ããã¯ããªã«ãããããŠæžãããã®ïŒ
OWASP Dependency-Check Maven PluginãšãããäŸåã©ã€ãã©ãªã®è匱æ§æ å ±ã確èªã§ãããã©ã°ã€ã³ããããšããããšãç¥ããŸããŠã
dependency-check-maven – Usage
ã¡ãã£ãšããã¡ããè©ŠããŠã¿ããããªãšã
OWASP Dependency-CheckïŒ
OWASP Dependency-Checkãšããã®ã¯ããããžã§ã¯ãã®äŸåããã³ã³ããŒãã³ãïŒã©ã€ãã©ãªïŒã®å
¬éãããŠããæ¢ç¥ã®è匱æ§ã
確èªããŠããããœãããŠã§ã¢ã§ãã
OWASP Dependency Check - OWASP
確èªã®çµæãè匱æ§ãèŠã€ãã£ãå Žåã¯è©²åœããCVEã®ãªã¹ãã衚瀺ãããŸãã
ããã¥ã¡ã³ãã«ãããšãJavaã.NETããµããŒããããŠãããPythonãRubyãPHPãNode.jsãå®éšçã«ãµããŒããããŠããæš¡æ§ã
Javaã ãšãMavenãGradleãªã©ã¯ãã¡ãã
dependency-check-maven – Usage
sbtãApache Antåãã®ã¿ã¹ã¯ããã£ããããŸããäžèŠ§ã¯ããã¡ãã
ãã®ä»ã®ãã¡ã€ã«ã®çš®é¡ã«ããAnalyzerã¯ããã¡ãã
dependency-check – File Type Analyzers
ä»åã¯ãApache Mavenåãã®ãã®ã䜿ã£ãŠè©ŠããŠãããããšæããŸãã
OWASP Dependency-Check Maven Plugin
ãšããããã§ãOWASP Dependency-Check Maven Pluginã䜿ã£ãŠã¿ãããšæããŸãã
OWASP Dependency-Check Maven Pluginã¯ãOWASP Dependency-CheckãšãããœãããŠã§ã¢çŸ€ã®ãApache Mavenåãã®ãã©ã°ã€ã³ã§ãã
â»ãã®ãŸãŸ
dependency-check-maven – Usage
䜿ãæ¹ãã§ããããšã¯ãããããŒãžã«ã»ãŒæžããŠãããŸãããã ããããããªæãã§ãã
- ãmvn dependency-check:checkãã«ããäŸåã©ã€ãã©ãªã®è匱æ§ã®ç¢ºèªãšã¬ããŒãäœæ
- ãmvn dependency-check:aggregateãã«ããã¬ããŒãäœæïŒãmvn siteããšåãããŠäœ¿ãïŒ
ãã§ãã¯å¯Ÿè±¡ã®ã©ã€ãã©ãªã®ã¹ã³ãŒãã¯ãåŸã§ããŸãæžããŸãããtestã¹ã³ãŒã以å€ãããã©ã«ãã§ãã§ãã¯ããŸãã
ãŸããè匱æ§æ
å ±ã¯NVDã®JSONãã£ãŒãããããŠã³ããŒãããŠããŒã¿ããŒã¹ãæ§ç¯ããã®ã§ãããç¹ã«ååã¯ãã£ãããªæéã
ããããŸãã
ããã¥ã¡ã³ãã«ã¯ãååã¯ããŠã³ããŒããæ
å ±ã®æŽæ°ã«10å以äžãããããšããããšæžãããŠããŸãããæå
ã®ç°å¢ã§ã¯4åã»ã©ã§
å®è¡ã§ããŸããã
2åç®ä»¥éã¯çç¥ãããŸãããå®æçã«ããŒã«ã«ã®ããŒã¿ãæŽæ°ããå¿ èŠããããŸãïŒãã©ã°ã€ã³ãè¡ããŸãïŒã
NVDã®ããŒã¿ã4æéããšãRetireJSã24æéããšã«ç¢ºèªããŠããã¿ããã§ãã
è©ŠããŠã¿ã
ããã§ã¯ãæ©éè©ŠããŠã¿ãŸãããã
ä»åã®ç°å¢ã¯ããã¡ãã§ãã
$ java -version openjdk version "11.0.3" 2019-04-16 OpenJDK Runtime Environment (build 11.0.3+7-Ubuntu-1ubuntu218.04.1) OpenJDK 64-Bit Server VM (build 11.0.3+7-Ubuntu-1ubuntu218.04.1, mixed mode, sharing) $ mvn -version Apache Maven 3.6.1 (d66c9c0b3152b2e69ee9bac180bb8fcc8e6af555; 2019-04-05T04:00:29+09:00) Maven home: $HOME/.sdkman/candidates/maven/current Java version: 11.0.3, vendor: Oracle Corporation, runtime: /usr/lib/jvm/java-11-openjdk-amd64 Default locale: ja_JP, platform encoding: UTF-8 OS name: "linux", version: "4.15.0-54-generic", arch: "amd64", family: "unix"
ãŸãã¯ãpom.xmlã«OWASP Dependency-Check Maven Pluginãè¿œå ããŸãã
<build> <plugins> <plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>5.0.0</version> </plugin> </plugins> </build>
ä»åã¯ããè©ŠããšããŠApache Struts 2ã®å€ãããŒãžã§ã³ãæã£ãŠããŸããã
<dependencies> <dependency> <groupId>org.apache.struts</groupId> <artifactId>struts2-core</artifactId> <version>2.3.34</version> </dependency> </dependencies>
å®è¡ã¯ããmvn dependency-check:checkãã§è¡ããŸãã
$ mvn dependency-check:check
çµæã2ã€ã®JARãã¡ã€ã«ããè匱æ§æ å ±ãæ€åºãããŸããã
