngine Highest Product file name Microsoft.TestPlatform.CrossPlatEngine High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.TestPlatform.CrossPlatEngine High Product grokassembly InternalName Microsoft.TestPlatform.CrossPlatEngine.dll Medium Product grokassembly OriginalFilename Microsoft.TestPlatform.CrossPlatEngine.dll Medium Product grokassembly ProductName Microsoft.VisualStudio.TestPlatform.CrossPlatEngine Highest Version grokassembly ProductVersion 16.11.0 Highest
Related Dependencies Microsoft.TestPlatform.CommunicationUtilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CommunicationUtilities.dll MD5: 716a71dd4301e9bb639cea379ae0113c SHA1: 31ddcbff9e0fad7bcfe40315919d680425f8c14b SHA256: 375472dd399e4dea667444426ba47ab29b6578b8cfbad1a706a072a92e94dc80 pkg:generic/Microsoft.TestPlatform.CommunicationUtilities@16.11.0 Microsoft.TestPlatform.CommunicationUtilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CommunicationUtilities.dll MD5: 716a71dd4301e9bb639cea379ae0113c SHA1: 31ddcbff9e0fad7bcfe40315919d680425f8c14b SHA256: 375472dd399e4dea667444426ba47ab29b6578b8cfbad1a706a072a92e94dc80 Microsoft.TestPlatform.CoreUtilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CoreUtilities.dll MD5: d9751a597e69942aa305cd30771aa86d SHA1: 28c570181a47e9909d41968b6506c0044c910978 SHA256: f0868b56b063b0ccb92c1b5f4964e2ae49f16166bead5ba3f20022776ca1d6e1 pkg:generic/Microsoft.TestPlatform.CoreUtilities@16.11.0 Microsoft.TestPlatform.CoreUtilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CoreUtilities.dll MD5: d9751a597e69942aa305cd30771aa86d SHA1: 28c570181a47e9909d41968b6506c0044c910978 SHA256: f0868b56b063b0ccb92c1b5f4964e2ae49f16166bead5ba3f20022776ca1d6e1 Microsoft.TestPlatform.CrossPlatEngine.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.CrossPlatEngine.dll MD5: 81c806d391cbbb115bd7c3057ad072e7 SHA1: 602b423ee14a267625e4d36063b86acfad08b12c SHA256: c3f39f643bec30b8af31337cb357999c82cd980ceb5a2ec25b6d49936006805e Microsoft.TestPlatform.PlatformAbstractions.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.PlatformAbstractions.dll MD5: b0fc6e3da0b5a615e319a85fd9c67d55 SHA1: 03516289a2119e083035de4fba6cb21735854ef5 SHA256: 6bf88824cea8d8c66a925e9c6c2fa19144bd3539b4ea8aad9160c8d83b1fe4e1 pkg:generic/Microsoft.TestPlatform.PlatformAbstractions@16.11.0 Microsoft.TestPlatform.PlatformAbstractions.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.PlatformAbstractions.dll MD5: b0fc6e3da0b5a615e319a85fd9c67d55 SHA1: 03516289a2119e083035de4fba6cb21735854ef5 SHA256: 6bf88824cea8d8c66a925e9c6c2fa19144bd3539b4ea8aad9160c8d83b1fe4e1 Microsoft.TestPlatform.Utilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.Utilities.dll MD5: c273ea7a862251766f7c0219826f8896 SHA1: 18698284531f27be341eae21cbaa5c4c7eee4e06 SHA256: 5e73d2a72a16956604c17874c4efe40686e8fd2d06b33bdf039f61004d6fdcf2 pkg:generic/Microsoft.TestPlatform.Utilities@16.11.0 Microsoft.TestPlatform.Utilities.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.TestPlatform.Utilities.dll MD5: c273ea7a862251766f7c0219826f8896 SHA1: 18698284531f27be341eae21cbaa5c4c7eee4e06 SHA256: 5e73d2a72a16956604c17874c4efe40686e8fd2d06b33bdf039f61004d6fdcf2 Microsoft.VisualStudio.TestPlatform.Common.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.TestPlatform.Common.dll MD5: 05412b8f14822abe76190569e0b28399 SHA1: bbd55017898acb32b2404c42a747f7fa7fafa524 SHA256: 932a36018fd8b41fddfe5e8f7c30a2e2eb98d71a2157f6a66f1f91629f8153ed pkg:generic/Microsoft.VisualStudio.TestPlatform.Common@16.11.0 Microsoft.VisualStudio.TestPlatform.Common.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.TestPlatform.Common.dll MD5: 05412b8f14822abe76190569e0b28399 SHA1: bbd55017898acb32b2404c42a747f7fa7fafa524 SHA256: 932a36018fd8b41fddfe5e8f7c30a2e2eb98d71a2157f6a66f1f91629f8153ed Microsoft.VisualStudio.TestPlatform.ObjectModel.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.TestPlatform.ObjectModel.dll MD5: a19400f825bb795575e7d306469b3792 SHA1: 396f3b197769a05e0ae0d5534e12e56bccd142bf SHA256: 4040e8319a11926207759c0effdeb7c44e111f7f9be500928742f05bb2ffef4e pkg:generic/Microsoft.VisualStudio.TestPlatform.ObjectModel@16.11.0 Microsoft.VisualStudio.TestPlatform.ObjectModel.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.TestPlatform.ObjectModel.dll MD5: a19400f825bb795575e7d306469b3792 SHA1: 396f3b197769a05e0ae0d5534e12e56bccd142bf SHA256: 4040e8319a11926207759c0effdeb7c44e111f7f9be500928742f05bb2ffef4e Microsoft.TestPlatform.CrossPlatEngine.resources.dllDescription:
Microsoft.TestPlatform.CrossPlatEngine File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\cs\Microsoft.TestPlatform.CrossPlatEngine.resources.dllMD5: 427e7a10eb9c5093d713554496368598SHA1: f2c050706126a51b137b55214b49b165a8298c04SHA256: ca634ddefd75f34228652f869df8731fc8d9c8b56843fdbb9d577343fbbe9c65
Evidence Type Source Name Value Confidence Vendor file name Microsoft.TestPlatform.CrossPlatEngine.resources High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.TestPlatform.CrossPlatEngine Low Vendor grokassembly InternalName Microsoft.TestPlatform.CrossPlatEngine.resources.dll Low Vendor grokassembly OriginalFilename Microsoft.TestPlatform.CrossPlatEngine.resources.dll Low Vendor grokassembly ProductName Microsoft.VisualStudio.TestPlatform.CrossPlatEngine Medium Product file name Microsoft.TestPlatform.CrossPlatEngine.resources High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.TestPlatform.CrossPlatEngine High Product grokassembly InternalName Microsoft.TestPlatform.CrossPlatEngine.resources.dll Medium Product grokassembly OriginalFilename Microsoft.TestPlatform.CrossPlatEngine.resources.dll Medium Product grokassembly ProductName Microsoft.VisualStudio.TestPlatform.CrossPlatEngine Highest Version grokassembly ProductVersion 16.11.0 Highest
Related Dependencies Microsoft.VisualStudio.CodeCoverage.Shim.dllDescription:
Microsoft.VisualStudio.CodeCoverage.Shim File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.CodeCoverage.Shim.dllMD5: d8b73579c30e309106f311f48fdc7c1bSHA1: e3fb3fb9716f53ab1238145555f34da98ff73f74SHA256: e943b0c764db6031031026c97a0d89057fa2602a7110e90183429048b6eb6fc7
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.VisualStudio.CodeCoverage Highest Vendor file name Microsoft.VisualStudio.CodeCoverage.Shim High Vendor grokassembly CompanyName Microsoft Highest Vendor grokassembly FileDescription Microsoft.VisualStudio.CodeCoverage.Shim Low Vendor grokassembly InternalName Microsoft.VisualStudio.CodeCoverage.Shim.dll Low Vendor grokassembly OriginalFilename Microsoft.VisualStudio.CodeCoverage.Shim.dll Low Vendor grokassembly ProductName Microsoft.VisualStudio.CodeCoverage.Shim Medium Product dll namespace Microsoft.VisualStudio.CodeCoverage Highest Product file name Microsoft.VisualStudio.CodeCoverage.Shim High Product grokassembly CompanyName Microsoft Low Product grokassembly FileDescription Microsoft.VisualStudio.CodeCoverage.Shim High Product grokassembly InternalName Microsoft.VisualStudio.CodeCoverage.Shim.dll Medium Product grokassembly OriginalFilename Microsoft.VisualStudio.CodeCoverage.Shim.dll Medium Product grokassembly ProductName Microsoft.VisualStudio.CodeCoverage.Shim Highest Version grokassembly FileVersion 16.1000.21.27002 High
Related Dependencies Microsoft.VisualStudio.CodeCoverage.Shim.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Microsoft.VisualStudio.CodeCoverage.Shim.dll MD5: d8b73579c30e309106f311f48fdc7c1b SHA1: e3fb3fb9716f53ab1238145555f34da98ff73f74 SHA256: e943b0c764db6031031026c97a0d89057fa2602a7110e90183429048b6eb6fc7 Microsoft.Win32.SystemEvents.dllDescription:
Microsoft.Win32.SystemEvents
Provides access to Windows system event notifications.
Commonly Used Types:
Microsoft.Win32.SystemEvents File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Microsoft.Win32.SystemEvents.dllMD5: 52c8b8b9b9042e81ac37425279af8080SHA1: 0ddb5d6aeb03a702bc31a652e77943f114b82b4dSHA256: ca495bf6c86b7f092d624928101985a941532d149dcd8acfea170f8a53be8850
Evidence Type Source Name Value Confidence Vendor dll namespace Microsoft.Win32 Highest Vendor file name Microsoft.Win32.SystemEvents High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription Microsoft.Win32.SystemEvents Low Vendor grokassembly InternalName Microsoft.Win32.SystemEvents.dll Low Vendor grokassembly OriginalFilename Microsoft.Win32.SystemEvents.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace Microsoft.Win32 Highest Product file name Microsoft.Win32.SystemEvents High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription Microsoft.Win32.SystemEvents High Product grokassembly InternalName Microsoft.Win32.SystemEvents.dll Medium Product grokassembly OriginalFilename Microsoft.Win32.SystemEvents.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 6.0.21.52210 High
Related Dependencies Microsoft.Win32.SystemEvents.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\runtimes\win\lib\net6.0\Microsoft.Win32.SystemEvents.dll MD5: fe9dbe5dd00cad8e0c009f9d1b642d91 SHA1: 152c49e5314fe9d9dc0dec71bccac7349634c803 SHA256: 142cce4ed8ac9da22d69c38a6f22738abfb22090dc9313e8b58e6f91978e89af pkg:generic/Microsoft.Win32.SystemEvents@6.0.21.52210 Newtonsoft.Json.Bson.dllDescription:
Json.NET BSON .NET Standard 2.0
Json.NET BSON adds support for reading and writing BSON File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Newtonsoft.Json.Bson.dllMD5: 46944e52dbb2982ea49a297902b91ea8SHA1: 0ed43a73f49e0df7b2fa681a627cad7e25074165SHA256: f3c56166d7f90296bbe6b03f64335623c3165ed25948288f1f316fa74dd8327f
Evidence Type Source Name Value Confidence Vendor dll namespace Newtonsoft.Json.Bson Highest Vendor file name Newtonsoft.Json.Bson High Vendor grokassembly CompanyName Newtonsoft Highest Vendor grokassembly FileDescription Json.NET BSON .NET Standard 2.0 Low Vendor grokassembly InternalName Newtonsoft.Json.Bson.dll Low Vendor grokassembly OriginalFilename Newtonsoft.Json.Bson.dll Low Vendor grokassembly ProductName Json.NET BSON Medium Product dll namespace Newtonsoft.Json.Bson Highest Product file name Newtonsoft.Json.Bson High Product grokassembly CompanyName Newtonsoft Low Product grokassembly FileDescription Json.NET BSON .NET Standard 2.0 High Product grokassembly InternalName Newtonsoft.Json.Bson.dll Medium Product grokassembly OriginalFilename Newtonsoft.Json.Bson.dll Medium Product grokassembly ProductName Json.NET BSON Highest Version AssemblyAnalyzer FilteredVersion 1.0.2 Highest
CVE-2024-21907 suppress
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
Newtonsoft.Json.dllDescription:
Json.NET .NET 6.0
Json.NET is a popular high-performance JSON framework for .NET File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Newtonsoft.Json.dllMD5: 86a83a63f12b55fd3718cfbfb577d7dcSHA1: 3df82ebba50086de83aee27c63255e80f2d73f3bSHA256: 4816c4276f575e4d85b80633a0df2eadf29496fe00bdc33cd7843e61373bde0e
Evidence Type Source Name Value Confidence Vendor dll namespace Newtonsoft.Json Highest Vendor file name Newtonsoft.Json High Vendor grokassembly CompanyName Newtonsoft Highest Vendor grokassembly FileDescription Json.NET .NET 6.0 Low Vendor grokassembly InternalName Newtonsoft.Json.dll Low Vendor grokassembly OriginalFilename Newtonsoft.Json.dll Low Vendor grokassembly ProductName Json.NET Medium Product dll namespace Newtonsoft.Json Highest Product file name Newtonsoft.Json High Product grokassembly CompanyName Newtonsoft Low Product grokassembly FileDescription Json.NET .NET 6.0 High Product grokassembly InternalName Newtonsoft.Json.dll Medium Product grokassembly OriginalFilename Newtonsoft.Json.dll Medium Product grokassembly ProductName Json.NET Highest Version AssemblyAnalyzer FilteredVersion 13.0.2 Highest
Newtonsoft.Json.dllDescription:
Json.NET .NET Standard 1.0
Json.NET is a popular high-performance JSON framework for .NET File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\Newtonsoft.Json.dllMD5: 04d49720df76d62bce434f19a0da62d2SHA1: 53d0a3b91036092132f4d0887500b5dc77891d78SHA256: 5d96ee51b2aff592039eebc2ed203d9f55fddf9c0882fb34d3f0e078374954a5
Evidence Type Source Name Value Confidence Vendor dll namespace Newtonsoft.Json Highest Vendor file name Newtonsoft.Json High Vendor grokassembly CompanyName Newtonsoft Highest Vendor grokassembly FileDescription Json.NET .NET Standard 1.0 Low Vendor grokassembly InternalName Newtonsoft.Json.dll Low Vendor grokassembly OriginalFilename Newtonsoft.Json.dll Low Vendor grokassembly ProductName Json.NET Medium Product dll namespace Newtonsoft.Json Highest Product file name Newtonsoft.Json High Product grokassembly CompanyName Newtonsoft Low Product grokassembly FileDescription Json.NET .NET Standard 1.0 High Product grokassembly InternalName Newtonsoft.Json.dll Medium Product grokassembly OriginalFilename Newtonsoft.Json.dll Medium Product grokassembly ProductName Json.NET Highest Version AssemblyAnalyzer FilteredVersion 9.0.1 Highest Version grokassembly ProductVersion 9.0.1 Highest
Related Dependencies Newtonsoft.Json.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\Newtonsoft.Json.dll MD5: 04d49720df76d62bce434f19a0da62d2 SHA1: 53d0a3b91036092132f4d0887500b5dc77891d78 SHA256: 5d96ee51b2aff592039eebc2ed203d9f55fddf9c0882fb34d3f0e078374954a5 CVE-2024-21907 suppress
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
Newtonsoft.Json:13.0.3File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Json Low Vendor msbuild id Newtonsoft Medium Vendor msbuild id Newtonsoft.Json Medium Product hint analyzer vendor net Medium Product msbuild id Json Medium Product msbuild id Newtonsoft.Json Highest Version msbuild version 13.0.3 Highest
Npgsql.EntityFrameworkCore.PostgreSQL.dllDescription:
Npgsql.EntityFrameworkCore.PostgreSQL
PostgreSQL/Npgsql provider for Entity Framework Core. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Npgsql.EntityFrameworkCore.PostgreSQL.dllMD5: bf2135dd0b4a7a8ec6d2ead16c7eb57aSHA1: bfede384b4e8b213d0d558180422917562e84df4SHA256: 4024339ffb23c801a13a281acf8b54f2a0c13184bfd0f583f88c6953662d65ad
