Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/eclipse/angus/angus-activation/2.0.0/angus-activation-2.0.0.jar MD5: 834539f269d476663784d8571048f3c4 SHA1: 72369f4e2314d38de2dcbb277141ef0226f73151 SHA256:3a12d321a0f35aa9458ff9b6ee93a3de76b78e3f18b077c81721473d83079147 Referenced In Project/Scope: lastmission:runtime angus-activation-2.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/antlr/antlr4-runtime/4.13.0/antlr4-runtime-4.13.0.jar MD5: bff95723c494b332b14575d713a65df4 SHA1: 5a02e48521624faaf5ff4d99afc88b01686af655 SHA256:bd7f7b5d07bc0b047f10915b32ca4bb1de9e57d8049098882e4453c88c076a5d Referenced In Project/Scope: lastmission:runtime antlr4-runtime-4.13.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/net/bytebuddy/byte-buddy/1.17.5/byte-buddy-1.17.5.jar MD5: cf90ce9f1d325155ec7b0276a781c592 SHA1: 88450f120903b7e72470462cdbd2b75a3842223c SHA256:71568c9f8396677219f650268fbf6493ded484edcdbdf2dae6129ca5be81e8db Referenced In Project/Scope: lastmission:runtime byte-buddy-1.17.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar MD5: e91fcd30ba329fd1b0b6dc5321fd067c SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c SHA256:aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b Referenced In Project/Scope: lastmission:runtime classmate-1.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/com/h2database/h2/2.3.232/h2-2.3.232.jar MD5: 756154ae197457f2995b89c11bc9b2c3 SHA1: 4fcc05d966ccdb2812ae8b9a718f69226c0cf4e2 SHA256:8dae62d22db8982c3dcb3826edb9c727c5d302063a67eef7d63d82de401f07d3 Referenced In Project/Scope: lastmission:compile h2-2.3.232.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
Common reflection code used in support of annotation processing
License:
Apache License Version 2.0: https://opensource.org/licenses/Apache-2.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/hibernate/common/hibernate-commons-annotations/7.0.3.Final/hibernate-commons-annotations-7.0.3.Final.jar MD5: 6698f99235fe6d36c42caaf2e6b52797 SHA1: e183c4be8bb41d12e9f19b374e00c34a0a85f439 SHA256:0db2fd57d5e43688ac6ed5cdf36deaf05d84340dcc24c2dd2a2114de38e5175d Referenced In Project/Scope: lastmission:runtime hibernate-commons-annotations-7.0.3.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/hibernate/orm/hibernate-core/6.6.44.Final/hibernate-core-6.6.44.Final.jar MD5: 402ce2743a3d9380654d6f00b4d69e75 SHA1: ee7b1495e4939dea693523ac59717aa32d499dd4 SHA256:041a1b9791331d64917ac995bf215ebb866ec9115c99a708a34df317ab74ab36 Referenced In Project/Scope: lastmission:compile hibernate-core-6.6.44.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/com/sun/istack/istack-commons-runtime/4.1.1/istack-commons-runtime-4.1.1.jar MD5: 8a0b5fe40f96b22dbf7a2d971bf21964 SHA1: 9b3769c76235bc283b060da4fae2318c6d53f07e SHA256:7e8148c5bf5d5ae6f8c4534c1873f82e80bf7f9164fd09ee573df0013918dcd3 Referenced In Project/Scope: lastmission:runtime istack-commons-runtime-4.1.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.0/jakarta.activation-api-2.1.0.jar MD5: 7c79641566f97305e17c5f7b9bb33fc3 SHA1: a58861b5deac5e151140511cf57d6b80a83f2d20 SHA256:56e8d994095fe49c28138c60291482f66f18d12ac2b720e938697dce6a3135c7 Referenced In Project/Scope: lastmission:runtime jakarta.activation-api-2.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/annotation/jakarta.annotation-api/3.0.0/jakarta.annotation-api-3.0.0.jar MD5: 7faffaab962918da4cf5ddfd76609dd2 SHA1: 54f928fadec906a99d558536756d171917b9d936 SHA256:b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2 Referenced In Project/Scope: lastmission:compile jakarta.annotation-api-3.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/jakarta.enterprise/jakarta.enterprise.cdi-api@4.1.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/el/jakarta.el-api/6.0.0/jakarta.el-api-6.0.0.jar MD5: 248086411e850bb59dac502ee785c6b0 SHA1: c937953432d6811ce5a460b6ef90750beecb35c2 SHA256:f33d0becf2d5516730ba5cc99a7b5a2b1f62986bf0a3370249cdff9a2f171507 Referenced In Project/Scope: lastmission:compile jakarta.el-api-6.