One or more dependencies were identified with known vulnerabilities in owasp-dependency-check-example: struts2-core-2.3.34.jar (pkg:maven/org.apache.struts/struts2-core@2.3.34, cpe:2.3:a:apache:struts:2.3.34:*:*:*:*:*:*:*) : CVE-2018-11776, CVE-2018-1327 commons-fileupload-1.3.2.jar (pkg:maven/commons-fileupload/commons-fileupload@1.3.2, cpe:2.3:a:apache:commons_fileupload:1.3.2:*:*:*:*:*:*:*) : CVE-2016-1000031 See the dependency-check report for more details.
察å¿ããCVEã®IDãåºåãããŠããŸããã
ãã®æããtarget/dependency-check-report.htmlãã«ã¬ããŒããåºåãããŠããã®ã§ç¢ºèªããŠã¿ãŸãããã
ãã现ããæ å ±ãèŠãããšãã§ããNVDãžã®ãªã³ã¯ã衚瀺ããŠããããããŸãã
1çªç°¡åãªäœ¿ãæ¹ã¯ãããªæãã§ããã
äž»ãªèšå®ã¯ããã¡ããèŠããšããã§ãããã
dependency-check-maven – dependency-check:check
dependency-check-maven – Goals
ãŸããã¬ããŒãã®èªã¿æ¹ã¯ãã¡ãã«ãæžãããŠããŸãã
dependency-check – How To Read The Reports
ã¡ãªã¿ã«ãææ°çã«æŽæ°ãããš
<dependencies> <dependency> <groupId>org.apache.struts</groupId> <artifactId>struts2-core</artifactId> <version>2.5.20</version> </dependency> </dependencies>
è匱æ§æ å ±ã¯ãªããªããŸãããã
[INFO] --- dependency-check-maven:5.0.0:check (default-cli) @ owasp-dependency-check-example --- [INFO] Central analyzer disabled [INFO] Checking for updates [INFO] Skipping NVD check since last check was within 4 hours. [INFO] Skipping RetireJS update since last update was within 24 hours. [INFO] Check for updates complete (7 ms) [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (2 seconds) [INFO] Finished CPE Analyzer (2 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished RetireJS Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (1 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (4 seconds) [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 12.538 s [INFO] Finished at: 2019-06-29T20:45:53+09:00 [INFO] ------------------------------------------------------------------------
éŸå€ãè¶ããCVSSã¹ã³ã¢ä»¥äžã®è匱æ§ããã£ãå Žåã¯ããšã©ãŒã«ãã
æå®ããCVSSã¹ã³ã¢ä»¥äžã®è匱æ§ããã£ãå Žåã¯ããšã©ãŒã«ããããšãã§ããŸããããã§ã¯ã8以äžã§ããã°ãšã©ãŒã«ããŠã¿ãŸãããã
<plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>5.0.0</version> <configuration> <failBuildOnCVSS>8</failBuildOnCVSS> </configuration> </plugin>
Apache Struts 2ã¯ãè匱æ§ãå«ãã ããŒãžã§ã³ã«æ»ããŠãããŸãã
<dependencies> <dependency> <groupId>org.apache.struts</groupId> <artifactId>struts2-core</artifactId> <version>2.3.34</version> </dependency> </dependencies>
確èªã
$ mvn dependency-check:check
2ã€ã8以äžã®ãã®ããã£ãããã§ãããšã©ãŒãšãªããŸããã
[ERROR] Failed to execute goal org.owasp:dependency-check-maven:5.0.0:check (default-cli) on project owasp-dependency-check-example: [ERROR] [ERROR] One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '8.0': [ERROR] [ERROR] struts2-core-2.3.34.jar: CVE-2018-11776 [ERROR] commons-fileupload-1.3.2.jar: CVE-2016-1000031 [ERROR] [ERROR] See the dependency-check report for more details.