Evidence Type Source Name Value Confidence Vendor dll namespace Npgsql.EntityFrameworkCore.PostgreSQL Highest Vendor file name Npgsql.EntityFrameworkCore.PostgreSQL High Vendor grokassembly CompanyName Npgsql Highest Vendor grokassembly FileDescription Npgsql.EntityFrameworkCore.PostgreSQL Low Vendor grokassembly InternalName Npgsql.EntityFrameworkCore.PostgreSQL.dll Low Vendor grokassembly OriginalFilename Npgsql.EntityFrameworkCore.PostgreSQL.dll Low Vendor grokassembly ProductName Npgsql.EntityFrameworkCore.PostgreSQL Medium Vendor msbuild id EntityFrameworkCore Low Vendor msbuild id EntityFrameworkCore.PostgreSQL Low Vendor msbuild id Npgsql Medium Vendor msbuild id Npgsql.EntityFrameworkCore.PostgreSQL Medium Product dll namespace Npgsql.EntityFrameworkCore.PostgreSQL Highest Product file name Npgsql.EntityFrameworkCore.PostgreSQL High Product grokassembly CompanyName Npgsql Low Product grokassembly FileDescription Npgsql.EntityFrameworkCore.PostgreSQL High Product grokassembly InternalName Npgsql.EntityFrameworkCore.PostgreSQL.dll Medium Product grokassembly OriginalFilename Npgsql.EntityFrameworkCore.PostgreSQL.dll Medium Product grokassembly ProductName Npgsql.EntityFrameworkCore.PostgreSQL Highest Product msbuild id EntityFrameworkCore Medium Product msbuild id EntityFrameworkCore.PostgreSQL Medium Product msbuild id Npgsql.EntityFrameworkCore.PostgreSQL Highest Version AssemblyAnalyzer FilteredVersion 6.0.7 Highest Version msbuild version 6.0.7 Highest
Related Dependencies Npgsql.EntityFrameworkCore.PostgreSQL:6.0.7File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Npgsql.EntityFrameworkCore.PostgreSQL@6.0.7 Npgsql.EntityFrameworkCore.PostgreSQL:6.0.7File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/Npgsql.EntityFrameworkCore.PostgreSQL@6.0.7 CVE-2015-0244 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3166 suppress
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10211 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. CWE-94 Improper Control of Generation of Code ('Code Injection'), NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-1115 suppress
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-0241 suppress
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0242 suppress
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0243 suppress
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10127 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:2.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:L/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2020-25695 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2016-5423 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types. CWE-476 NULL Pointer Dereference
CVSSv3:
Base Score: HIGH (8.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2016-7048 suppress
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2020-25694 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-327 Use of a Broken or Risky Cryptographic Algorithm
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-23214 suppress
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.1) Vector: /AV:N/AC:H/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2019-10128 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.1) Vector: /AV:L/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-3167 suppress
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2016-0768 suppress
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2016-0773 suppress
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-7484 suppress
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access. CWE-285 Improper Authorization, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-5424 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv3:
Base Score: HIGH (7.1) Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2017-14798 suppress
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. CWE-61 UNIX Symbolic Link (Symlink) Following, CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.9) Vector: /AV:L/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions:
CVE-2019-10210 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. CWE-522 Insufficiently Protected Credentials
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0061 suppress
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0063 suppress
Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0064 suppress
Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector. CWE-189 Numeric Errors
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0065 suppress
Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, a different vulnerability than CVE-2014-0063. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-5288 suppress
The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2007-2138 suppress
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings." CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2014-0062 suppress
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window. CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv2:
Base Score: MEDIUM (4.9) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0067 suppress
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-8161 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3165 suppress
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-3393 suppress
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0060 suppress
PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0066 suppress
The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2010-0733 suppress
Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations. CWE-189 Numeric Errors
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH secalert@redhat.com - PATCH Vulnerable Software & Versions: (show all )
Npgsql.dllDescription:
Npgsql
Npgsql is the open source .NET data provider for PostgreSQL. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Npgsql.dllMD5: 9bbbe5b13b4af4811f75f092fac09458SHA1: 0d52c3d42f3cd30ef076c746fe43596e28e00853SHA256: 7a2c0f05fc717b039e2ae37ca2c831683b8c5a7cd4fdf90f088d399b4de18e3e
Evidence Type Source Name Value Confidence Vendor dll namespace Npgsql Highest Vendor file name Npgsql High Vendor grokassembly CompanyName Npgsql Highest Vendor grokassembly FileDescription Npgsql Low Vendor grokassembly InternalName Npgsql.dll Low Vendor grokassembly OriginalFilename Npgsql.dll Low Vendor grokassembly ProductName Npgsql Medium Product dll namespace Npgsql Highest Product file name Npgsql High Product grokassembly CompanyName Npgsql Low Product grokassembly FileDescription Npgsql High Product grokassembly InternalName Npgsql.dll Medium Product grokassembly OriginalFilename Npgsql.dll Medium Product grokassembly ProductName Npgsql Highest Version AssemblyAnalyzer FilteredVersion 6.0.7 Highest
NuGet.Frameworks.dllDescription:
NuGet.Frameworks
The understanding of target frameworks for NuGet.Packaging. File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\NuGet.Frameworks.dllMD5: a943ff4524e20e7c456efb37cdbf6952SHA1: c1e695466b22abad8c2908c64fa8bcc8e3d9b383SHA256: bdef879f0a4ab2ad97fe934f54e30aee0d06ad06a3ef292933308fca34906ef8
Evidence Type Source Name Value Confidence Vendor dll namespace NuGet.Frameworks Highest Vendor file name NuGet.Frameworks High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription NuGet.Frameworks Low Vendor grokassembly InternalName NuGet.Frameworks.dll Low Vendor grokassembly OriginalFilename NuGet.Frameworks.dll Low Vendor grokassembly ProductName NuGet Medium Product dll namespace NuGet.Frameworks Highest Product file name NuGet.Frameworks High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription NuGet.Frameworks High Product grokassembly InternalName NuGet.Frameworks.dll Medium Product grokassembly OriginalFilename NuGet.Frameworks.dll Medium Product grokassembly ProductName NuGet Highest Version AssemblyAnalyzer FilteredVersion 5.0.0 Highest
Related Dependencies NuGet.Frameworks.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\NuGet.Frameworks.dll MD5: a943ff4524e20e7c456efb37cdbf6952 SHA1: c1e695466b22abad8c2908c64fa8bcc8e3d9b383 SHA256: bdef879f0a4ab2ad97fe934f54e30aee0d06ad06a3ef292933308fca34906ef8 CVE-2022-30184 suppress
.NET and Visual Studio Information Disclosure Vulnerability NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
ReadWriteSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\ReadWriteSwagger.jsMD5: 2fb28455e421d836a06b87bdb3711b8aSHA1: 78255407ae919443f1295b7fbe80ea5ccff9a3d4SHA256: 67dff2c37270f33068846632f51127ca1f8059d10d2b865dccbb6b70d4fffb76
Evidence Type Source Name Value Confidence
RemainderMailHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\RemainderMailHandler.csprojMD5: 90b22bd1f338865525aacd8f27ccee24SHA1: 64d687d18d24214aad7cccaea7564f088a7a944bSHA256: 3a999d1189a919377a88c93bea923f0acf47c65ad350b0dce8517c77bc89c2e0
Evidence Type Source Name Value Confidence Vendor file name RemainderMailHandler High Product file name RemainderMailHandler High
RemainderMailHandler.dllDescription:
RemainderMailHandler File Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\bin\Debug\net6.0\RemainderMailHandler.dllMD5: 5f15398cc0c4e9666bbb2183148a19daSHA1: 0766227d3a768a233cced8839a7c37ccc88644f3SHA256: 1506e48b132955afa5735ca5fb7256b222a995ae7684533db2c23e1f2e6442fd
Evidence Type Source Name Value Confidence Vendor dll namespace RemainderMailHandler Highest Vendor file name RemainderMailHandler High Vendor grokassembly CompanyName RemainderMailHandler Highest Vendor grokassembly FileDescription RemainderMailHandler Low Vendor grokassembly InternalName RemainderMailHandler.dll Low Vendor grokassembly OriginalFilename RemainderMailHandler.dll Low Vendor grokassembly ProductName RemainderMailHandler Medium Product dll namespace RemainderMailHandler Highest Product file name RemainderMailHandler High Product grokassembly CompanyName RemainderMailHandler Low Product grokassembly FileDescription RemainderMailHandler High Product grokassembly InternalName RemainderMailHandler.dll Medium Product grokassembly OriginalFilename RemainderMailHandler.dll Medium Product grokassembly ProductName RemainderMailHandler Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies RemainderMailHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\obj\Debug\net6.0\RemainderMailHandler.dll MD5: 5f15398cc0c4e9666bbb2183148a19da SHA1: 0766227d3a768a233cced8839a7c37ccc88644f3 SHA256: 1506e48b132955afa5735ca5fb7256b222a995ae7684533db2c23e1f2e6442fd RemainderMailHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\obj\Debug\net6.0\ref\RemainderMailHandler.dll MD5: 6c9217a8e826330b35ff4d6796059e60 SHA1: 531f1fb2db496007efba301b8731c2c30b35d2b5 SHA256: 3633c851bfb9c2207cfb1a371b162544b2953689366d3bdb8163381fa7e9262d pkg:generic/RemainderMailHandler@1.0.0 RemainderMailHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\RemainderMailHandler\obj\Debug\net6.0\refint\RemainderMailHandler.dll MD5: 6c9217a8e826330b35ff4d6796059e60 SHA1: 531f1fb2db496007efba301b8731c2c30b35d2b5 SHA256: 3633c851bfb9c2207cfb1a371b162544b2953689366d3bdb8163381fa7e9262d ReportDownloadHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\ReportDownloadHandler.csprojMD5: 94c4019ea0e551e15f5b55ece9e3bcc0SHA1: a8766b9c2b349c275e6eb32612ef692567571d93SHA256: 7a24ed8a4023cb0c57e29b4820292c71957201a5552cab73c76e3a69e2ec8f7a
Evidence Type Source Name Value Confidence Vendor file name ReportDownloadHandler High Product file name ReportDownloadHandler High
ReportDownloadHandler.dllDescription:
ReportDownloadHandler File Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\bin\Debug\net6.0\ReportDownloadHandler.dllMD5: 9172923a40b8eabd51a0314664d8d557SHA1: 8f4a47e35d4b1851e74122a30816baba15812b6aSHA256: a598b2ed9dcd899160cfab1baa40b2a4ac0c37a8e787424953a417dbe639c111
Evidence Type Source Name Value Confidence Vendor dll namespace ReportDownloadHandler Highest Vendor file name ReportDownloadHandler High Vendor grokassembly CompanyName ReportDownloadHandler Highest Vendor grokassembly FileDescription ReportDownloadHandler Low Vendor grokassembly InternalName ReportDownloadHandler.dll Low Vendor grokassembly OriginalFilename ReportDownloadHandler.dll Low Vendor grokassembly ProductName ReportDownloadHandler Medium Product dll namespace ReportDownloadHandler Highest Product file name ReportDownloadHandler High Product grokassembly CompanyName ReportDownloadHandler Low Product grokassembly FileDescription ReportDownloadHandler High Product grokassembly InternalName ReportDownloadHandler.dll Medium Product grokassembly OriginalFilename ReportDownloadHandler.dll Medium Product grokassembly ProductName ReportDownloadHandler Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies ReportDownloadHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\obj\Debug\net6.0\ReportDownloadHandler.dll MD5: 9172923a40b8eabd51a0314664d8d557 SHA1: 8f4a47e35d4b1851e74122a30816baba15812b6a SHA256: a598b2ed9dcd899160cfab1baa40b2a4ac0c37a8e787424953a417dbe639c111 ReportDownloadHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\obj\Debug\net6.0\ref\ReportDownloadHandler.dll MD5: abfe395f6da2636f75d4312c460dbbde SHA1: 1003d1acc26ba90c6b551206371371c14e8d5356 SHA256: e027d424506dce880b5c98af4bc68f666cb3c20dfff05113512eb9b48dba759e pkg:generic/ReportDownloadHandler@1.0.0 ReportDownloadHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\ReportDownloadHandler\obj\Debug\net6.0\refint\ReportDownloadHandler.dll MD5: abfe395f6da2636f75d4312c460dbbde SHA1: 1003d1acc26ba90c6b551206371371c14e8d5356 SHA256: e027d424506dce880b5c98af4bc68f666cb3c20dfff05113512eb9b48dba759e ReportSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\ReportSwagger.jsMD5: d8abcda055f5c44ff287003ced174772SHA1: c7e1d0a584a1f780d2c7eb4fc8276371776f9c54SHA256: 3311a59dd46c70bc5883ec7fbac0f819fc97aacb3c591bd0a9b9418f14fe158e
Evidence Type Source Name Value Confidence
RulesEngine:5.0.3File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id RulesEngine Medium Vendor msbuild id RulesEngine Low Product msbuild id RulesEngine Highest Version msbuild version 5.0.3 Highest
Related Dependencies RulesEngine:5.0.3File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/RulesEngine@5.0.3 Runnable2_eSign2.1_Single.jar (shaded: commons-codec:commons-codec:1.9)Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-codec/commons-codec/pom.xmlMD5: 921b8b50ce6dc0c5a8605d7c7011bd37SHA1: f5357ff0f308600af3660bf00a8be3415a335723SHA256: e5efcf039cd909688c201dc5479b144fd6f01f0e40252b7fc5e7d2e1b5c07990
