Bump com.h2database:h2 from 2.1.214 to 2.2.220 #524
An automation triggered a pipeline warning
Found 8 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.
Output from Automations
4 rules were checked:
If a new dependency is added where the license risk is at least medium
then notify all users in the group admins by email
✔️ The rule did not trigger. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before
then notify all users in the group admins by email
✔️ The rule did not trigger. Manage rule
If there is a dependency where the license risk is at least high
then send a pipeline warning
✔️ The rule did not trigger. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected
then send a pipeline warning
| Vulnerability | CVSS2 | CVSS3 | Dependency | Dependency Licenses |
|---|---|---|---|---|
| CVE-2019-17571 | 7.5 | 9.8 | log4j:log4j (Maven) | Apache-2.0 |
| CVE-2022-23305 | 6.8 | 9.8 | log4j:log4j (Maven) | Apache-2.0 |
| CVE-2024-49203 | N/A | 9.8 | com.querydsl:querydsl-apt (Maven) | Apache-2.0 |
| CVE-2024-49203 | N/A | 9.8 | com.querydsl:querydsl-jpa (Maven) | Apache-2.0 |
| CVE-2022-23302 | 6 | 8.8 | log4j:log4j (Maven) | Apache-2.0 |
| CVE-2022-45868 | N/A | 7.8 | com.h2database:h2 (Maven) | EPL-1.0, MPL-2.0 |
| CVE-2021-4104 | 6 | 7.5 | log4j:log4j (Maven) | Apache-2.0 |
| CVE-2021-47621 | N/A | 7.5 | io.github.classgraph:classgraph (Maven) | MIT |
| CVE-2020-9488 | 4.3 | 3.7 | log4j:log4j (Maven) | Apache-2.0 |