ã¡ãªã¿ã«ãã¹ã³ã¢ã«ã€ããŠã¯ãã¡ããåç §ã
CVSS v2.0ãšCVSS v3.0ã§ã¹ã³ã¢ãéã£ããããã®ã§ããããããã©ã¡ãã§èŠãŠããã®ããšãããšãäž¡æ¹èŠãŠããããã§ãã
ãmvn siteãã«çµ±åãã
ãmvn siteãã®çµæã«çµ±åããããšãã§ããŸãã以äžã®ããã«èšå®ã
<reporting> <plugins> <plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>5.0.0</version> <reportSets> <reportSet> <reports> <report>aggregate</report> </reports> </reportSet> </reportSets> </plugin> </plugins> </reporting> <build> <plugins> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-site-plugin</artifactId> <version>3.7.1</version> </plugin> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-project-info-reports-plugin</artifactId> <version>3.0.0</version> </plugin> </plugins> </build>
ãmvn siteããå®è¡ãããšããProject Reportsãã«ãdependency-check:aggregateãã衚瀺ãããããã«ãªããŸãã
ã¬ããŒãã
ç¹å®ã®ã¹ã³ãŒãã®äŸåé¢ä¿ã¯ããã§ãã¯å¯Ÿè±¡å€ã«ãã
ç¹å®ã®ã¹ã³ãŒãã®ã©ã€ãã©ãªãããã§ãã¯ã®å¯Ÿè±¡å€ã«ããããšãã§ããŸãã
ããäœçºçã§ãããApache Struts 2ã®äŸåé¢ä¿ã«å«ãŸããŠããCommons FileuploadãåãåºããŠãprovidedã¹ã³ãŒãã«ããŠã¿ãŸãããã
<dependencies> <dependency> <groupId>org.apache.struts</groupId> <artifactId>struts2-core</artifactId> <version>2.3.34</version> </dependency> <dependency> <groupId>commons-fileupload</groupId> <artifactId>commons-fileupload</artifactId> <version>1.3.2</version> <scope>provided</scope> </dependency> </dependencies>
ããã¥ã¡ã³ãã«ããµã³ãã«ãšããŠãããã®ã§ãããä»åã¯providedããã³runtimeã¹ã³ãŒãããã§ãã¯å¯Ÿè±¡å€ã«ããŠã¿ãŸãã
<plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>5.0.0</version> <configuration> <skipProvidedScope>true</skipProvidedScope> <skipRuntimeScope>true</skipRuntimeScope> </configuration> </plugin>
ãããšãprovidedã¹ã³ãŒãã§ããCommons Fileuploadã¯ãã¬ããŒãã«ã¯å«ãŸããªããªããŸãïŒçæãããHTMLãããããªããªããŸãïŒã
One or more dependencies were identified with known vulnerabilities in owasp-dependency-check-example: struts2-core-2.3.34.jar (pkg:maven/org.apache.struts/struts2-core@2.3.34, cpe:2.3:a:apache:struts:2.3.34:*:*:*:*:*:*:*) : CVE-2018-11776, CVE-2018-1327 See the dependency-check report for more details.