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-codec/ Medium Version pom parent-version 1.9 Low Version pom version 1.9 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: commons-codec:commons-codec:1.9)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-codec/commons-codec/pom.xml MD5: 921b8b50ce6dc0c5a8605d7c7011bd37 SHA1: f5357ff0f308600af3660bf00a8be3415a335723 SHA256: e5efcf039cd909688c201dc5479b144fd6f01f0e40252b7fc5e7d2e1b5c07990 pkg:maven/commons-codec/commons-codec@1.9 Runnable2_eSign2.1_Single.jar (shaded: commons-io:commons-io:2.6)Description:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-io/commons-io/pom.xmlMD5: 142e515fa628cd8379aaac94ab237a8cSHA1: 5060835593e5b6ed18c82fc2e782f0a3c30a00b1SHA256: 0c23863893a2291f5a7afdbd8d15923b3948afd87e563fa341cdcf6eae338a60
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-io/ Medium Version pom parent-version 2.6 Low Version pom version 2.6 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: commons-io:commons-io:2.6)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-io/commons-io/pom.xml MD5: 142e515fa628cd8379aaac94ab237a8c SHA1: 5060835593e5b6ed18c82fc2e782f0a3c30a00b1 SHA256: 0c23863893a2291f5a7afdbd8d15923b3948afd87e563fa341cdcf6eae338a60 pkg:maven/commons-io/commons-io@2.6 CVE-2024-47554 (OSSINDEX) suppress
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. CWE-400 Uncontrolled Resource Consumption
CVSSv2:
Base Score: MEDIUM (5.300000190734863) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:commons-io:commons-io:2.6:*:*:*:*:*:*:* CVE-2021-29425 suppress
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
OSSINDEX - [CVE-2021-29425] CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') OSSIndex - https://github.com/apache/commons-io/pull/52 OSSIndex - https://issues.apache.org/jira/browse/IO-556 OSSIndex - https://issues.apache.org/jira/browse/IO-559 af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - EXPLOIT,ISSUE_TRACKING,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
Runnable2_eSign2.1_Single.jar (shaded: commons-logging:commons-logging:1.2)Description:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-logging/commons-logging/pom.xmlMD5: 51509fc18ecc54daf0a030f8a830deb0SHA1: 075c03ba4b01932842a996ef8d3fc1ab61ddeac2SHA256: c91ab5aa570d86f6fd07cc158ec6bc2c50080402972ee9179fe24100739fbb20
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-logging Low Vendor pom developer email baliuka@apache.org Low Vendor pom developer email costin@apache.org Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dennisl@apache.org Low Vendor pom developer email donaldp@apache.org Low Vendor pom developer email morgand@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rsitze@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer email skitching@apache.org Low Vendor pom developer email tn@apache.org Low Vendor pom developer id baliuka Medium Vendor pom developer id bstansberry Medium Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dennisl Medium Vendor pom developer id donaldp Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id skitching Medium Vendor pom developer id tn Medium Vendor pom developer name Brian Stansberry Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dennis Lundberg Medium Vendor pom developer name Juozas Baliuka Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Peter Donald Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Simon Kitching Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer org Apache Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom groupid commons-logging Highest Vendor pom name Apache Commons Logging High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Product pom artifactid commons-logging Highest Product pom developer email baliuka@apache.org Low Product pom developer email costin@apache.org Low Product pom developer email craigmcc@apache.org Low Product pom developer email dennisl@apache.org Low Product pom developer email donaldp@apache.org Low Product pom developer email morgand@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rsitze@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer email skitching@apache.org Low Product pom developer email tn@apache.org Low Product pom developer id baliuka Low Product pom developer id bstansberry Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id dennisl Low Product pom developer id donaldp Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id skitching Low Product pom developer id tn Low Product pom developer name Brian Stansberry Low Product pom developer name Costin Manolache Low Product pom developer name Craig McClanahan Low Product pom developer name Dennis Lundberg Low Product pom developer name Juozas Baliuka Low Product pom developer name Morgan Delagrange Low Product pom developer name Peter Donald Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Simon Kitching Low Product pom developer name Thomas Neidhart Low Product pom developer org Apache Low Product pom developer org The Apache Software Foundation Low Product pom groupid commons-logging Highest Product pom name Apache Commons Logging High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-logging/ Medium Version pom parent-version 1.2 Low Version pom version 1.2 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: commons-logging:commons-logging:1.2)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/commons-logging/commons-logging/pom.xml MD5: 51509fc18ecc54daf0a030f8a830deb0 SHA1: 075c03ba4b01932842a996ef8d3fc1ab61ddeac2 SHA256: c91ab5aa570d86f6fd07cc158ec6bc2c50080402972ee9179fe24100739fbb20 pkg:maven/commons-logging/commons-logging@1.2 Runnable2_eSign2.1_Single.jar (shaded: log4j:log4j:1.2.16)Description:
Apache Log4j 1.2 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/log4j/log4j/pom.xml
MD5: e15d65d6c97d87704176c1e9338a2adb
SHA1: 88efb1b8d3d993fe339e9e2b201c75eed57d4c65
SHA256: 2b1e9f1055cf0b4a4659aaf474b65e842d5c1dc580b5c4e0238ef63470d110fd
Evidence Type Source Name Value Confidence Vendor pom artifactid log4j Low Vendor pom groupid log4j Highest Vendor pom name Apache Log4j High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://www.apache.org Medium Vendor pom url http://logging.apache.org/log4j/1.2/ Highest Product pom artifactid log4j Highest Product pom groupid log4j Highest Product pom name Apache Log4j High Product pom organization name Apache Software Foundation Low Product pom organization url http://www.apache.org Low Product pom url http://logging.apache.org/log4j/1.2/ Medium Version pom version 1.2.16 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: log4j:log4j:1.2.16)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/log4j/log4j/pom.xml MD5: e15d65d6c97d87704176c1e9338a2adb SHA1: 88efb1b8d3d993fe339e9e2b201c75eed57d4c65 SHA256: 2b1e9f1055cf0b4a4659aaf474b65e842d5c1dc580b5c4e0238ef63470d110fd pkg:maven/log4j/log4j@1.2.16 CVE-2019-17571 suppress
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
OSSINDEX - [CVE-2019-17571] CWE-502: Deserialization of Untrusted Data OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-17571 OSSIndex - https://bugzilla.redhat.com/show_bug.cgi?id=1785616 OSSIndex - https://issues.apache.org/jira/browse/LOG4J2-1863 OSSIndex - https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3E af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-9493 suppress
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-23305 suppress
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
OSSINDEX - [CVE-2022-23305] CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23305 OSSIndex - https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y OSSIndex - https://logging.apache.org/log4j/1.2/index.html OSSIndex - https://logging.apache.org/log4j/2.x/security.html af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY security@apache.org - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-23302 suppress
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
OSSINDEX - [CVE-2022-23302] CWE-502: Deserialization of Untrusted Data OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23302 OSSIndex - https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w OSSIndex - https://logging.apache.org/log4j/1.2/index.html af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY security@apache.org - MAILING_LIST,MITIGATION,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-23307 suppress
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2021-4104 (OSSINDEX) suppress
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2021-4104 for details CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:log4j:log4j:1.2.16:*:*:*:*:*:*:* CVE-2023-26464 suppress
** UNSUPPORTED WHEN ASSIGNED **
When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested)
hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.
This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
Runnable2_eSign2.1_Single.jar (shaded: org.apache.pdfbox:fontbox:2.0.8)Description:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/org.apache.pdfbox/fontbox/pom.xmlMD5: c2c9b539ef6acfb4153d1799642b2589SHA1: 6daaf6eec25aeb9adac1a023f3edb53fe4c45b55SHA256: 1f5d07c587feefd1bbaa73c45c432cf999dd3c0fcc8b81d274cd5906b43d8803
Evidence Type Source Name Value Confidence Vendor pom artifactid fontbox Low Vendor pom groupid org.apache.pdfbox Highest Vendor pom name Apache FontBox High Vendor pom parent-artifactid pdfbox-parent Low Vendor pom url http://pdfbox.apache.org/ Highest Product pom artifactid fontbox Highest Product pom groupid org.apache.pdfbox Highest Product pom name Apache FontBox High Product pom parent-artifactid pdfbox-parent Medium Product pom url http://pdfbox.apache.org/ Medium Version pom version 2.0.8 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: org.apache.pdfbox:fontbox:2.0.8)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/org.apache.pdfbox/fontbox/pom.xml MD5: c2c9b539ef6acfb4153d1799642b2589 SHA1: 6daaf6eec25aeb9adac1a023f3edb53fe4c45b55 SHA256: 1f5d07c587feefd1bbaa73c45c432cf999dd3c0fcc8b81d274cd5906b43d8803 pkg:maven/org.apache.pdfbox/fontbox@2.0.8 CVE-2018-8036 (OSSINDEX) suppress
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2018-8036 for details CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.apache.pdfbox:fontbox:2.0.8:*:*:*:*:*:*:* Runnable2_eSign2.1_Single.jar (shaded: org.apache.pdfbox:pdfbox:2.0.8)Description:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jar\META-INF/maven/org.apache.pdfbox/pdfbox/pom.xmlMD5: 1d4ccea88c8090584ab46aaaf631c937SHA1: add23697d741b786a2cae25a79cfe3abcac431bdSHA256: acefad4963635a4222d924a508e06beda354c392d936916bfb15009d0fb522b5
Evidence Type Source Name Value Confidence Vendor pom artifactid pdfbox Low Vendor pom groupid org.apache.pdfbox Highest Vendor pom name Apache PDFBox High Vendor pom parent-artifactid pdfbox-parent Low Product pom artifactid pdfbox Highest Product pom groupid org.apache.pdfbox Highest Product pom name Apache PDFBox High Product pom parent-artifactid pdfbox-parent Medium Version pom version 2.0.8 Highest
Related Dependencies Runnable2_eSign2.1_Single.jar (shaded: org.apache.pdfbox:pdfbox:2.0.8)File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar\META-INF/maven/org.apache.pdfbox/pdfbox/pom.xml MD5: 1d4ccea88c8090584ab46aaaf631c937 SHA1: add23697d741b786a2cae25a79cfe3abcac431bd SHA256: acefad4963635a4222d924a508e06beda354c392d936916bfb15009d0fb522b5 pkg:maven/org.apache.pdfbox/pdfbox@2.0.8 CVE-2018-8036 suppress
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-11797 suppress
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree. NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-27807 suppress
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. CWE-834 Excessive Iteration
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-27906 suppress
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. CWE-789 Memory Allocation with Excessive Size Value, NVD-CWE-Other
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-31811 suppress
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-31812 suppress
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. CWE-834 Excessive Iteration, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
OSSINDEX - [CVE-2021-31812] CWE-834: Excessive Iteration OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-31812 OSSIndex - https://lists.apache.org/thread.html/rf251f6c358087107f8c23473468b279d59d50a75db6b4768165c78d3@%3Cannounce.apache.org%3E af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
Runnable2_eSign2.1_Single.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\eSign_2.1_Utility\Runnable2_eSign2.1_Single.jarMD5: 663df0c72ffea2cf6367dadddcf07468SHA1: 8a55aff1990f7267453bc1439939fbecd86908e1SHA256: 225e08266a3bd4d2bdf7f4962a07a2fc77d26ae21f64d183dd2818d801f67558
Evidence Type Source Name Value Confidence Vendor file name Runnable2_eSign2.1_Single High Vendor jar package name apache Highest Vendor jar package name bouncycastle Low Vendor manifest: org.apache.log4j Implementation-Vendor "Apache Software Foundation" Medium Product file name Runnable2_eSign2.1_Single High Product jar package name log4j Highest Product manifest: org.apache.log4j Implementation-Title log4j Medium Version file name Runnable2_eSign2.1_Single Medium Version file version 2.1 High Version manifest: org.apache.log4j Implementation-Version 1.2.16 Medium
Related Dependencies Runnable2_eSign2.1_Single.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Runnable2_eSign2.1_Single.jar MD5: 663df0c72ffea2cf6367dadddcf07468 SHA1: 8a55aff1990f7267453bc1439939fbecd86908e1 SHA256: 225e08266a3bd4d2bdf7f4962a07a2fc77d26ae21f64d183dd2818d801f67558 cpe:2.3:a:apache:log4j:2.1:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2021-44228 suppress
CISA Known Exploited Vulnerability: Product: Apache Log4j2 Name: Apache Log4j2 Remote Code Execution Vulnerability Date Added: 2021-12-10 Description: Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. Required Action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available. Due Date: 2021-12-24 Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. CWE-400 Uncontrolled Resource Consumption, CWE-502 Deserialization of Untrusted Data, CWE-20 Improper Input Validation, CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv3:
Base Score: CRITICAL (10.0) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK,EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK,PRODUCT,US_GOVERNMENT_RESOURCE af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - BROKEN_LINK,EXPLOIT,THIRD_PARTY_ADVISORY security@apache.org - BROKEN_LINK,PRODUCT,US_GOVERNMENT_RESOURCE security@apache.org - EXPLOIT,MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY,VENDOR_ADVISORY security@apache.org - RELEASE_NOTES security@apache.org - RELEASE_NOTES security@apache.org - RELEASE_NOTES,VENDOR_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2017-5645 suppress
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - ISSUE_TRACKING,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - PATCH security@apache.org - PATCH security@apache.org - PATCH security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2021-45046 suppress
CISA Known Exploited Vulnerability: Product: Apache Log4j2 Name: Apache Log4j2 Deserialization of Untrusted Data Vulnerability Date Added: 2023-05-01 Description: Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. Required Action: Apply updates per vendor instructions. Due Date: 2023-05-22 Notes: https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default. CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv3:
Base Score: CRITICAL (9.0) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.1) Vector: /AV:N/AC:H/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - NOT_APPLICABLE af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE security@apache.org - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,RELEASE_NOTES security@apache.org - MAILING_LIST,RELEASE_NOTES security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MITIGATION,RELEASE_NOTES,VENDOR_ADVISORY security@apache.org - NOT_APPLICABLE security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE Vulnerable Software & Versions: (show all )
CVE-2021-44832 suppress
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2. CWE-20 Improper Input Validation, CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv3:
Base Score: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,PATCH,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-45105 suppress
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1. CWE-20 Improper Input Validation, CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY security@apache.org - MAILING_LIST,MITIGATION,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - RELEASE_NOTES,VENDOR_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE security@apache.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2020-9488 suppress
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 CWE-295 Improper Certificate Validation
CVSSv3:
Base Score: LOW (3.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MITIGATION,PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,MITIGATION,PATCH,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
SixLabors.ImageSharp.dllDescription:
SixLabors.ImageSharp
A new, fully featured, fully managed, cross-platform, 2D graphics API for .NET File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\SixLabors.ImageSharp.dllMD5: a40efa1d42a3a30f36c02f51cef30df7SHA1: 429c492836c632520601eb0fb2713cbff6d09cefSHA256: 0a15ca64cd2d91dc94481055fdfe29a2324385f8693f0ef56e2431405387f32a
Evidence Type Source Name Value Confidence Vendor dll namespace SixLabors Highest Vendor dll namespace SixLabors.ImageSharp Highest Vendor file name SixLabors.ImageSharp High Vendor grokassembly CompanyName Six Labors Highest Vendor grokassembly FileDescription SixLabors.ImageSharp Low Vendor grokassembly InternalName SixLabors.ImageSharp.dll Low Vendor grokassembly OriginalFilename SixLabors.ImageSharp.dll Low Vendor grokassembly ProductName SixLabors.ImageSharp Medium Vendor msbuild id ImageSharp Low Vendor msbuild id SixLabors Medium Vendor msbuild id SixLabors.ImageSharp Medium Product dll namespace SixLabors Highest Product dll namespace SixLabors.ImageSharp Highest Product file name SixLabors.ImageSharp High Product grokassembly CompanyName Six Labors Low Product grokassembly FileDescription SixLabors.ImageSharp High Product grokassembly InternalName SixLabors.ImageSharp.dll Medium Product grokassembly OriginalFilename SixLabors.ImageSharp.dll Medium Product grokassembly ProductName SixLabors.ImageSharp Highest Product msbuild id ImageSharp Medium Product msbuild id SixLabors.ImageSharp Highest Version AssemblyAnalyzer FilteredVersion 3.0.1 Highest Version msbuild version 3.0.1 Highest
Related Dependencies SixLabors.ImageSharp:3.0.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj pkg:nuget/SixLabors.ImageSharp@3.0.1 CVE-2024-32035 suppress
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. The problem has been patched in v3.1.4 and v2.1.8. CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PRODUCT af854a3a-2127-422b-91ae-364da2661108 - PRODUCT af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY security-advisories@github.com - PATCH security-advisories@github.com - PATCH security-advisories@github.com - PRODUCT security-advisories@github.com - PRODUCT security-advisories@github.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2024-32036 suppress
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8. CWE-226 Sensitive Information in Resource Not Removed Before Reuse, CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY security-advisories@github.com - PATCH security-advisories@github.com - PATCH security-advisories@github.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
StatusEventHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\StatusEventHandler.csprojMD5: 0367bb03a7eacda97fb2be2829feafeaSHA1: ec7c5db747524d293de6b0ab9ea3ec43b3490243SHA256: a255415e858ed69187418c82af63862837177f4da329d57f590a677bc57ccced
Evidence Type Source Name Value Confidence Vendor file name StatusEventHandler High Product file name StatusEventHandler High
StatusEventHandler.dllDescription:
StatusEventHandler File Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\bin\Debug\net6.0\StatusEventHandler.dllMD5: 30a1aec1a475aaf8a543853977fab276SHA1: c80a2b18e2e35a6a99d40b54422e0d4bdc49edafSHA256: 53f590732538cf8ffc0ceff29bfe3ef6ff670e726e0c24e406773471de4a277f
Evidence Type Source Name Value Confidence Vendor dll namespace StatusEventHandler Highest Vendor file name StatusEventHandler High Vendor grokassembly CompanyName StatusEventHandler Highest Vendor grokassembly FileDescription StatusEventHandler Low Vendor grokassembly InternalName StatusEventHandler.dll Low Vendor grokassembly OriginalFilename StatusEventHandler.dll Low Vendor grokassembly ProductName StatusEventHandler Medium Product dll namespace StatusEventHandler Highest Product file name StatusEventHandler High Product grokassembly CompanyName StatusEventHandler Low Product grokassembly FileDescription StatusEventHandler High Product grokassembly InternalName StatusEventHandler.dll Medium Product grokassembly OriginalFilename StatusEventHandler.dll Medium Product grokassembly ProductName StatusEventHandler Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies StatusEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\obj\Debug\net6.0\StatusEventHandler.dll MD5: 30a1aec1a475aaf8a543853977fab276 SHA1: c80a2b18e2e35a6a99d40b54422e0d4bdc49edaf SHA256: 53f590732538cf8ffc0ceff29bfe3ef6ff670e726e0c24e406773471de4a277f StatusEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\obj\Debug\net6.0\ref\StatusEventHandler.dll MD5: bc968b3c8c1e249fcdb6830dc9f64779 SHA1: 7199ab60cc6f7c2340e4bb718c3214ee7de5fb75 SHA256: 75942d6aeae5c947671084736ba9df3dbf559e742d00d3b482a58d312c30caa7 pkg:generic/StatusEventHandler@1.0.0 StatusEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\StatusEventHandler\obj\Debug\net6.0\refint\StatusEventHandler.dll MD5: bc968b3c8c1e249fcdb6830dc9f64779 SHA1: 7199ab60cc6f7c2340e4bb718c3214ee7de5fb75 SHA256: 75942d6aeae5c947671084736ba9df3dbf559e742d00d3b482a58d312c30caa7 SwaggerController.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\controller\SwaggerController.jsMD5: fbb9c42c9574d8659a0cbe5295f81cdfSHA1: fb37a7f99eb7c42d3b151b80f2a73804c1a24053SHA256: df3b37f7e1805a91a7a80755b4b5990d71a874b042fadf7dd4f13eba62e27025
Evidence Type Source Name Value Confidence
Swashbuckle.AspNetCore.Examples.dllDescription:
Swashbuckle.AspNetCore.Examples
Adds the SwaggerRequestExample and SwaggerResponseExample attribute for Swashbuckle. This will populate the example property of a schema object in the output swagger. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Swashbuckle.AspNetCore.Examples.dllMD5: e8e4af0942a93e9e14a41db9da877386SHA1: cf0e97d388fb10d4c3bd3e38272231e725917af7SHA256: e49c970927f55ca30d51ef02a72a8018d636d01dee49da8c1a6cb9e151772b0b
Evidence Type Source Name Value Confidence Vendor dll namespace Swashbuckle.AspNetCore.Examples Highest Vendor file name Swashbuckle.AspNetCore.Examples High Vendor grokassembly CompanyName Matt Frear Highest Vendor grokassembly FileDescription Swashbuckle.AspNetCore.Examples Low Vendor grokassembly InternalName Swashbuckle.AspNetCore.Examples.dll Low Vendor grokassembly OriginalFilename Swashbuckle.AspNetCore.Examples.dll Low Vendor grokassembly ProductName Swashbuckle.AspNetCore.Examples Medium Vendor msbuild id AspNetCore Low Vendor msbuild id AspNetCore.Examples Low Vendor msbuild id Swashbuckle Medium Vendor msbuild id Swashbuckle.AspNetCore.Examples Medium Product dll namespace Swashbuckle.AspNetCore.Examples Highest Product file name Swashbuckle.AspNetCore.Examples High Product grokassembly CompanyName Matt Frear Low Product grokassembly FileDescription Swashbuckle.AspNetCore.Examples High Product grokassembly InternalName Swashbuckle.AspNetCore.Examples.dll Medium Product grokassembly OriginalFilename Swashbuckle.AspNetCore.Examples.dll Medium Product grokassembly ProductName Swashbuckle.AspNetCore.Examples Highest Product msbuild id AspNetCore Medium Product msbuild id AspNetCore.Examples Medium Product msbuild id Swashbuckle.AspNetCore.Examples Highest Version AssemblyAnalyzer FilteredVersion 2.9.0 Highest Version grokassembly ProductVersion 2.9.0 Highest Version msbuild version 2.9.0 Highest
Related Dependencies Swashbuckle.AspNetCore.Examples:2.9.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Swashbuckle.AspNetCore.Examples@2.9.0 Swashbuckle.AspNetCore.Swagger.dllDescription:
Swashbuckle.AspNetCore.Swagger
Middleware to expose Swagger JSON endpoints from API's built on ASP.NET Core File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Swashbuckle.AspNetCore.Swagger.dllMD5: 1561a8168854d0d464856cd980acc455SHA1: 26e98626430375d7c4842be8d0a25e8d7026c5b0SHA256: c797237da5e07d88a1576d5edbcd2e775e0b5f506d464e2d3b40e5985593c564
Evidence Type Source Name Value Confidence Vendor dll namespace Swashbuckle.AspNetCore.Swagger Highest Vendor file name Swashbuckle.AspNetCore.Swagger High Vendor grokassembly FileDescription Swashbuckle.AspNetCore.Swagger Low Vendor grokassembly InternalName Swashbuckle.AspNetCore.Swagger.dll Low Vendor grokassembly OriginalFilename Swashbuckle.AspNetCore.Swagger.dll Low Vendor grokassembly ProductName Swashbuckle.SwaggerCore Medium Vendor msbuild id AspNetCore Low Vendor msbuild id AspNetCore.Swagger Low Vendor msbuild id Swashbuckle Medium Vendor msbuild id Swashbuckle.AspNetCore.Swagger Medium Product dll namespace Swashbuckle.AspNetCore.Swagger Highest Product file name Swashbuckle.AspNetCore.Swagger High Product grokassembly FileDescription Swashbuckle.AspNetCore.Swagger High Product grokassembly InternalName Swashbuckle.AspNetCore.Swagger.dll Medium Product grokassembly OriginalFilename Swashbuckle.AspNetCore.Swagger.dll Medium Product grokassembly ProductName Swashbuckle.SwaggerCore Highest Product msbuild id AspNetCore Medium Product msbuild id AspNetCore.Swagger Medium Product msbuild id Swashbuckle.AspNetCore.Swagger Highest Version AssemblyAnalyzer FilteredVersion 2.4.0 Highest Version grokassembly ProductVersion 2.4.0 Highest Version msbuild version 2.4.0 Highest
Related Dependencies Swashbuckle.AspNetCore.Swagger:2.4.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Swashbuckle.AspNetCore.Swagger@2.4.0 Swashbuckle.AspNetCore.SwaggerGen.dllDescription:
Swashbuckle.AspNetCore.SwaggerGen
Swagger Generator for API's built on ASP.NET Core File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Swashbuckle.AspNetCore.SwaggerGen.dllMD5: 5b00e76687a228a01f7432e8b49a3cc4SHA1: 5c4f85708881a9ca9de58af46768bfec55b30a97SHA256: 210ead724c458892b0ab805107e5cb2b44c74d169e89f56e851a71b6e4182747
Evidence Type Source Name Value Confidence Vendor dll namespace Swashbuckle.AspNetCore.SwaggerGen Highest Vendor file name Swashbuckle.AspNetCore.SwaggerGen High Vendor grokassembly CompanyName Swashbuckle.AspNetCore.SwaggerGen Highest Vendor grokassembly FileDescription Swashbuckle.AspNetCore.SwaggerGen Low Vendor grokassembly InternalName Swashbuckle.AspNetCore.SwaggerGen.dll Low Vendor grokassembly OriginalFilename Swashbuckle.AspNetCore.SwaggerGen.dll Low Vendor grokassembly ProductName Swashbuckle.AspNetCore.SwaggerGen Medium Vendor msbuild id AspNetCore Low Vendor msbuild id AspNetCore.SwaggerGen Low Vendor msbuild id Swashbuckle Medium Vendor msbuild id Swashbuckle.AspNetCore.SwaggerGen Medium Product dll namespace Swashbuckle.AspNetCore.SwaggerGen Highest Product file name Swashbuckle.AspNetCore.SwaggerGen High Product grokassembly CompanyName Swashbuckle.AspNetCore.SwaggerGen Low Product grokassembly FileDescription Swashbuckle.AspNetCore.SwaggerGen High Product grokassembly InternalName Swashbuckle.AspNetCore.SwaggerGen.dll Medium Product grokassembly OriginalFilename Swashbuckle.AspNetCore.SwaggerGen.dll Medium Product grokassembly ProductName Swashbuckle.AspNetCore.SwaggerGen Highest Product msbuild id AspNetCore Medium Product msbuild id AspNetCore.SwaggerGen Medium Product msbuild id Swashbuckle.AspNetCore.SwaggerGen Highest Version AssemblyAnalyzer FilteredVersion 2.4.0 Highest Version grokassembly ProductVersion 2.4.0 Highest Version msbuild version 2.4.0 Highest
Related Dependencies Swashbuckle.AspNetCore.SwaggerGen:2.4.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj pkg:nuget/Swashbuckle.AspNetCore.SwaggerGen@2.4.0 System.Drawing.Common.dllDescription:
System.Drawing.Common
Provides access to GDI+ graphics functionality.