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/jakarta.enterprise/jakarta.enterprise.cdi-api@4.1.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/enterprise/jakarta.enterprise.cdi-api/4.1.0/jakarta.enterprise.cdi-api-4.1.0.jar MD5: f72ee39b19274ffe26cac952acae6dc3 SHA1: fed9518709d33252bfe0817fe61ad4dfd1b2e848 SHA256:c42c808f17925129a0800f618febe050d966e181a4c7384c8a5e7a0283d68699 Referenced In Project/Scope: lastmission:compile jakarta.enterprise.cdi-api-4.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/enterprise/jakarta.enterprise.lang-model/4.1.0/jakarta.enterprise.lang-model-4.1.0.jar MD5: fd9efbe0808984a89690e04ea28cd368 SHA1: 9270ae3df4239d4f337215403ebc9801fe659a2b SHA256:bb56f571f60d2862b2387d5468fe8f5540f8094727283ed991f89082708095ee Referenced In Project/Scope: lastmission:compile jakarta.enterprise.lang-model-4.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/jakarta.enterprise/jakarta.enterprise.cdi-api@4.1.0
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/inject/jakarta.inject-api/2.0.1/jakarta.inject-api-2.0.1.jar MD5: 72003bf6efcc8455d414bbd7da86c11c SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e SHA256:f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c Referenced In Project/Scope: lastmission:compile jakarta.inject-api-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
Jakarta Interceptors defines a means of interposing on business method invocations
and specific events—such as lifecycle events and timeout events—that occur on instances
of Jakarta EE components and other managed classes.
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/interceptor/jakarta.interceptor-api/2.2.0/jakarta.interceptor-api-2.2.0.jar MD5: ef5c0cb454edafbd9e5b3cb0f728f61f SHA1: ed3605f9c5428d45549d4720235f3e943339f39a SHA256:d240d72b4dd38a2e431c804079810010cb97903678fa5f987fb7434878b04398 Referenced In Project/Scope: lastmission:compile jakarta.interceptor-api-2.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/persistence/jakarta.persistence-api/3.2.0/jakarta.persistence-api-3.2.0.jar MD5: 79acec18d202797dcba1fff596a47684 SHA1: bb75a113f3fa191c2c7ee7b206d8e674251b3129 SHA256:be8a26b0e75c84c1b7600f759256fbc68d60333d89ec0ce3f784fc3ffa09aa8c Referenced In Project/Scope: lastmission:compile jakarta.persistence-api-3.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/transaction/jakarta.transaction-api/2.0.1/jakarta.transaction-api-2.0.1.jar MD5: 5315974a3935e342b40849478e1c9966 SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a SHA256:50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875 Referenced In Project/Scope: lastmission:compile jakarta.transaction-api-2.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.0/jakarta.xml.bind-api-4.0.0.jar MD5: b5132a66e2d3a60904f8035a1f8a34a8 SHA1: bbb399208d288b15ec101fa4fcfc4bd77cedc97a SHA256:57e3796ad5753640088f5f9d3c53c183f2c250b7dad90529ea3e19a5515aa122 Referenced In Project/Scope: lastmission:runtime jakarta.xml.bind-api-4.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/io/smallrye/jandex/3.2.0/jandex-3.2.0.jar MD5: 703254a1bd4c37efeebdc0a283c65565 SHA1: f17ad860f62a08487b9edabde608f8ac55c62fa7 SHA256:6da3e9ce8d0c0a433f3e7ce610a3c66accb00c71fee67aa0ff3e5a841395ac15 Referenced In Project/Scope: lastmission:runtime jandex-3.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-base/25/javafx-base-25-linux.jar MD5: fe25b70bad424aa18876ad53cc5a61da SHA1: 1f52994bfed549d07ef52a5fa4603db17ea44fbe SHA256:32425946bb8b8db0717cfa2fb2e00e21cd489f35b9662b6faca18b615a4a9669 Referenced In Project/Scope: lastmission:compile javafx-base-25-linux.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.openjfx/javafx-graphics@25