ããã©ã«ããã©ããªã£ãŠããããšãããšãèšå®ã«é¢ããããŒãžãèŠãŸãããã
dependency-check-maven – Goals
ã¹ã³ãŒã | ããã©ã«ãã§ãã§ãã¯å¯Ÿè±¡ã«å«ãŸããã | ã¹ãããããããã®ãããã㣠|
---|---|---|
compile | å«ãŸãã | ãªã |
test | å«ãŸããªã | skipTestScope |
runtime | å«ãŸãã | skipRuntimeScope |
provided | å«ãŸãã | skipProvidedScope |
system | å«ãŸãã | skipSystemScope |
ãŸããdependencyManagementã«èšèŒããå
容ã確èªããŠãããããã§ãããããã©ã«ãã§ã¯ã¹ãããããŸãããã®æåãå€æŽãããå Žåã¯ã
skipDependencyManagementããããã£ã䜿çšããŸãã
ããŒã«ã«ã®è匱æ§æ å ±ãæŽæ°ãã
OWASP Dependency-Check Maven Pluginã¯ãè匱æ§æ
å ±ãããŒã¿ããŒã¹ã«æã£ãŠããã®ã§ãããããã®æŽæ°ã ããå®è¡ããããšã
ã§ããŸãã
ãmvn dependency-check:update-onlyãã§ãã
$ mvn dependency-check:update-only
dependency-check-maven – dependency-check:update-only
ãªã®ã§ãããä»åã¯æŽæ°ãããŸããã§ããããã°ã«åºãŠããŸãããNVDã¯4æéãRetireJSã¯24æéããšã«ç¢ºèªããããã§ãã
[INFO] --- dependency-check-maven:5.0.0:update-only (default-cli) @ owasp-dependency-check-example --- [INFO] Central analyzer disabled [INFO] Checking for updates [INFO] Skipping NVD check since last check was within 4 hours. [INFO] Skipping RetireJS update since last update was within 24 hours. [INFO] Check for updates complete (9 ms
å®ã¯ããããmvn dependency-check:checkãã®æã«ãå®è¡ãããŠããã®ã§ããupdate-onlyãã¯æ¬åœã«æŽæ°ã®ã¿ã§ãã
ããŒã«ã«ã®è匱æ§æ å ±ãã¯ãªã¢ãã
ãŸããããŒã«ã«ã«æã£ãŠããè匱æ§æ å ±ãã¯ãªã¢ããã«ã¯ã以äžã®ã³ãã³ããå®è¡ããŸãã
$ mvn dependency-check:purge
ããŒã«ã«ã«æã£ãŠããããŒã¿ãåé€ãããã®ã§ã次åã¯ããŠã³ããŒãããããçŽãã«ãªããŸãã
[INFO] --- dependency-check-maven:5.0.0:purge (default-cli) @ owasp-dependency-check-example --- [INFO] Database file purged; local copy of the NVD has been removed [INFO] RetireJS repo removed successfully [INFO] OSS Cache directory purged
ããŒã«ã«ã«æã£ãŠããè匱æ§æ å ±ãšã¯ãã©ãã«ïŒ
ãããŸã§æžããšãããŒã«ã«ã«æã£ãŠããè匱æ§æ å ±ïŒNVDãRetireJSã®æ å ±ïŒãã©ãã«æã£ãŠããã®ããæ°ã«ãªããŸãã
çãã¯ãMavenããŒã«ã«ãªããžããªå ã§ãããã©ã°ã€ã³ãšã¯ãéãå Žæã«ãããã§ããã
$ find $HOME/.m2/repository/org/owasp/dependency-check-data/4.0 -type f $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/odc.mv.db $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/63/a0/63a0e302861c0932765a8fe91c9f2e51bd8d310f $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/bf/f9/bff94743cb2638fcaeac582bb552bf8f92d37708 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/c7/33/c733b453bc7d85ced5328c2ad8581aaeddc02d5a $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/0c/b4/0cb45bbb31457160fc2912bb6136ede905212009 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/81/27/812716eca563c1ca19b74b73f9a1fdda59d39c68 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/e9/04/e904eec7818f16ffa89f58cce17fb986f4f7eaf5 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/26/fc/26fca3f904f26e5120503afea2c3c84da1f8da2d $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/86/f7/86f71e409e1c0914d5da165d7cf99617cc8e3870 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/80/c3/80c3ee85a1f342d209d1fe00d90636995fa420e0 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/d4/36/d4369d9dc8466cf688c01ef731ba1050c56c7b54 $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/oss_cache/3b/4d/3b4da8057f9948ecb69821740f7c548e5d3404aa $HOME/.m2/repository/org/owasp/dependency-check-data/4.0/jsrepository.json
ãŸãšã
OWASP Dependency-Check Maven Pluginãè©ŠããŠã¿ãŸããã