Commonly Used Types:
System.Drawing.Bitmap
System.Drawing.BitmapData
System.Drawing.Brush
System.Drawing.Font
System.Drawing.Graphics
System.Drawing.Icon
Unix support is disabled by default. See https://aka.ms/systemdrawingnonwindows for more information. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\System.Drawing.Common.dllMD5: 916949ef1ba93758bd98d58a6b278092SHA1: 2f1aaf6a045be385c7f6c69d1aa8f7ed232baa04SHA256: 98d07e6b1e7d3641a8608a360b3dc273fe8a0f78926b6e1e5f679a7a074d491f
Evidence Type Source Name Value Confidence Vendor dll namespace System Highest Vendor dll namespace System.Drawing Highest Vendor file name System.Drawing.Common High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription System.Drawing.Common Low Vendor grokassembly InternalName System.Drawing.Common.dll Low Vendor grokassembly OriginalFilename System.Drawing.Common.dll Low Vendor grokassembly ProductName Microsoft® .NET Medium Product dll namespace System Highest Product dll namespace System.Drawing Highest Product file name System.Drawing.Common High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription System.Drawing.Common High Product grokassembly InternalName System.Drawing.Common.dll Medium Product grokassembly OriginalFilename System.Drawing.Common.dll Medium Product grokassembly ProductName Microsoft® .NET Highest Version grokassembly FileVersion 6.0.21.52210 High
Related Dependencies System.Drawing.Common.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\runtimes\unix\lib\net6.0\System.Drawing.Common.dll MD5: e4a29e2a788763b0f32bab6a3d7349cf SHA1: 9ee3c82ebeab89a93af55fc844f32ecc436e6998 SHA256: 89ea595ccb1fd1384480c1e30bd487c92af5d06d3b06f295323eff601acd9019 pkg:generic/System.Drawing.Common@6.0.21.52210 System.Drawing.Common.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\runtimes\win\lib\net6.0\System.Drawing.Common.dll MD5: 19ff37e998f5fb9f3f4f29b5f2e139dd SHA1: 49b8a72582df281db172d5e71f1debe9b7063829 SHA256: 4d3001697df50cca54f32ed2dbbd1f3f415b48d5d756b1bf9500a43ae9b68da0 pkg:generic/System.Drawing.Common@6.0.21.52210 System.Drawing.Common:6.0.0File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\MerchantManagement.API.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id Drawing Low Vendor msbuild id Drawing.Common Low Vendor msbuild id System Medium Vendor msbuild id System.Drawing.Common Medium Product msbuild id Drawing Medium Product msbuild id Drawing.Common Medium Product msbuild id System.Drawing.Common Highest Version msbuild version 6.0.0 Highest
System.IdentityModel.Tokens.Jwt.dllDescription:
System.IdentityModel.Tokens.Jwt
Includes types that provide support for creating, serializing and validating JSON Web Tokens. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\System.IdentityModel.Tokens.Jwt.dllMD5: 9f46bcace87297112eb2d5c014c567dfSHA1: 67233c3f7b1a18e42922cdc8090cc8b3ae3df216SHA256: d846a6c25639740ab0bd169734859678b32af9c371b544c5faf5960f70df3727
Evidence Type Source Name Value Confidence Vendor dll namespace System.IdentityModel.Tokens.Jwt Highest Vendor file name System.IdentityModel.Tokens.Jwt High Vendor grokassembly CompanyName Microsoft Corporation. Highest Vendor grokassembly FileDescription System.IdentityModel.Tokens.Jwt Low Vendor grokassembly InternalName System.IdentityModel.Tokens.Jwt.dll Low Vendor grokassembly OriginalFilename System.IdentityModel.Tokens.Jwt.dll Low Vendor grokassembly ProductName Microsoft IdentityModel Medium Product dll namespace System.IdentityModel.Tokens.Jwt Highest Product file name System.IdentityModel.Tokens.Jwt High Product grokassembly CompanyName Microsoft Corporation. Low Product grokassembly FileDescription System.IdentityModel.Tokens.Jwt High Product grokassembly InternalName System.IdentityModel.Tokens.Jwt.dll Medium Product grokassembly OriginalFilename System.IdentityModel.Tokens.Jwt.dll Medium Product grokassembly ProductName Microsoft IdentityModel Highest Version AssemblyAnalyzer FilteredVersion 6.25.1.31130 Highest Version grokassembly FileVersion 6.25.1.31130 High
pkg:generic/System.IdentityModel.Tokens.Jwt@6.25.1.31130 (Confidence :Medium)cpe:2.3:a:identitymodel_project:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identity_model:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:microsoft:identitymodel:6.25.1.31130:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-21319 suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:2.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
System.IdentityModel.Tokens.Jwt:6.25.1File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement\MerchantManagement.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id IdentityModel Low Vendor msbuild id IdentityModel.Tokens.Jwt Low Vendor msbuild id System Medium Vendor msbuild id System.IdentityModel.Tokens.Jwt Medium Product msbuild id IdentityModel Medium Product msbuild id IdentityModel.Tokens.Jwt Medium Product msbuild id System.IdentityModel.Tokens.Jwt Highest Version msbuild version 6.25.1 Highest
CVE-2024-21319 (OSSINDEX) suppress
Microsoft Identity Denial of service vulnerability CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (6.800000190734863) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:*:System.IdentityModel.Tokens.Jwt:6.25.1:*:*:*:*:*:*:* TermsAndConditionsSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\TermsAndConditionsSwagger.jsMD5: 9c60dd3a3cdf4ee103450f8591c57170SHA1: 388661ea976810cb5e4b60110924a0519c6af52dSHA256: 0cb43a5de0adba45d2747defe5cc5bc363ca7d17f51baa71c93e980c7c5a0166
Evidence Type Source Name Value Confidence
Tesseract.dllDescription:
Tesseract
Tesseract 4 adds a new neural net (LSTM) based OCR engine which is focused on line recognition, but also still supports the legacy Tesseract OCR engine of Tesseract 3 which works by recognizing character patterns. Compatibility with Tesseract 3 is enabled by using the Legacy OCR Engine mode (--oem 0). It also needs traineddata files which support the legacy engine, for example those from the tessdata repository. File Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\Tesseract.dllMD5: 8156de188eb6fe31980c95f38936a841SHA1: fc0a366b6f1fd45ba123ce4f6a1a47ac974872bfSHA256: 621ac53ad55c7f9d87fd44a7ff4b196a0e62fe895e1733a42fee4ba5eb067d2b
Evidence Type Source Name Value Confidence Vendor dll namespace Tesseract Highest Vendor file name Tesseract High Vendor grokassembly CompanyName Charles Weld Highest Vendor grokassembly FileDescription Tesseract Low Vendor grokassembly InternalName Tesseract.dll Low Vendor grokassembly OriginalFilename Tesseract.dll Low Vendor grokassembly ProductName Tesseract Medium Product dll namespace Tesseract Highest Product file name Tesseract High Product grokassembly CompanyName Charles Weld Low Product grokassembly FileDescription Tesseract High Product grokassembly InternalName Tesseract.dll Medium Product grokassembly OriginalFilename Tesseract.dll Medium Product grokassembly ProductName Tesseract Highest Version AssemblyAnalyzer FilteredVersion 4.1.1 Highest Version grokassembly ProductVersion 4.1.1 Highest
US_export_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\security\policy\limited\US_export_policy.jarMD5: 0d59c5639aa24c7d326e7bd54bb8eda5SHA1: 58875d7463460d7998c4013912fb89965e823044SHA256: 9ce50a70ed7051c155ab8ea06755f94823d8d1cba67ffd8fd3fe3249b3ac31ea
Evidence Type Source Name Value Confidence Vendor file name US_export_policy High Vendor Manifest crypto-strength unlimited Low Product file name US_export_policy High Product Manifest crypto-strength unlimited Low
Related Dependencies US_export_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\security\policy\limited\US_export_policy.jar MD5: 0d59c5639aa24c7d326e7bd54bb8eda5 SHA1: 58875d7463460d7998c4013912fb89965e823044 SHA256: 9ce50a70ed7051c155ab8ea06755f94823d8d1cba67ffd8fd3fe3249b3ac31ea US_export_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\security\policy\unlimited\US_export_policy.jarMD5: 6cbca5808b4a8613d2fed6fe4a84c449SHA1: 0135b30ebec03fb69d79cdc3126e608d9effb8b2SHA256: 761aab2969883e9e5ea76df63ca404fb67673efc3f97def057f8e22517fc9518
Evidence Type Source Name Value Confidence Vendor file name US_export_policy High Vendor Manifest crypto-strength unlimited Low Product file name US_export_policy High Product Manifest crypto-strength unlimited Low
Related Dependencies US_export_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\security\policy\unlimited\US_export_policy.jar MD5: 6cbca5808b4a8613d2fed6fe4a84c449 SHA1: 0135b30ebec03fb69d79cdc3126e608d9effb8b2 SHA256: 761aab2969883e9e5ea76df63ca404fb67673efc3f97def057f8e22517fc9518 VerificationSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\VerificationSwagger.jsMD5: f953368f6e0dd506f23a789482e8ef72SHA1: 4dae19f777f14a1b739f6fb62a66b7e52e4956cdSHA256: dbe1e5d47a671e2094afcfafa2cb70e4f13af6d43a5da49aaa1eaaf55899a5f7
Evidence Type Source Name Value Confidence
WebhookEventHandler.csprojFile Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\WebhookEventHandler.csprojMD5: d63f7617652a880d4de581e54fae459cSHA1: 5177bc4e6e332bf652773a4397e028c3eedd6f40SHA256: d23458d6bc7c31dda805e6227fdb5a7777aa18b3db8dc41cec828861807fa000
Evidence Type Source Name Value Confidence Vendor file name WebhookEventHandler High Product file name WebhookEventHandler High
WebhookEventHandler.dllDescription:
WebhookEventHandler File Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\bin\Debug\net6.0\WebhookEventHandler.dllMD5: d698383dab45060b697087b2e31bffaeSHA1: 20d662d06d2c8c841b24481027731202069b9f6bSHA256: 5814bb71975641e1d904a856355db9e713348ef1819391407ac695a292eb9c99
Evidence Type Source Name Value Confidence Vendor dll namespace WebhookEventHandler Highest Vendor file name WebhookEventHandler High Vendor grokassembly CompanyName WebhookEventHandler Highest Vendor grokassembly FileDescription WebhookEventHandler Low Vendor grokassembly InternalName WebhookEventHandler.dll Low Vendor grokassembly OriginalFilename WebhookEventHandler.dll Low Vendor grokassembly ProductName WebhookEventHandler Medium Product dll namespace WebhookEventHandler Highest Product file name WebhookEventHandler High Product grokassembly CompanyName WebhookEventHandler Low Product grokassembly FileDescription WebhookEventHandler High Product grokassembly InternalName WebhookEventHandler.dll Medium Product grokassembly OriginalFilename WebhookEventHandler.dll Medium Product grokassembly ProductName WebhookEventHandler Highest Version AssemblyAnalyzer FilteredVersion 1.0.0 Highest Version grokassembly ProductVersion 1.0.0 Highest
Related Dependencies WebhookEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\obj\Debug\net6.0\WebhookEventHandler.dll MD5: d698383dab45060b697087b2e31bffae SHA1: 20d662d06d2c8c841b24481027731202069b9f6b SHA256: 5814bb71975641e1d904a856355db9e713348ef1819391407ac695a292eb9c99 WebhookEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\obj\Debug\net6.0\ref\WebhookEventHandler.dll MD5: 21b0759604b970e4ebdb9d82adfdf11d SHA1: e185d1458380408075ac987e0c2afed87c15d777 SHA256: ca84b572f98a0ee7a0a2713f019f1638619c14d2f3c6084c7b3852b3b64709a5 pkg:generic/WebhookEventHandler@1.0.0 WebhookEventHandler.dllFile Path: D:\Onboarding\MerchantManagement\src\WebhookEventHandler\obj\Debug\net6.0\refint\WebhookEventHandler.dll MD5: 21b0759604b970e4ebdb9d82adfdf11d SHA1: e185d1458380408075ac987e0c2afed87c15d777 SHA256: ca84b572f98a0ee7a0a2713f019f1638619c14d2f3c6084c7b3852b3b64709a5 WebhookSwagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\definitions\WebhookSwagger.jsMD5: b8c75e5f023717498b451912e1b565a1SHA1: 7557fdf90eee2b3f267b33be6198e2dcf45d216dSHA256: 1a5c928140e374b04f621cbfda104f71f2b80c145844afb736cb6e65b632abda
Evidence Type Source Name Value Confidence
charsets.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\charsets.jarMD5: be75a8a9ef9d57f82fd36dec50499da6SHA1: cc11cb6830b747274959accdce356c53c4af4951SHA256: 25ced31eaffc46d3c9ce8152c55582e6387d0c2af1224e25e71b4d4dedcb130e
Evidence Type Source Name Value Confidence Vendor file name charsets High Vendor jar package name cs Low Vendor jar package name nio Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name charsets High Product jar package name cs Low Product jar package name ext Low Product jar package name nio Low
Related Dependencies charsets.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\charsets.jar MD5: be75a8a9ef9d57f82fd36dec50499da6 SHA1: cc11cb6830b747274959accdce356c53c4af4951 SHA256: 25ced31eaffc46d3c9ce8152c55582e6387d0c2af1224e25e71b4d4dedcb130e cldrdata.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\cldrdata.jarMD5: e340f52bb44fb8037fc5aaee310d870eSHA1: 895d2b3e73b2b77cd330ddf090edfeeb45c05673SHA256: bdf9ab179946462317faff751388927af7e0fbdbf27e2ae813d8f69632417645
Evidence Type Source Name Value Confidence Vendor file name cldrdata High Vendor jar package name resources Low Vendor jar package name sun Low Vendor jar package name util Low Vendor jar (hint) package name oracle Low Product file name cldrdata High Product jar package name cldr Low Product jar package name resources Low Product jar package name util Low Version Manifest cldr-version 21.0.1 Medium
Related Dependencies cldrdata.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\cldrdata.jar MD5: e340f52bb44fb8037fc5aaee310d870e SHA1: 895d2b3e73b2b77cd330ddf090edfeeb45c05673 SHA256: bdf9ab179946462317faff751388927af7e0fbdbf27e2ae813d8f69632417645 coverlet.collector:3.1.0File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\MerchantManagement.Tests.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id collector Low Vendor msbuild id coverlet Medium Vendor msbuild id coverlet.collector Medium Product msbuild id collector Medium Product msbuild id coverlet.collector Highest Version msbuild version 3.1.0 Highest
Related Dependencies coverlet.collector:3.1.0File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\MerchantManagement.API.Tests.csproj pkg:nuget/coverlet.collector@3.1.0 deploy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\deploy.jarMD5: bd9b63cd8ef803810d99e30ee37c3fbcSHA1: b4ce5d7e65b78b7654dc9afa3a478e2084d6411bSHA256: e7a20615cd163d543b69129278a1fdcaa25a8123cadb78d5171226f3661c2c2e