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-base/25/javafx-base-25.jar MD5: 4e151e87928c9b427908baa2644a0a37 SHA1: ea9353f332c3461a58bae6bbb2a2aa1469fe3d71 SHA256:7e2edc1858c3f7eef353bf32b4fee5b8d3277e7567e6b410f27f44fcc99ad51c Referenced In Project/Scope: lastmission:compile javafx-base-25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.openjfx/javafx-graphics@25
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-controls/25/javafx-controls-25-linux.jar MD5: dd5b3f49e7a96a771e8ea2e21f72c107 SHA1: d2a1bb11a5fb507ed5da975eee949d8f78a75d9a SHA256:37355e4d91c67e88fd9815f601e6ac5b55ddde9f5e9b93fc8f4aa04577e691d3 Referenced In Project/Scope: lastmission:compile javafx-controls-25-linux.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.openjfx/javafx-controls@25
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-controls/25/javafx-controls-25.jar MD5: 183e65f9a54ff8fba5bd0b59c02c010a SHA1: 3baa78c90ec73f3c2e3c4f3a09ff287431a680f0 SHA256:7627805fa9011423ab7798dfe3c3e54fa42f5e4c0747fdaa8b3c6c0dc9e214f2 Referenced In Project/Scope: lastmission:compile javafx-controls-25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-fxml/25/javafx-fxml-25-linux.jar MD5: 6477c4c9e2fc76dda935e51b24afb08d SHA1: 88f86d5e0de073d5a5718c0d200a969186f4dfdf SHA256:394ae32f64c122c14fbd10ef49bdde7dbb05569b7ab8e7f9f170c81924b95a2b Referenced In Project/Scope: lastmission:compile javafx-fxml-25-linux.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.openjfx/javafx-fxml@25
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-fxml/25/javafx-fxml-25.jar MD5: f0ff551811c6886595193759edab7ca6 SHA1: 467465994c63da0aa5334234f860e0aa39b0eae6 SHA256:ce3be379dc230c2d3420c2a8b670254f50be208ca8415b0d6f2996b7b930090b Referenced In Project/Scope: lastmission:compile javafx-fxml-25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-graphics/25/javafx-graphics-25.jar MD5: 3c92b948f4541fbd0a3783d799e23cc7 SHA1: aa61e4a0b057b5e65f576f7c224ebd0f3142cd37 SHA256:cddb66bf4adc94c54386c84f929f6f3c0f502efff6581e75500ee70e442fc9aa Referenced In Project/Scope: lastmission:compile javafx-graphics-25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-media/25/javafx-media-25-linux.jar MD5: 88066d74c0f058ef143c0f7b8ee61318 SHA1: f74ecde162f9e434a0c37bd9b1a7fe38b8013096 SHA256:0ce73fd23aba5aa2408771640e916e32e25ed1c24dba1e03e43e654016b4b952 Referenced In Project/Scope: lastmission:compile javafx-media-25-linux.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.openjfx/javafx-media@25
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/openjfx/javafx-media/25/javafx-media-25.jar MD5: 210289b7ca77712053cb4a55ccef09e6 SHA1: 125004731cd76e8063b22d0a5d9e3a3214ffd7ee SHA256:062addff4eec5de283dea32abfb522663f08329ba0c09db24ab3d98b0379b9a1 Referenced In Project/Scope: lastmission:compile javafx-media-25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/glassfish/jaxb/jaxb-core/4.0.2/jaxb-core-4.0.2.jar MD5: f47f53ebb68dd97dea880a6eeb49814e SHA1: 08c29249f6c10f4ee08967783831580b0f5c5360 SHA256:d7ff2954ad78480bbab9391cccff3a22f42a82b6e09aeca1c7d502411c470ccd Referenced In Project/Scope: lastmission:runtime jaxb-core-4.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/glassfish/jaxb/jaxb-runtime/4.0.2/jaxb-runtime-4.0.2.jar MD5: b7fa25f7058a49fe29ad39619efb4022 SHA1: e4e4e0c5b0d42054d00dc4023901572a60d368c7 SHA256:1bc271e61b71ca4bd89eb053f3d2c91d478211b02a8982cb520f216fe0e9a939 Referenced In Project/Scope: lastmission:runtime jaxb-runtime-4.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/jboss/logging/jboss-logging/3.5.0.Final/jboss-logging-3.5.0.Final.jar MD5: bdb57db05e9905e02dbbf1cbedf26469 SHA1: c19307cc11f28f5e2679347e633a3294d865334d SHA256:7bb135b081952f6d32d83374619ae5201b05ca3bf862a28dd111016ce19b2c07 Referenced In Project/Scope: lastmission:runtime jboss-logging-3.5.0.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final
A versatile, industrial-grade, and reference implementation of the Log4j API.
