Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Testing

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
APF.Core3.1.API:6.0.0.*pkg:nuget/APF.Core3.1.API@6.0.0.%2A 08
APF.Core3.1.AWS:6.0.0.*pkg:nuget/APF.Core3.1.AWS@6.0.0.%2A 08
APF.Core3.1:6.0.0.*pkg:nuget/APF.Core3.1@6.0.0.%2A 08
APF.Core3.1:6.0.0.12pkg:nuget/APF.Core3.1@6.0.0.12 08
APF.Core3.1:6.0.0.8pkg:nuget/APF.Core3.1@6.0.0.8 08
AWSSDK.APIGateway:3.7.100.22pkg:nuget/AWSSDK.APIGateway@3.7.100.22 06
AWSSDK.CodePipeline:3.7.100.22pkg:nuget/AWSSDK.CodePipeline@3.7.100.22 06
AWSSDK.Core:3.7.100.22pkg:nuget/AWSSDK.Core@3.7.100.22 06
AWSSDK.Extensions.NETCore.Setup:3.7.2pkg:nuget/AWSSDK.Extensions.NETCore.Setup@3.7.2 08
AWSSDK.S3:3.7.100pkg:nuget/AWSSDK.S3@3.7.100 06
AWSSDK.S3:3.7.9.23pkg:nuget/AWSSDK.S3@3.7.9.23 06
AWSSDK.SecurityToken:3.7.100.22pkg:nuget/AWSSDK.SecurityToken@3.7.100.22 06
AWSSDK.SimpleSystemsManagement:3.7.100.2pkg:nuget/AWSSDK.SimpleSystemsManagement@3.7.100.2 06
Amazon.Lambda.AspNetCoreServer:6.1.0cpe:2.3:a:asp-project:asp-project:6.1.0:*:*:*:*:*:*:*pkg:nuget/Amazon.Lambda.AspNetCoreServer@6.1.0 0Low8
Amazon.Lambda.Core:2.1.0pkg:nuget/Amazon.Lambda.Core@2.1.0 08
Amazon.Lambda.S3Events:2.0.1pkg:nuget/Amazon.Lambda.S3Events@2.0.1 08
Amazon.Lambda.SNSEvents:2.0.0pkg:nuget/Amazon.Lambda.SNSEvents@2.0.0 08
Amazon.Lambda.Serialization.Json:2.0.0pkg:nuget/Amazon.Lambda.Serialization.Json@2.0.0 08
Amazon.Lambda.Serialization.SystemTextJson:2.3.0pkg:nuget/Amazon.Lambda.Serialization.SystemTextJson@2.3.0 08
AutoMapper.Extensions.Microsoft.DependencyInjection:12.0.0pkg:nuget/AutoMapper.Extensions.Microsoft.DependencyInjection@12.0.0 08
AutoMapper:12.0.0pkg:nuget/AutoMapper@12.0.0 04
AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0pkg:nuget/AwsParameterStore.Microsoft.Extensions.Configuration@0.7.0 08
FluentValidation.DependencyInjectionExtensions:11.9.0pkg:nuget/FluentValidation.DependencyInjectionExtensions@11.9.0 06
FluentValidation:11.9.0pkg:nuget/FluentValidation@11.9.0 04
Hashids.net:1.3.0pkg:nuget/Hashids.net@1.3.0 06
Lumigo.DotNET:1.0.45pkg:nuget/Lumigo.DotNET@1.0.45 06
Microsoft.AspNetCore.Authentication.JwtBearer:3.1.3cpe:2.3:a:asp-project:asp-project:3.1.3:*:*:*:*:*:*:*pkg:nuget/Microsoft.AspNetCore.Authentication.JwtBearer@3.1.3LOW1Low8
Microsoft.AspNetCore.Mvc.NewtonsoftJson:6.0.24cpe:2.3:a:asp-project:asp-project:6.0.24:*:*:*:*:*:*:*pkg:nuget/Microsoft.AspNetCore.Mvc.NewtonsoftJson@6.0.24 0Low8
Microsoft.AspNetCore.Mvc.Versioning:5.0.0cpe:2.3:a:asp-project:asp-project:5.0.0:*:*:*:*:*:*:*pkg:nuget/Microsoft.AspNetCore.Mvc.Versioning@5.0.0 0Low8
Microsoft.EntityFrameworkCore.Design:8.0.0pkg:nuget/Microsoft.EntityFrameworkCore.Design@8.0.0 08
Microsoft.EntityFrameworkCore.SqlServer:8.0.0cpe:2.3:a:www-sql_project:www-sql:8.0.0:*:*:*:*:*:*:*pkg:nuget/Microsoft.EntityFrameworkCore.SqlServer@8.0.0 0Low8
Microsoft.EntityFrameworkCore.Tools:8.0.0pkg:nuget/Microsoft.EntityFrameworkCore.Tools@8.0.0 08
Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1pkg:nuget/Microsoft.Extensions.Configuration.EnvironmentVariables@6.0.1 08
Microsoft.Extensions.Configuration.Json:6.0.0pkg:nuget/Microsoft.Extensions.Configuration.Json@6.0.0 08
Microsoft.Extensions.Configuration:6.0.1pkg:nuget/Microsoft.Extensions.Configuration@6.0.1 08
Microsoft.Extensions.DependencyInjection:6.0.1pkg:nuget/Microsoft.Extensions.DependencyInjection@6.0.1 08
Microsoft.Extensions.Logging.Console:6.0.0pkg:nuget/Microsoft.Extensions.Logging.Console@6.0.0 08
Microsoft.Extensions.Logging:6.0.0pkg:nuget/Microsoft.Extensions.Logging@6.0.0 08
Newtonsoft.Json:13.0.3pkg:nuget/Newtonsoft.Json@13.0.3 07
PayoutAdapter.API.csproj 02
PayoutAdapter.csproj 02
PayoutCodePipelineDeployAPI.csproj 02
PayoutEntity.dllpkg:generic/PayoutEntity@1.0.0 013
Pomelo.EntityFrameworkCore.MySql:8.0.0cpe:2.3:a:mysql:mysql:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:www-sql_project:www-sql:8.0.0:*:*:*:*:*:*:*
pkg:nuget/Pomelo.EntityFrameworkCore.MySql@8.0.0 0Low8
SSH.NET:2016.1.0cpe:2.3:a:ssh:ssh:2016.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ssh.net_project:ssh.net:2016.1.0:*:*:*:*:*:*:*
pkg:nuget/SSH.NET@2016.1.0 0Low6
SSH.NET:2020.0.0cpe:2.3:a:ssh:ssh:2020.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ssh.net_project:ssh.net:2020.0.0:-:*:*:*:.net:*:*
pkg:nuget/SSH.NET@2020.0.0MEDIUM1Highest6
StatusHandler.csproj 02
SwaggerController.js 00
Swashbuckle.AspNetCore:6.4.0pkg:nuget/Swashbuckle.AspNetCore@6.4.0 06
TransactionHandler.csproj 02
TransactionSwagger.js 00
package.json 00
swagger.js 00
swaggerDefinition.js 00