Evidence Type Source Name Value Confidence Vendor file name deploy High Vendor jar package name deploy Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name deploy High Product jar package name deploy Low
Related Dependencies deploy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\deploy.jar MD5: bd9b63cd8ef803810d99e30ee37c3fbc SHA1: b4ce5d7e65b78b7654dc9afa3a478e2084d6411b SHA256: e7a20615cd163d543b69129278a1fdcaa25a8123cadb78d5171226f3661c2c2e dnsns.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\dnsns.jarMD5: cef025c4c4137b2455cff867ce923184SHA1: 64c5697beefb66fcbeeaae3fb0fb87f7ee40c5f5SHA256: 16ba799d7b41a5c5366a82c61b2e941f18cf224915e4692a1429c900b7cf6439
Evidence Type Source Name Value Confidence Vendor file name dnsns High Vendor jar package name net Low Vendor jar package name spi Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name dnsns High Product jar package name nameservice Low Product jar package name net Low Product jar package name spi Low
Related Dependencies dnsns.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\dnsns.jar MD5: cef025c4c4137b2455cff867ce923184 SHA1: 64c5697beefb66fcbeeaae3fb0fb87f7ee40c5f5 SHA256: 16ba799d7b41a5c5366a82c61b2e941f18cf224915e4692a1429c900b7cf6439 jaccess.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\jaccess.jarMD5: 223749749aa47e7e3f1bcce4a140d8c4SHA1: f6b60adcb2e903e6cbf0bd2a334ba9b7ef772f7fSHA256: 166559f8f1e0c2fbfdaa0a2b183c459a7a7a0d98b0a2ec5bc2225eef58883f3f
Evidence Type Source Name Value Confidence Vendor file name jaccess High Vendor jar package name accessibility Low Vendor jar package name java Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name jaccess High Product jar package name accessibility Low Product jar package name java Low Product jar package name util Low
Related Dependencies jaccess.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\jaccess.jar MD5: 223749749aa47e7e3f1bcce4a140d8c4 SHA1: f6b60adcb2e903e6cbf0bd2a334ba9b7ef772f7f SHA256: 166559f8f1e0c2fbfdaa0a2b183c459a7a7a0d98b0a2ec5bc2225eef58883f3f javaws.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\javaws.jarMD5: 3d7068376febd26cf6d7d29a5d4ee420SHA1: 7d828c64c02b893fc07355c2176e9d92130b8fd3SHA256: ed958eaebb2a7c3b284730694ef8e495eaa5339f7b30de985997c4a82e8dd8e7
Evidence Type Source Name Value Confidence Vendor file name javaws High Vendor jar package name javaws Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name javaws High Product jar package name javaws Low
Related Dependencies javaws.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\javaws.jar MD5: 3d7068376febd26cf6d7d29a5d4ee420 SHA1: 7d828c64c02b893fc07355c2176e9d92130b8fd3 SHA256: ed958eaebb2a7c3b284730694ef8e495eaa5339f7b30de985997c4a82e8dd8e7 jce.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\jce.jarMD5: 1f4d4fc6b33c30c5782c66b80d92c4f9SHA1: 194df32fb23b470dae4929605d18abd041c743c6SHA256: 81b8de0e148ed3601cf5f1bdf2787c5b15213d842bc537af9ede9635d692b904
Evidence Type Source Name Value Confidence Vendor file name jce High Vendor jar package name crypto Highest Vendor jar package name crypto Low Vendor jar package name javax Highest Vendor jar package name javax Low Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name javax.crypto Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name jce High Product jar package name crypto Highest Product jar package name crypto Low Product jar package name javax Highest Product Manifest extension-name javax.crypto Medium Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies jce.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\jce.jar MD5: 1f4d4fc6b33c30c5782c66b80d92c4f9 SHA1: 194df32fb23b470dae4929605d18abd041c743c6 SHA256: 81b8de0e148ed3601cf5f1bdf2787c5b15213d842bc537af9ede9635d692b904 jfr.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\jfr.jarMD5: 4e4400ad8bb0c3d3de86191cd24d3c4cSHA1: 456724c9a558b3d5d2a29c17d868f84d42e6f7f3SHA256: 4d88e36fcceb71a0775c1dbcf2d5aac6b6dd89b9f3a8a7f6187dd640b064de43
Evidence Type Source Name Value Confidence Vendor file name jfr High Vendor jar package name jfr Low Vendor jar package name jrockit Low Vendor jar package name oracle Highest Vendor jar package name oracle Low Vendor jar (hint) package name sun Highest Vendor jar (hint) package name sun Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Product file name jfr High Product jar package name jfr Low Product jar package name jrockit Low Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies jfr.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\jfr.jar MD5: 4e4400ad8bb0c3d3de86191cd24d3c4c SHA1: 456724c9a558b3d5d2a29c17d868f84d42e6f7f3 SHA256: 4d88e36fcceb71a0775c1dbcf2d5aac6b6dd89b9f3a8a7f6187dd640b064de43 CVE-2009-1006 suppress
Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.2 and earlier, with SDK/JRE 1.4.2, JRE/JDK 5, and JRE/JDK 6, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2011-3545 suppress
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2013-2380 suppress
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this might be a duplicate of CVE-2013-1537 and CVE-2013-2415. If so, then CVE-2013-2380 might be REJECTed in the future. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2013-5782 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2013-5830 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK,MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - NOT_APPLICABLE af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert_us@oracle.com - BROKEN_LINK secalert_us@oracle.com - BROKEN_LINK secalert_us@oracle.com - BROKEN_LINK secalert_us@oracle.com - BROKEN_LINK secalert_us@oracle.com - BROKEN_LINK,MAILING_LIST secalert_us@oracle.com - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY secalert_us@oracle.com - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY secalert_us@oracle.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert_us@oracle.com - NOT_APPLICABLE secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY secalert_us@oracle.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert_us@oracle.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2011-3551 suppress
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2011-3556 suppress
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-5802 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2011-3557 suppress
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3556. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-5804 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-5823 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-5825 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JAXP. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-5780 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2011-3553 suppress
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-5797 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-5803 suppress
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
jfxrt.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\jfxrt.jarMD5: decab926ec27ece8ad8de1959bbe6e40SHA1: 19f97d5951f07e7895dff0b61f56e34b02f68cf8SHA256: 986e41698d6afdef1a554fcce1b4ade86784ee4df579c074472659395a66f5b1
Evidence Type Source Name Value Confidence Vendor file name jfxrt High Vendor jar package name javafx Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name jfxrt High
Related Dependencies jfxrt.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\jfxrt.jar MD5: decab926ec27ece8ad8de1959bbe6e40 SHA1: 19f97d5951f07e7895dff0b61f56e34b02f68cf8 SHA256: 986e41698d6afdef1a554fcce1b4ade86784ee4df579c074472659395a66f5b1 jsse.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\jsse.jarMD5: 6f71db514c082474b5e2d6ced7215dd9SHA1: a11cefd162f46c4bd4898d712267c74faa03a34fSHA256: 5c8a841a3ecc757ab84fdb6569bcc6d5f7ae1752531c915d43d491541d8de937
Evidence Type Source Name Value Confidence Vendor file name jsse High Vendor jar package name security Low Vendor jar package name ssl Low Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Product file name jsse High Product jar package name security Low Product jar package name ssl Low Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies jsse.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\jsse.jar MD5: 6f71db514c082474b5e2d6ced7215dd9 SHA1: a11cefd162f46c4bd4898d712267c74faa03a34f SHA256: 5c8a841a3ecc757ab84fdb6569bcc6d5f7ae1752531c915d43d491541d8de937 leptonica-1.80.0.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\x64\leptonica-1.80.0.dllMD5: 35e3f58d3d868e244b103f901fb2c66dSHA1: 35c7829b8d204bfa85449017afb7462fa4512284SHA256: 29e58956c947ac5d21ff6c5755607098dfdfb220b21566bb146bcc6dbc454cdf
Evidence Type Source Name Value Confidence Vendor file name leptonica High Product file name leptonica High Version file name leptonica Medium Version file version 1.80.0 High
cpe:2.3:a:leptonica:leptonica:1.80.0:*:*:*:*:*:*:* (Confidence :Low) suppress leptonica-1.80.0.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\x86\leptonica-1.80.0.dllMD5: bfc156ebfe3b86fbce3f24b475c19f20SHA1: 79c38f3505ee30132ac708895c5bb433794cafd2SHA256: 23ae1310c7aa3e661963a363dae33bb698407648e7ea3085afa7a1dbdefea594
Evidence Type Source Name Value Confidence Vendor file name leptonica High Product file name leptonica High Version file name leptonica Medium Version file version 1.80.0 High
cpe:2.3:a:leptonica:leptonica:1.80.0:*:*:*:*:*:*:* (Confidence :Low) suppress local_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\security\policy\limited\local_policy.jarMD5: 6280d06e46e0cc047e04c85c83874566SHA1: 7d0a29932b496edbdd1fc55572014bc89703ad07SHA256: 92780525250258f336a8f746ed7437035512d06050d85786fb44fdf12e08419c
Evidence Type Source Name Value Confidence Vendor file name local_policy High Vendor Manifest crypto-strength limited Low Product file name local_policy High Product Manifest crypto-strength limited Low
Related Dependencies local_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\security\policy\limited\local_policy.jar MD5: 6280d06e46e0cc047e04c85c83874566 SHA1: 7d0a29932b496edbdd1fc55572014bc89703ad07 SHA256: 92780525250258f336a8f746ed7437035512d06050d85786fb44fdf12e08419c local_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\security\policy\unlimited\local_policy.jarMD5: 360663f26c5584e6c6127254b261fa0cSHA1: aee6515eede2ad7c697ba8a61bdd9359be3319d2SHA256: 02f69a433405ea928c89a8aade74e5462282ccb9a9d30851312ed3459398f85c
Evidence Type Source Name Value Confidence Vendor file name local_policy High Vendor Manifest crypto-strength unlimited Low Product file name local_policy High Product Manifest crypto-strength unlimited Low
Related Dependencies local_policy.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\security\policy\unlimited\local_policy.jar MD5: 360663f26c5584e6c6127254b261fa0c SHA1: aee6515eede2ad7c697ba8a61bdd9359be3319d2 SHA256: 02f69a433405ea928c89a8aade74e5462282ccb9a9d30851312ed3459398f85c localedata.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\localedata.jarMD5: 4d2e3063b3d1fc20deb18859e10357f9SHA1: 3ec186a9394223d5fecd27f45679f426998603efSHA256: 751eb64554449397845cb997cde0918834ad7147efeb429ff83be3d2b2b4b87b
Evidence Type Source Name Value Confidence Vendor file name localedata High Vendor jar package name resources Low Vendor jar package name sun Low Vendor jar package name util Low Vendor jar (hint) package name oracle Low Product file name localedata High Product jar package name resources Low Product jar package name util Low
Related Dependencies localedata.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\localedata.jar MD5: 4d2e3063b3d1fc20deb18859e10357f9 SHA1: 3ec186a9394223d5fecd27f45679f426998603ef SHA256: 751eb64554449397845cb997cde0918834ad7147efeb429ff83be3d2b2b4b87b management-agent.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\management-agent.jarMD5: fa58bb0dea08d8c8629afdcb57d124a4SHA1: 1995713167f486a9dd340411767a24487cd51510SHA256: b4770222b7a752f2c887ff25f20cd8402b0650f8c9e9ba05e07f0ad608e47e67
Evidence Type Source Name Value Confidence Vendor file name management-agent High Product file name management-agent High
Related Dependencies management-agent.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\management-agent.jar MD5: fa58bb0dea08d8c8629afdcb57d124a4 SHA1: 1995713167f486a9dd340411767a24487cd51510 SHA256: b4770222b7a752f2c887ff25f20cd8402b0650f8c9e9ba05e07f0ad608e47e67 nashorn.jar: base.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\base.jsMD5: 4884a40c521d57e79eb78446dab4ec36SHA1: 2b501655f4967658431bdd02dac98ecbfdf5fbceSHA256: bfcd57b6cdfa2c3e880da9e04ebe73d63a20e226c0a911120e70fb05e2503a79
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: base.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\base.js MD5: 4884a40c521d57e79eb78446dab4ec36 SHA1: 2b501655f4967658431bdd02dac98ecbfdf5fbce SHA256: bfcd57b6cdfa2c3e880da9e04ebe73d63a20e226c0a911120e70fb05e2503a79 nashorn.jar: bootstrap.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\bootstrap.jsMD5: 0852e1ca5f5196c655c83f4a31d9a38eSHA1: d2c673b70d5b86a7ade93b7d91aefb52ba7b0d59SHA256: 716d8a0b83f41f70580a84faafce491672ec9429f842e8a87972d795bb90a81e
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: bootstrap.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\bootstrap.js MD5: 0852e1ca5f5196c655c83f4a31d9a38e SHA1: d2c673b70d5b86a7ade93b7d91aefb52ba7b0d59 SHA256: 716d8a0b83f41f70580a84faafce491672ec9429f842e8a87972d795bb90a81e nashorn.jar: controls.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\controls.jsMD5: 517df1cdcc12e68624bcfd93b3795e2bSHA1: 5770571b49c0d98f04fa56349282051bee54695bSHA256: a65a5409c41e4926bc66f9d982e8759e11faa4a224453db64d03880b74de6667
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: controls.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\controls.js MD5: 517df1cdcc12e68624bcfd93b3795e2b SHA1: 5770571b49c0d98f04fa56349282051bee54695b SHA256: a65a5409c41e4926bc66f9d982e8759e11faa4a224453db64d03880b74de6667 nashorn.jar: fxml.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\fxml.jsMD5: 4f6c5373999aba13c67e938079e1c5d6SHA1: 0b87229d0b8c2035fe18eb850c87332915ae92d1SHA256: b28e554027f850fd7ec750f3a7aeb48fb86f37233b62136493b960b6810c2602
