Update solr.version#34
Security Report
You have successfully remediated 7 vulnerabilities, but introduced 12 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2024-8309Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/langchain-0.0.331.dist-info Dependency Hierarchy: -> ❌ langchain-0.0.331-py3-none-any.whl (Vulnerable Library) |
9.8 | langchain-0.0.331-py3-none-any.whl | Upgrade to version: langchain - 0.2.0 | None | |
CVE-2025-48988Path to dependency file: /nifi-registry/nifi-registry-core/nifi-registry-web-api/pom.xml Path to vulnerable library: /nifi-registry/nifi-registry-core/nifi-registry-web-api/pom.xml Dependency Hierarchy: -> spring-boot-starter-web-3.2.0.jar (Root Library) -> spring-boot-starter-tomcat-3.2.0.jar -> ❌ tomcat-embed-core-10.1.16.jar (Vulnerable Library) |
7.5 | tomcat-embed-core-10.1.16.jar | None | ||
CVE-2025-49125Path to dependency file: /nifi-registry/nifi-registry-core/nifi-registry-web-api/pom.xml Path to vulnerable library: /nifi-registry/nifi-registry-core/nifi-registry-web-api/pom.xml Dependency Hierarchy: -> spring-boot-starter-web-3.2.0.jar (Root Library) -> spring-boot-starter-tomcat-3.2.0.jar -> ❌ tomcat-embed-core-10.1.16.jar (Vulnerable Library) |
6.5 | tomcat-embed-core-10.1.16.jar | None | ||
CVE-2021-41496Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> langchain-0.0.331-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-41496Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> chromadb-0.4.14-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-41496Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> onnxruntime-1.19.2-cp39-cp39-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.5 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-41495Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> langchain-0.0.331-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-41495Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> chromadb-0.4.14-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-41495Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> onnxruntime-1.19.2-cp39-cp39-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | None | ||
CVE-2021-33430Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> langchain-0.0.331-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Upgrade to version: numpy - 1.21.0 | None | |
CVE-2021-33430Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> chromadb-0.4.14-py3-none-any.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Upgrade to version: numpy - 1.21.0 | None | |
CVE-2021-33430Path to dependency file: /nifi-python-extensions/nifi-text-embeddings-module/src/main/python/vectorstores/requirements.txt Path to vulnerable library: /tmp/ws-ua_20250630145530_GJHFCV/python_YBFHJN/202506301455311/env/lib/python3.9/site-packages/numpy-1.26.4.dist-info Dependency Hierarchy: -> onnxruntime-1.19.2-cp39-cp39-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl (Root Library) -> ❌ numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.3 | numpy-1.26.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Upgrade to version: numpy - 1.21.0 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2023-50298 | solr-solrj-streaming-9.4.0.jar |
| CVE-2021-41496 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2021-41495 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2025-50181 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2025-50182 | urllib3-2.0.7-py3-none-any.whl |
| CVE-2021-33430 | numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl |
| CVE-2025-4565 | protobuf-4.24.4-cp37-abi3-manylinux2014_x86_64.whl |
Base branch total remaining vulnerabilities: 73
Base branch commit: null
Total libraries scanned: 1975
Scan token: e6499c80de0c42ce96f4dea191d0526c