Dependencies (vulnerable)

APF.Core3.1.API:6.0.0.*

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

APF.Core3.1.AWS:6.0.0.*

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\TransactionHandler\TransactionHandler.csproj

Identifiers

APF.Core3.1:6.0.0.*

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\TransactionHandler\TransactionHandler.csproj

Identifiers

APF.Core3.1:6.0.0.12

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

APF.Core3.1:6.0.0.8

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.APIGateway:3.7.100.22

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.CodePipeline:3.7.100.22

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.Core:3.7.100.22

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.Extensions.NETCore.Setup:3.7.2

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

AWSSDK.S3:3.7.100

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.S3:3.7.9.23

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

AWSSDK.SecurityToken:3.7.100.22

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AWSSDK.SimpleSystemsManagement:3.7.100.2

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Amazon.Lambda.AspNetCoreServer:6.1.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Amazon.Lambda.Core:2.1.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Amazon.Lambda.S3Events:2.0.1

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

Amazon.Lambda.SNSEvents:2.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

Amazon.Lambda.Serialization.Json:2.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

Amazon.Lambda.Serialization.SystemTextJson:2.3.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

AutoMapper.Extensions.Microsoft.DependencyInjection:12.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

AutoMapper:12.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

AwsParameterStore.Microsoft.Extensions.Configuration:0.7.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

FluentValidation.DependencyInjectionExtensions:11.9.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

FluentValidation:11.9.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

Hashids.net:1.3.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

Lumigo.DotNET:1.0.45

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Microsoft.AspNetCore.Authentication.JwtBearer:3.1.3

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

CVE-2021-34532 (OSSINDEX)  

ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CWE-noinfo

CVSSv2:
  • Base Score: LOW (2.0999999046325684)
  • Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:*:Microsoft.AspNetCore.Authentication.JwtBearer:3.1.3:*:*:*:*:*:*:*

Microsoft.AspNetCore.Mvc.NewtonsoftJson:6.0.24

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Microsoft.AspNetCore.Mvc.Versioning:5.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Microsoft.EntityFrameworkCore.Design:8.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Microsoft.EntityFrameworkCore.SqlServer:8.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

Microsoft.EntityFrameworkCore.Tools:8.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

Microsoft.Extensions.Configuration.EnvironmentVariables:6.0.1

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Microsoft.Extensions.Configuration.Json:6.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Microsoft.Extensions.Configuration:6.0.1

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

Microsoft.Extensions.DependencyInjection:6.0.1

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Microsoft.Extensions.Logging.Console:6.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

Microsoft.Extensions.Logging:6.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

Newtonsoft.Json:13.0.3

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj

Identifiers

PayoutAdapter.API.csproj

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj
MD5: 49b686017356691fd3958ccee59617bb
SHA1: 6a8fda55f69a630ffdfbfb786da1a3baafb2c1bf
SHA256:54690e3f255983ca7b28f56f015830c0386d55e97720417d3ba7aee2ac799899