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: fxml.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\fxml.js MD5: 4f6c5373999aba13c67e938079e1c5d6 SHA1: 0b87229d0b8c2035fe18eb850c87332915ae92d1 SHA256: b28e554027f850fd7ec750f3a7aeb48fb86f37233b62136493b960b6810c2602 nashorn.jar: graphics.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\graphics.jsMD5: acb809d6467da2969d074ff1f13b0103SHA1: 047729c8dc0ccf151b4292b4fed8ead4cef99005SHA256: ef2ab315d7a6e27ce2fa671b108316a48bfcbbeeb018b3d297b5c7ebe837d589
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: graphics.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\graphics.js MD5: acb809d6467da2969d074ff1f13b0103 SHA1: 047729c8dc0ccf151b4292b4fed8ead4cef99005 SHA256: ef2ab315d7a6e27ce2fa671b108316a48bfcbbeeb018b3d297b5c7ebe837d589 nashorn.jar: media.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\media.jsMD5: d4638490bda644b5923d2343e10c0810SHA1: 880275b9d59522bf40d925b9a859dc3297a4e8d4SHA256: 620f1bf0f3400b76766ed2370a968472ed2bba20655a3c271100c10a7013505d
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: media.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\media.js MD5: d4638490bda644b5923d2343e10c0810 SHA1: 880275b9d59522bf40d925b9a859dc3297a4e8d4 SHA256: 620f1bf0f3400b76766ed2370a968472ed2bba20655a3c271100c10a7013505d nashorn.jar: mozilla_compat.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\mozilla_compat.jsMD5: 99de93bc0ab59c29f697a85af0a3368aSHA1: 76e77f67936752966d21f9ae9417adec8cd1253dSHA256: 7fb48c8da0ba954827417160745d9b1b9fc045c9b2e02f5f5fa05d25ad4b9c32
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: mozilla_compat.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\mozilla_compat.js MD5: 99de93bc0ab59c29f697a85af0a3368a SHA1: 76e77f67936752966d21f9ae9417adec8cd1253d SHA256: 7fb48c8da0ba954827417160745d9b1b9fc045c9b2e02f5f5fa05d25ad4b9c32 nashorn.jar: parser.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\parser.jsMD5: 007899ccc6ae2a845c86bfdfaeb2a534SHA1: 44c413366635773825b0515148bf204e237ae5b8SHA256: cf94d48fb199626fbe05c093e94c2a3021fb54fdf48270519165b625379ce697
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: parser.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\parser.js MD5: 007899ccc6ae2a845c86bfdfaeb2a534 SHA1: 44c413366635773825b0515148bf204e237ae5b8 SHA256: cf94d48fb199626fbe05c093e94c2a3021fb54fdf48270519165b625379ce697 nashorn.jar: swing.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\swing.jsMD5: c6681565ae3327935fcdcbcc5325566eSHA1: 55e28e524464c46d8363683c18b1349bfc5fca74SHA256: 8c6982f67558f4ddab5b43de97650e4027186ebc6274bcb99f2ce740a9decec7
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: swing.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\swing.js MD5: c6681565ae3327935fcdcbcc5325566e SHA1: 55e28e524464c46d8363683c18b1349bfc5fca74 SHA256: 8c6982f67558f4ddab5b43de97650e4027186ebc6274bcb99f2ce740a9decec7 nashorn.jar: swt.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\swt.jsMD5: 2302f9444742118e7630d79fc265116fSHA1: 3dc7e9ce146c71e09b8ad00f310aacdd5b9c1510SHA256: 43a93bce53690bdf0b767a018f1e2d579a23b955992d679e147053767e7d1c12
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: swt.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\swt.js MD5: 2302f9444742118e7630d79fc265116f SHA1: 3dc7e9ce146c71e09b8ad00f310aacdd5b9c1510 SHA256: 43a93bce53690bdf0b767a018f1e2d579a23b955992d679e147053767e7d1c12 nashorn.jar: web.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\web.jsMD5: af46e2d30ec629796f76e1539993e1c6SHA1: 5b5005fb18a2498f4e9b954da69bd8083ed121d4SHA256: 653e15f1477cc6d8d3282f5ed3cc6a4ba9932954c98ce8a252e55dc56d5d656e
Evidence Type Source Name Value Confidence
Related Dependencies nashorn.jar: web.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar\jdk\nashorn\internal\runtime\resources\fx\web.js MD5: af46e2d30ec629796f76e1539993e1c6 SHA1: 5b5005fb18a2498f4e9b954da69bd8083ed121d4 SHA256: 653e15f1477cc6d8d3282f5ed3cc6a4ba9932954c98ce8a252e55dc56d5d656e nashorn.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\nashorn.jarMD5: 74c436e75f08a01f57cb473f2c8a5515SHA1: 0970f14e2431afeabd51f0c3dc147d4a80056965SHA256: 347dda25d017cc19034ef28c97dddc9331f5e11b568931769c2e052dac302f57
Evidence Type Source Name Value Confidence Vendor file name nashorn High Vendor jar package name internal Low Vendor jar package name jdk Low Vendor jar package name nashorn Low Vendor manifest: jdk/nashorn/ Implementation-Vendor Oracle Corporation Medium Product file name nashorn High Product jar package name internal Low Product jar package name nashorn Highest Product jar package name nashorn Low Product manifest: jdk/nashorn/ Implementation-Title Oracle Nashorn Medium Version manifest: jdk/nashorn/ Implementation-Version 1.8.0_351-b10 Medium
Related Dependencies nashorn.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\nashorn.jar MD5: 74c436e75f08a01f57cb473f2c8a5515 SHA1: 0970f14e2431afeabd51f0c3dc147d4a80056965 SHA256: 347dda25d017cc19034ef28c97dddc9331f5e11b568931769c2e052dac302f57 package.jsonFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\package.jsonMD5: 900eea6dcc0ec5f5e340d4e925c560e9SHA1: 102729223fff910795cb01de9abd02b2c99f57dfSHA256: b1d5cca4276e489b92c01b11088b551c14288c76a704d813097231c13927f608
Evidence Type Source Name Value Confidence
package.jsonFile Path: D:\Onboarding\MerchantManagement\src\OCR\package.jsonMD5: 245567ae0be728133fd5b9d1f9e8e49aSHA1: b6c5855bd4ae707a64e0c9ad9b700799a396c9a3SHA256: 3f65ac9b18446364f50449ba9fcda2f3e0aaabd9290cf13435bae2479671b8c6
Evidence Type Source Name Value Confidence
pdfium.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\runtimes\win-x64\native\pdfium.dllMD5: 1d1b12e0f3e12a764424f6365255fdefSHA1: 8ba7a14e6177154d373c07e18791f5ad8376fd65SHA256: bca96944d731dd72877116d3472083c847fe307fc58ca39bce16cbe998c478f1
Evidence Type Source Name Value Confidence Vendor file name pdfium High Product file name pdfium High
pdfium.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\runtimes\win-x86\native\pdfium.dllMD5: 2154a2872defd49f6c26e060212cae5cSHA1: e6fb9e6537e11e8f621fa4a14c3b95076c7e2c30SHA256: b7851fd6581b8bfe40c485a7c7e2f08fca245a7c2d1d5dcf051807488d346f09
Evidence Type Source Name Value Confidence Vendor file name pdfium High Product file name pdfium High
plugin.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\plugin.jarMD5: 771eab9517aa9f593e7702ce31ec9524SHA1: 41cc24f59b5bcc4d3b71f56b0f9e2b8d9fe8dc3cSHA256: 2da9ba5e7893265ef9abf38a5e9a6f524ee635e5d8067433aae6f8447b810535
Evidence Type Source Name Value Confidence Vendor file name plugin High Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Product file name plugin High
Related Dependencies plugin.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\plugin.jar MD5: 771eab9517aa9f593e7702ce31ec9524 SHA1: 41cc24f59b5bcc4d3b71f56b0f9e2b8d9fe8dc3c SHA256: 2da9ba5e7893265ef9abf38a5e9a6f524ee635e5d8067433aae6f8447b810535 resources.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\resources.jarMD5: 33fa302bbb01eb666f0b5db79e5e9b4fSHA1: d9e8dfb00cc1cb4bc0a7d4fbc6d06972b74639d9SHA256: 9138df6eb6a6f0793db455a8b26ff294aa45fda4510a784575c4240ab80775bf
Evidence Type Source Name Value Confidence Vendor file name resources High Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Product file name resources High Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies resources.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\resources.jar MD5: 33fa302bbb01eb666f0b5db79e5e9b4f SHA1: d9e8dfb00cc1cb4bc0a7d4fbc6d06972b74639d9 SHA256: 9138df6eb6a6f0793db455a8b26ff294aa45fda4510a784575c4240ab80775bf rt.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\rt.jarMD5: c1af941217d3e71df0061022ce628981SHA1: 03c0241595dde88052ab6ab4c868b117badcbbeeSHA256: 93f8e5fd7a9c3b2ced83cb7d65cb3b7a4956ca7c6312c000f65245ca1e2698cf
Evidence Type Source Name Value Confidence Vendor file name rt High Vendor jar package name oracle Highest Vendor jar package name sun Low Vendor jar (hint) package name oracle Low Vendor jar (hint) package name sun Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Product file name rt High Product jar package name api Highest Product jar package name environment Highest Product jar package name java Highest Product jar package name platform Highest Product jar package name runtime Highest Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies rt.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\rt.jar MD5: c1af941217d3e71df0061022ce628981 SHA1: 03c0241595dde88052ab6ab4c868b117badcbbee SHA256: 93f8e5fd7a9c3b2ced83cb7d65cb3b7a4956ca7c6312c000f65245ca1e2698cf sunec.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\sunec.jarMD5: 8f584d88c5b02b9dde9b4ac752ee05f6SHA1: 2dfc8984e13a84aa39b1766072219f6df1a58228SHA256: b7467f44b1e57661c56726e72d5c0ad1d8b608813c9f723373a0e98e5648c98f
Evidence Type Source Name Value Confidence Vendor file name sunec High Vendor jar package name ec Low Vendor jar package name security Low Vendor jar package name sun Highest Vendor jar package name sun Low Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor Manifest extension-name javax.crypto Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name sunec High Product jar package name ec Low Product jar package name security Low Product Manifest extension-name javax.crypto Medium Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_271 High
Related Dependencies sunec.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\sunec.jar MD5: 8f584d88c5b02b9dde9b4ac752ee05f6 SHA1: 2dfc8984e13a84aa39b1766072219f6df1a58228 SHA256: b7467f44b1e57661c56726e72d5c0ad1d8b608813c9f723373a0e98e5648c98f sunjce_provider.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\sunjce_provider.jarMD5: 67ac818985503bcc5ef5545a80af1240SHA1: 4cfd63f68a2d4c2ea88d6cc536dbafe4aeafbe40SHA256: 9990d3b64e314ab6d44898bc7f99d0be2e7990b352d8025ac9f5e6afb547cfd9
Evidence Type Source Name Value Confidence Vendor file name sunjce_provider High Vendor jar package name crypto Highest Vendor jar package name crypto Low Vendor jar package name provider Low Vendor jar package name sun Highest Vendor jar package name sun Low Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor Manifest extension-name javax.crypto Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name sunjce_provider High Product jar package name crypto Highest Product jar package name crypto Low Product jar package name provider Low Product Manifest extension-name javax.crypto Medium Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_321 High
Related Dependencies sunjce_provider.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\sunjce_provider.jar MD5: 67ac818985503bcc5ef5545a80af1240 SHA1: 4cfd63f68a2d4c2ea88d6cc536dbafe4aeafbe40 SHA256: 9990d3b64e314ab6d44898bc7f99d0be2e7990b352d8025ac9f5e6afb547cfd9 sunpkcs11.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\sunpkcs11.jarMD5: dc3a3b045015dc549800fea995ec1706SHA1: a90d2e662af87da76127c16b90f0090fc5fd5a36SHA256: 214c4f284c5e535228c715625112b8a85afddf190ad701802c80eec0ad5c96a6
Evidence Type Source Name Value Confidence Vendor file name sunpkcs11 High Vendor jar package name pkcs11 Low Vendor jar package name security Low Vendor jar package name sun Highest Vendor jar package name sun Low Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor Manifest extension-name javax.crypto Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name sunpkcs11 High Product jar package name pkcs11 Low Product jar package name security Low Product Manifest extension-name javax.crypto Medium Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version file name sunpkcs11 Medium Version file version 11 Medium Version Manifest Implementation-Version 1.8.0_361 High
Related Dependencies sunpkcs11.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\sunpkcs11.jar MD5: dc3a3b045015dc549800fea995ec1706 SHA1: a90d2e662af87da76127c16b90f0090fc5fd5a36 SHA256: 214c4f284c5e535228c715625112b8a85afddf190ad701802c80eec0ad5c96a6 cpe:2.3:a:oracle:platform_security_for_java:1.8.0.361:*:*:*:*:*:*:* (Confidence :Low) suppress swagger.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger.jsMD5: 8c966df86ee27632be72505b900f5916SHA1: 9763a3faecb7eb413fff25dc9b64d48180ad717dSHA256: 2361cc5e66651683d9f2ad44475939cb656919330e9eda7752d39bceeb20a068
Evidence Type Source Name Value Confidence
swaggerDefinition.jsFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.Swagger.API\swagger\swaggerDefinition.jsMD5: afae31f15746414aff51064fb3c51250SHA1: 20d641446c9e33111a6b44913defc7b24e5b6e46SHA256: 96e4e22625439f4efa5c0d6fa670379c38b2e224ada6d7bb5b5c0d97f3653cde
Evidence Type Source Name Value Confidence
tesseract41.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\x64\tesseract41.dllMD5: 3255fefb5dda0bb81adfbb1722fe45efSHA1: dd7ef8696354ff16410d298042642106241ceb62SHA256: 13a8eaffc40b2f2e50e8f4ad835a9b25143413e3d6a85a3e64f6ec575a795375
Evidence Type Source Name Value Confidence Vendor file name tesseract41 High Product file name tesseract41 High Version file name tesseract41 Medium Version file version 41 Medium
tesseract41.dllFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\x86\tesseract41.dllMD5: 298c0d71957cb2d82654373582c2313dSHA1: 5144e81cdb46cf31dc57000cd0c4c656c5e5e489SHA256: f7456f32c1066da10e9d1a94b73900ef61d6652729cb159504771f65dd331872
Evidence Type Source Name Value Confidence Vendor file name tesseract41 High Product file name tesseract41 High Version file name tesseract41 Medium Version file version 41 Medium
testhost.dllDescription:
testhost File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\testhost.dllMD5: 2f688db5ce1a04d7e68e67508ceb89daSHA1: f7f423e77d3a8f98a30e6288290fde469a282c33SHA256: 6bb2d901bb119deb7b2a3047cc2d51bdb1e88544295e6ef497cdc26b01bcd573