NVDã§å ¬éãããŠããè匱æ§æ å ±ã§ãäŸåã©ã€ãã©ãªã確èªã§ããã®ã§ãªããªã䟿å©ãªã®ã§ã¯ãªãã§ããããã
å®è¡ããæã¯ãå°çšã®Maven Profileãäœããªãããmvn siteããå®è¡ããæãªããéåžžã®ãã«ããšã¯éãã¿ã€ãã³ã°ã§å®æçã«
è¡ãæãã«ãªããã§ããããã
ãªãã±
ååå®è¡æã®ãã°ãèŒããŠãããŸãã
[INFO] Central analyzer disabled [INFO] Checking for updates [INFO] NVD CVE requires several updates; this could take a couple of minutes. [INFO] Download Started for NVD CVE - 2003 [INFO] Download Started for NVD CVE - 2002 [INFO] Download Complete for NVD CVE - 2003 (1733 ms) [INFO] Processing Started for NVD CVE - 2003 [INFO] Download Started for NVD CVE - 2004 [INFO] Download Complete for NVD CVE - 2002 (2537 ms) [INFO] Download Started for NVD CVE - 2005 [INFO] Processing Started for NVD CVE - 2002 [INFO] Download Complete for NVD CVE - 2004 (1826 ms) [INFO] Processing Started for NVD CVE - 2004 [INFO] Download Started for NVD CVE - 2006 [INFO] Download Complete for NVD CVE - 2005 (2043 ms) [INFO] Download Started for NVD CVE - 2007 [INFO] Processing Started for NVD CVE - 2005 [INFO] Processing Complete for NVD CVE - 2003 (3473 ms) [INFO] Download Complete for NVD CVE - 2006 (2378 ms) [INFO] Download Started for NVD CVE - 2008 [INFO] Processing Started for NVD CVE - 2006 [INFO] Download Complete for NVD CVE - 2007 (2503 ms) [INFO] Download Started for NVD CVE - 2009 [INFO] Processing Started for NVD CVE - 2007 [INFO] Download Complete for NVD CVE - 2008 (2653 ms) [INFO] Download Started for NVD CVE - 2010 [INFO] Processing Started for NVD CVE - 2008 [INFO] Download Complete for NVD CVE - 2009 (2315 ms) [INFO] Download Started for NVD CVE - 2011 [INFO] Processing Started for NVD CVE - 2009 [INFO] Download Complete for NVD CVE - 2010 (2838 ms) [INFO] Download Started for NVD CVE - 2012 [INFO] Processing Started for NVD CVE - 2010 [INFO] Processing Complete for NVD CVE - 2004 (8680 ms) [INFO] Download Complete for NVD CVE - 2011 (4902 ms) [INFO] Download Started for NVD CVE - 2013 [INFO] Processing Started for NVD CVE - 2011 [INFO] Download Complete for NVD CVE - 2012 (3556 ms) [INFO] Download Started for NVD CVE - 2014 [INFO] Download Complete for NVD CVE - 2014 (2485 ms) [INFO] Download Started for NVD CVE - 2015 [INFO] Download Complete for NVD CVE - 2013 (3924 ms) [INFO] Download Started for NVD CVE - 2016 [INFO] Download Complete for NVD CVE - 2015 (2415 ms) [INFO] Download Started for NVD CVE - 2017 [INFO] Download Complete for NVD CVE - 2016 (2629 ms) [INFO] Download Started for NVD CVE - 2018 [INFO] Download Complete for NVD CVE - 2017 (4628 ms) [INFO] Download Started for NVD CVE - 2019 [INFO] Download Complete for NVD CVE - 2018 (6150 ms) [INFO] Download Complete for NVD CVE - 2019 (2855 ms) [INFO] Processing Complete for NVD CVE - 2005 (28925 ms) [INFO] Processing Started for NVD CVE - 2012 [INFO] Processing Complete for NVD CVE - 2002 (31827 ms) [INFO] Processing Started for NVD CVE - 2014 [INFO] Processing Complete for NVD CVE - 2009 (64650 ms) [INFO] Processing Started for NVD CVE - 2013 [INFO] Processing Complete for NVD CVE - 2007 (73684 ms) [INFO] Processing Started for NVD CVE - 2015 [INFO] Processing Complete for NVD CVE - 2010 (70105 ms) [INFO] Processing Started for NVD CVE - 2016 [INFO] Processing Complete for NVD CVE - 2006 (75705 ms) [INFO] Processing Started for NVD CVE - 2017 [INFO] Processing Complete