Identifiers

  • None

PayoutAdapter.csproj

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj
MD5: 475c32e8f585c0c67a47cde7619fae14
SHA1: 771b7e38d81c5be9d0b21df7ff44b74c7db158fb
SHA256:409d0fca7f447c231a56b48f2237e055585efced4868bd740aec55ce2217824e

Identifiers

  • None

PayoutCodePipelineDeployAPI.csproj

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutCodePipelineDeployAPI\PayoutCodePipelineDeployAPI.csproj
MD5: b6fce2c49bc94a08111bd72e9493b86a
SHA1: d1ebdd80916fb7d6291b6cc6e0cca95414f2fd40
SHA256:ed64a4ee108f6cc22f5d7f46c94c9406df76cc59df01ef13a45c76f710172aed

Identifiers

  • None

PayoutEntity.dll

Description:

PayoutEntity

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\libs\PayoutEntity.dll
MD5: f0695e5669da6523a7b22d93111bf489
SHA1: bfff569d31b69001bd5ed312522f04cb1f9e4e1d
SHA256:2f1495cbe72386f2ecdfb9eb8d8fbcac43bdf8612a6686724d9d78b14cd1a5c8

Identifiers

Pomelo.EntityFrameworkCore.MySql:8.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter\PayoutAdapter.csproj

Identifiers

SSH.NET:2016.1.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj

Identifiers

  • pkg:nuget/SSH.NET@2016.1.0  (Confidence:Highest)
  • cpe:2.3:a:ssh:ssh:2016.1.0:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:ssh.net_project:ssh.net:2016.1.0:*:*:*:*:*:*:*  (Confidence:Low)  

SSH.NET:2020.0.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\TransactionHandler\TransactionHandler.csproj

Identifiers

CVE-2022-29245  

SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with a weak random number generator whose seed can be brute forced. This allows an attacker who is able to eavesdrop on the communications to decrypt them. Version 2020.0.2 contains a patch for this issue. As a workaround, one may disable support for `curve25519-sha256` and `curve25519-sha256@libssh.org` key exchange algorithms.
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CVSSv3:
  • Base Score: MEDIUM (5.9)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:2.2/RC:R/MAV:A
CVSSv2:
  • Base Score: MEDIUM (4.3)
  • Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N

References:

Vulnerable Software & Versions: (show all)

StatusHandler.csproj

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\StatusHandler\StatusHandler.csproj
MD5: fd5f26048a2f021ae85ad9b78bdfdd2d
SHA1: efd618d49c08346bd1187c32cd98d4b629b50663
SHA256:166a5726f8ec5932919a5d0d6a51475fca3c978498c5d57b7335e1feac499fd8

Identifiers

  • None

SwaggerController.js

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutMerchant.Swagger.API\swagger\controller\SwaggerController.js
MD5: ea5c6a29560ad544f6eef7cc8fa98f53
SHA1: 8de53cd42626b49cd7055cdfc14d47a94e0332e0
SHA256:6e9d16cae89824286bcc50bd1f73dc228360ecd0d324c2afd2ec89df607afbc6

Identifiers

  • None

Swashbuckle.AspNetCore:6.4.0

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutAdapter.API\PayoutAdapter.API.csproj

Identifiers

TransactionHandler.csproj

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\TransactionHandler\TransactionHandler.csproj
MD5: 3fb28547731008206780cfc63acb416f
SHA1: 981940220de738a977c071bbd2ddb2be83124f19
SHA256:cac5ffdd5873c43dd6a1c31c4b2c838227294fd0edc040970570cce9a7951434

Identifiers

  • None

TransactionSwagger.js

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutMerchant.Swagger.API\swagger\definitions\TransactionSwagger.js
MD5: 50758a2d9ab92dd7b82cc4b07bb5eed5
SHA1: fdad1e72ecd75473e452974f9aa673a1d5915e36
SHA256:6dbd2c1c59e15c173ca456709a3a2d3a28bad5b1deb1efcdfe4b9ed321a49341

Identifiers

  • None

package.json

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutMerchant.Swagger.API\package.json
MD5: 99e15b5d9858b477442716c33d83de34
SHA1: 26b0c01ac4525b39abcbecee02ca4339aa86f73a
SHA256:6a6435019db1810ef7343576b579d934d28d9239b2113d761f877c9abbd6f6dd

Identifiers

  • None

swagger.js

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutMerchant.Swagger.API\swagger.js
MD5: 8c966df86ee27632be72505b900f5916
SHA1: 9763a3faecb7eb413fff25dc9b64d48180ad717d
SHA256:2361cc5e66651683d9f2ad44475939cb656919330e9eda7752d39bceeb20a068

Identifiers

  • None

swaggerDefinition.js

File Path: D:\Auropayrepos\Payout\PayoutAdapter\src\PayoutMerchant.Swagger.API\swaggerDefinition.js
MD5: 0cd7e8876e33919f448540bf11161400
SHA1: a9183fdafd7f3f5887b2d40ba03d6aa5be4f31b2
SHA256:72d7732d9443d9e7c9292e7af5a03d52cfc88e87cc5f8928570df931bb82b024

Identifiers

  • None


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.