Evidence Type Source Name Value Confidence Vendor file name testhost High Vendor grokassembly CompanyName Microsoft Corporation Highest Vendor grokassembly FileDescription testhost Low Vendor grokassembly InternalName testhost.dll Low Vendor grokassembly OriginalFilename testhost.dll Low Vendor grokassembly ProductName Microsoft.TestHost Medium Product file name testhost High Product grokassembly CompanyName Microsoft Corporation Low Product grokassembly FileDescription testhost High Product grokassembly InternalName testhost.dll Medium Product grokassembly OriginalFilename testhost.dll Medium Product grokassembly ProductName Microsoft.TestHost Highest Version grokassembly ProductVersion 16.11.0 Highest
Related Dependencies testhost.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\testhost.dll MD5: 2f688db5ce1a04d7e68e67508ceb89da SHA1: f7f423e77d3a8f98a30e6288290fde469a282c33 SHA256: 6bb2d901bb119deb7b2a3047cc2d51bdb1e88544295e6ef497cdc26b01bcd573 testhost.exeFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\testhost.exeMD5: 402637a8ffd2c97840985117d59f44d5SHA1: 01054699ec09dcebacd1d838479650b588790787SHA256: 106530dd43192e1bf8a7cab256131da7383a465de940798405774d2279f0dc02
Evidence Type Source Name Value Confidence Vendor file name testhost High Product file name testhost High
Related Dependencies testhost.exeFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\testhost.exe MD5: 402637a8ffd2c97840985117d59f44d5 SHA1: 01054699ec09dcebacd1d838479650b588790787 SHA256: 106530dd43192e1bf8a7cab256131da7383a465de940798405774d2279f0dc02 xunit.abstractions.dllDescription:
xUnit.net Abstractions (PCL) File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.abstractions.dllMD5: d8a035462916c19a6dd13cb534051e81SHA1: 92a0d358e7342e3da1e73dfb27c783de55a379c1SHA256: 3166dc70323fb30ccf1cedb0fe86f2ad122c46d254542342d90386efc4c9285c
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit.Abstractions Highest Vendor file name xunit.abstractions High Vendor grokassembly CompanyName Outercurve Foundation Highest Vendor grokassembly FileDescription xUnit.net Abstractions (PCL) Low Vendor grokassembly InternalName xunit.abstractions.dll Low Vendor grokassembly OriginalFilename xunit.abstractions.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit.Abstractions Highest Product file name xunit.abstractions High Product grokassembly CompanyName Outercurve Foundation Low Product grokassembly FileDescription xUnit.net Abstractions (PCL) High Product grokassembly InternalName xunit.abstractions.dll Medium Product grokassembly OriginalFilename xunit.abstractions.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.0.0.0 Highest Version grokassembly FileVersion 2.0.0.0 High Version grokassembly ProductVersion 2.0.0.0 Highest
Related Dependencies xunit.abstractions.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.abstractions.dll MD5: d8a035462916c19a6dd13cb534051e81 SHA1: 92a0d358e7342e3da1e73dfb27c783de55a379c1 SHA256: 3166dc70323fb30ccf1cedb0fe86f2ad122c46d254542342d90386efc4c9285c xunit.assert.dllDescription:
xUnit.net Assertion Library File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.assert.dllMD5: 424d4d02c203bb271b05891afd4b840bSHA1: b8f5f3d5063635765be0beab80329a0c1da87619SHA256: 17b97301ee85f235cc45134055a2edc2fe6996966bd9fdebf0aede9770c6a06e
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor file name xunit.assert High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Assertion Library Low Vendor grokassembly InternalName xunit.assert.dll Low Vendor grokassembly OriginalFilename xunit.assert.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product file name xunit.assert High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Assertion Library High Product grokassembly InternalName xunit.assert.dll Medium Product grokassembly OriginalFilename xunit.assert.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.1 Highest Version grokassembly FileVersion 2.4.1 High Version grokassembly ProductVersion 2.4.1 Highest
Related Dependencies xunit.assert.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.assert.dll MD5: 424d4d02c203bb271b05891afd4b840b SHA1: b8f5f3d5063635765be0beab80329a0c1da87619 SHA256: 17b97301ee85f235cc45134055a2edc2fe6996966bd9fdebf0aede9770c6a06e xunit.core.dllDescription:
xUnit.net Core File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.core.dllMD5: 63af8c05d126e90217560b32436283baSHA1: 048ae886d2b90c14b0fbac8f852a9537a1720013SHA256: ea7acbee4e78e941df6cfe346e44be0e35e959015dc4421635fd114dbec42467
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor file name xunit.core High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Core Low Vendor grokassembly InternalName xunit.core.dll Low Vendor grokassembly OriginalFilename xunit.core.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product file name xunit.core High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Core High Product grokassembly InternalName xunit.core.dll Medium Product grokassembly OriginalFilename xunit.core.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.1 Highest Version grokassembly FileVersion 2.4.1 High Version grokassembly ProductVersion 2.4.1 Highest
Related Dependencies xunit.core.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.core.dll MD5: 63af8c05d126e90217560b32436283ba SHA1: 048ae886d2b90c14b0fbac8f852a9537a1720013 SHA256: ea7acbee4e78e941df6cfe346e44be0e35e959015dc4421635fd114dbec42467 xunit.execution.dotnet.dllDescription:
xUnit.net Execution (dotnet) File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.execution.dotnet.dllMD5: bf60647fe6418db954344327a1fd9329SHA1: e36e00d865b5778fa6872b7e91aa43c2f506e3d2SHA256: 99088544fcadd500e30258645765ab01e21d31fc29c46fd46b7def55fe35268f
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor file name xunit.execution.dotnet High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Execution (dotnet) Low Vendor grokassembly InternalName xunit.execution.dotnet.dll Low Vendor grokassembly OriginalFilename xunit.execution.dotnet.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product file name xunit.execution.dotnet High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Execution (dotnet) High Product grokassembly InternalName xunit.execution.dotnet.dll Medium Product grokassembly OriginalFilename xunit.execution.dotnet.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.1 Highest Version grokassembly FileVersion 2.4.1 High Version grokassembly ProductVersion 2.4.1 Highest
Related Dependencies xunit.execution.dotnet.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.execution.dotnet.dll MD5: bf60647fe6418db954344327a1fd9329 SHA1: e36e00d865b5778fa6872b7e91aa43c2f506e3d2 SHA256: 99088544fcadd500e30258645765ab01e21d31fc29c46fd46b7def55fe35268f xunit.runner.reporters.netcoreapp10.dllDescription:
xUnit.net Runner Reporters (.NET Core 1.0) File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.runner.reporters.netcoreapp10.dllMD5: 8dd04d8859206dcce5c1d400cd918dcdSHA1: eb81d761992ab633584cf7ecd8f7843743d1b136SHA256: 2029c8d47645da90e0d58537ee0fd101e1291108806630232c138d52ec382de4
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor dll namespace Xunit.Runner.Reporters Highest Vendor file name xunit.runner.reporters.netcoreapp10 High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Runner Reporters (.NET Core 1.0) Low Vendor grokassembly InternalName xunit.runner.reporters.netcoreapp10.dll Low Vendor grokassembly OriginalFilename xunit.runner.reporters.netcoreapp10.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product dll namespace Xunit.Runner.Reporters Highest Product file name xunit.runner.reporters.netcoreapp10 High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Runner Reporters (.NET Core 1.0) High Product grokassembly InternalName xunit.runner.reporters.netcoreapp10.dll Medium Product grokassembly OriginalFilename xunit.runner.reporters.netcoreapp10.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.1 Highest Version grokassembly FileVersion 2.4.1 High Version grokassembly ProductVersion 2.4.1 Highest
Related Dependencies xunit.runner.reporters.netcoreapp10.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.runner.reporters.netcoreapp10.dll MD5: 8dd04d8859206dcce5c1d400cd918dcd SHA1: eb81d761992ab633584cf7ecd8f7843743d1b136 SHA256: 2029c8d47645da90e0d58537ee0fd101e1291108806630232c138d52ec382de4 xunit.runner.utility.netcoreapp10.dllDescription:
xUnit.net Runner Utility (.NET Core 1.0) File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.runner.utility.netcoreapp10.dllMD5: 23b2927c45ffe829bcdc6ba6e437c651SHA1: 9de3650db94aa5fe82f8c04a719f137179f50059SHA256: 508b79ae64e32fe80180118c86529f62d278deeec48c58c2cc091843650727e0
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor file name xunit.runner.utility.netcoreapp10 High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Runner Utility (.NET Core 1.0) Low Vendor grokassembly InternalName xunit.runner.utility.netcoreapp10.dll Low Vendor grokassembly OriginalFilename xunit.runner.utility.netcoreapp10.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product file name xunit.runner.utility.netcoreapp10 High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Runner Utility (.NET Core 1.0) High Product grokassembly InternalName xunit.runner.utility.netcoreapp10.dll Medium Product grokassembly OriginalFilename xunit.runner.utility.netcoreapp10.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.1 Highest Version grokassembly FileVersion 2.4.1 High Version grokassembly ProductVersion 2.4.1 Highest
Related Dependencies xunit.runner.utility.netcoreapp10.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.runner.utility.netcoreapp10.dll MD5: 23b2927c45ffe829bcdc6ba6e437c651 SHA1: 9de3650db94aa5fe82f8c04a719f137179f50059 SHA256: 508b79ae64e32fe80180118c86529f62d278deeec48c58c2cc091843650727e0 xunit.runner.visualstudio.dotnetcore.testadapter.dllDescription:
xUnit.net Runner for Visual Studio (netcoreapp2.1)
Visual Studio 2017 15.9+ Test Explorer runner for the xUnit.net framework. Capable of running xUnit.net v1.9.2 and v2.0+ tests. Supports .NET 2.0 or later, .NET Core 2.1 or later, and Universal Windows 10.0.16299 or later. File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\bin\Debug\net6.0\xunit.runner.visualstudio.dotnetcore.testadapter.dllMD5: f59853cbf4a8e6b9398e0fb728b8684cSHA1: c52840f8848c91e41d63790df0a1fc5e7ae5daf5SHA256: 070380b5358b9b6bb58b4ae75b7aa04972c0ba40edc8b119ef72ac3ab70ebc45
Evidence Type Source Name Value Confidence Vendor dll namespace Xunit Highest Vendor dll namespace Xunit.Runner.VisualStudio Highest Vendor file name xunit.runner.visualstudio.dotnetcore.testadapter High Vendor grokassembly CompanyName .NET Foundation Highest Vendor grokassembly FileDescription xUnit.net Runner for Visual Studio (netcoreapp2.1) Low Vendor grokassembly InternalName xunit.runner.visualstudio.dotnetcore.testadapter.dll Low Vendor grokassembly OriginalFilename xunit.runner.visualstudio.dotnetcore.testadapter.dll Low Vendor grokassembly ProductName xUnit.net Testing Framework Medium Product dll namespace Xunit Highest Product dll namespace Xunit.Runner.VisualStudio Highest Product file name xunit.runner.visualstudio.dotnetcore.testadapter High Product grokassembly CompanyName .NET Foundation Low Product grokassembly FileDescription xUnit.net Runner for Visual Studio (netcoreapp2.1) High Product grokassembly InternalName xunit.runner.visualstudio.dotnetcore.testadapter.dll Medium Product grokassembly OriginalFilename xunit.runner.visualstudio.dotnetcore.testadapter.dll Medium Product grokassembly ProductName xUnit.net Testing Framework Highest Version AssemblyAnalyzer FilteredVersion 2.4.3 Highest
Related Dependencies xunit.runner.visualstudio.dotnetcore.testadapter.dllFile Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\bin\Debug\net6.0\xunit.runner.visualstudio.dotnetcore.testadapter.dll MD5: f59853cbf4a8e6b9398e0fb728b8684c SHA1: c52840f8848c91e41d63790df0a1fc5e7ae5daf5 SHA256: 070380b5358b9b6bb58b4ae75b7aa04972c0ba40edc8b119ef72ac3ab70ebc45 xunit.runner.visualstudio:2.4.3File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\MerchantManagement.Tests.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id runner Low Vendor msbuild id runner.visualstudio Low Vendor msbuild id xunit Medium Vendor msbuild id xunit.runner.visualstudio Medium Product msbuild id runner Medium Product msbuild id runner.visualstudio Medium Product msbuild id xunit.runner.visualstudio Highest Version msbuild version 2.4.3 Highest
Related Dependencies xunit.runner.visualstudio:2.4.3File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\MerchantManagement.API.Tests.csproj pkg:nuget/xunit.runner.visualstudio@2.4.3 xunit:2.4.1File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.Tests\MerchantManagement.Tests.csproj
Evidence Type Source Name Value Confidence Vendor msbuild id xunit Medium Vendor msbuild id xunit Low Product msbuild id xunit Highest Version msbuild version 2.4.1 Highest
Related Dependencies xunit:2.4.1File Path: D:\Onboarding\MerchantManagement\test\MerchantManagement.API.Tests\MerchantManagement.API.Tests.csproj pkg:nuget/xunit@2.4.1 zipfs.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\jre1.8.0_351\jre\lib\ext\zipfs.jarMD5: 6d7da4a8f1fc737689d382a821dd3e4cSHA1: 2675f3995983180a637f1d5cd71ac436057fa994SHA256: 6bb0619d4cb6c7e273d50fc4be13aca32441e3b8bfbdd8a03032d5c2c300abc3
Evidence Type Source Name Value Confidence Vendor file name zipfs High Vendor jar package name nio Low Vendor jar package name sun Low Vendor jar package name zipfs Low Vendor jar (hint) package name oracle Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Product file name zipfs High Product jar package name nio Low Product jar package name zipfs Low Product Manifest Implementation-Title Java Runtime Environment High Product Manifest specification-title Java Platform API Specification Medium Version Manifest Implementation-Version 1.8.0_351 High
Related Dependencies zipfs.jarFile Path: D:\Onboarding\MerchantManagement\src\MerchantManagement.API\bin\Debug\net6.0\jre\lib\ext\zipfs.jar MD5: 6d7da4a8f1fc737689d382a821dd3e4c SHA1: 2675f3995983180a637f1d5cd71ac436057fa994 SHA256: 6bb0619d4cb6c7e273d50fc4be13aca32441e3b8bfbdd8a03032d5c2c300abc3