It bundles a rich set of components to assist various use cases:
Appenders targeting files, network sockets, databases, SMTP servers;
Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;
Filters that can be configured using log event rates, regular expressions, scripts, time, etc.
It contains several extension points to introduce custom components, if needed.
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3.jar MD5: 3f52ab7782fdd1349bd872b5dcf48bed SHA1: 7f6a261243ca767c7f38fd4b542bcde626c8894e SHA256:7eb4084596ae25bd3c61698e48e8d0ab65a9260758884ed5cbb9c6e55c44a56a Referenced In Project/Scope: lastmission:compile log4j-core-2.24.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:
* The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.
* The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.
Users of the SyslogAppender are not affected, as its configuration attributes were not modified.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
CWE-117 Improper Output Neutralization for Logs, CWE-684 Incorrect Provision of Specified Functionality
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
Two groups of users are affected:
* Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.
* Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.
Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue.
Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters.
The impact depends on the StAX implementation in use:
* JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.
* Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true.
This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:
* The attacker is able to intercept or redirect network traffic between the client and the log receiver.
* The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).
Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.
As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.
CWE-295 Improper Certificate Validation, CWE-297 Improper Validation of Certificate with Host Mismatch
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element.
Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.
A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:
* An SMTP, Socket, or Syslog appender is in use.
* TLS is configured via a nested <Ssl> element.
* The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.
This issue does not affect users of the HTTP appender, which uses a separate verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName attribute that was not subject to this bug and verifies host names by default.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
CWE-295 Improper Certificate Validation, CWE-297 Improper Validation of Certificate with Host Mismatch
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.
An attacker can exploit this issue only if both of the following conditions are met:
* The application uses JsonTemplateLayout.
* The application logs a MapMessage containing an attacker-controlled floating-point value.
Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue.
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!
License:
The MIT License: https://projectlombok.org/LICENSE
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/projectlombok/lombok/1.18.42/lombok-1.18.42.jar MD5: f29149836e0187fb9fd95d82dc718d36 SHA1: 8365263844ebb62398e0dc33057ba10ba472d3b8 SHA256:3488a4e9994c26596baaceebee58cad36a50e3bdaec5be72b5834d3c3b560306 Referenced In Project/Scope: lastmission:provided lombok-1.18.42.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/net.dobiasovsky/lastmission@1.0.0
TXW is a library that allows you to write XML documents.
File Path: /builds/michaldobiasovsky/last-mission/.m2/repository/org/glassfish/jaxb/txw2/4.0.2/txw2-4.0.2.jar MD5: d6f9cea932f006bad4ac3fd48dc8c799 SHA1: 24e167be69c29ebb7ee0a3b1f9b546f1dfd111fc SHA256:ea71912e4f0a42530f77c9840ae90019c46402dedfdf007cff03797429a0cf0c Referenced In Project/Scope: lastmission:runtime txw2-4.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.hibernate.orm/hibernate-core@6.6.44.Final