for NVD CVE - 2011 (72071 ms) [INFO] Processing Started for NVD CVE - 2018 [INFO] Processing Complete for NVD CVE - 2008 (82790 ms) [INFO] Processing Started for NVD CVE - 2019 [INFO] Processing Complete for NVD CVE - 2012 (71014 ms) [INFO] Processing Complete for NVD CVE - 2013 (43451 ms) [INFO] Processing Complete for NVD CVE - 2014 (83339 ms) [INFO] Processing Complete for NVD CVE - 2019 (26732 ms) [INFO] Processing Complete for NVD CVE - 2015 (40873 ms) [INFO] Processing Complete for NVD CVE - 2016 (41670 ms) [INFO] Processing Complete for NVD CVE - 2017 (44982 ms) [INFO] Processing Complete for NVD CVE - 2018 (41352 ms) [INFO] Download Started for NVD CVE - Modified [INFO] Download Complete for NVD CVE - Modified (2673 ms) [INFO] Processing Started for NVD CVE - Modified [INFO] Processing Complete for NVD CVE - Modified (454 ms) [INFO] Begin database maintenance [INFO] End database maintenance (27730 ms) [INFO] Begin database defrag [INFO] End database defrag (37985 ms) [INFO] Check for updates complete (211543 ms) [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (2 seconds) [INFO] Finished CPE Analyzer (2 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished RetireJS Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (1 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (6 seconds) [WARNING] One or more dependencies were identified with known vulnerabilities in owasp-dependency-check-example: struts2-core-2.3.34.jar (pkg:maven/org.apache.struts/struts2-core@2.3.34, cpe:2.3:a:apache:struts:2.3.34:*:*:*:*:*:*:*) : CVE-2018-11776, CVE-2018-1327 commons-fileupload-1.3.2.jar (pkg:maven/commons-fileupload/commons-fileupload@1.3.2, cpe:2.3:a:apache:commons_fileupload:1.3.2:*:*:*:*:*:*:*) : CVE-2016-1000031 See the dependency-check report for more details. [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 03:54 min [INFO] Finished at: 2019-06-29T19:12:58+09:00 [INFO] ------------------------------------------------------------------------
2åç®ã
[INFO] --- dependency-check-maven:5.0.0:check (default-cli) @ owasp-dependency-check-example --- [INFO] Central analyzer disabled [INFO] Checking for updates [INFO] Skipping NVD check since last check was within 4 hours. [INFO] Skipping RetireJS update since last update was within 24 hours. [INFO] Check for updates complete (8 ms) [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (1 seconds) [INFO] Finished CPE Analyzer (2 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished RetireJS Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (0 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (3 seconds) [WARNING] One or more dependencies were identified with known vulnerabilities in owasp-dependency-check-example: struts2-core-2.3.34.jar (pkg:maven/org.apache.struts/struts2-core@2.3.34, cpe:2.3:a:apache:struts:2.3.34:*:*:*:*:*:*:*) : CVE-2018-11776, CVE-2018-1327 commons-fileupload-1.3.2.jar (pkg:maven/commons-fileupload/commons-fileupload@1.3.2, cpe:2.3:a:apache:commons_fileupload:1.3.2:*:*:*:*:*:*:*) : CVE-2016-1000031 See the dependency-check report for more details. [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 5.076 s [INFO] Finished at: 2019-06-29T21:21:42+09:00 [INFO] ------------------------------------------------------------------------