[midPoint-ci] Build failed in Jenkins: midPoint - master - security checks #70

Jenkins noreply at evolveum.com
Wed Nov 1 07:55:54 CET 2023


See <https://jenkins.evolveum.com/job/midpoint-master-security/70/display/redirect>

Changes:


------------------------------------------
[...truncated 84396 lines...]
[INFO] Download Started for NVD CVE - 2015
[INFO] Download Complete for NVD CVE - 2015  (1269 ms)
[INFO] Processing Started for NVD CVE - 2015
[INFO] Processing Complete for NVD CVE - 2014  (7041 ms)
[INFO] Download Started for NVD CVE - 2016
[INFO] Download Complete for NVD CVE - 2016  (1341 ms)
[INFO] Processing Started for NVD CVE - 2016
[INFO] Processing Complete for NVD CVE - 2015  (5656 ms)
[INFO] Download Started for NVD CVE - 2017
[INFO] Download Complete for NVD CVE - 2017  (1561 ms)
[INFO] Processing Started for NVD CVE - 2017
[INFO] Processing Complete for NVD CVE - 2016  (5911 ms)
[INFO] Download Started for NVD CVE - 2018
[INFO] Download Complete for NVD CVE - 2018  (1658 ms)
[INFO] Processing Started for NVD CVE - 2018
[INFO] Processing Complete for NVD CVE - 2017  (7284 ms)
[INFO] Download Started for NVD CVE - 2019
[INFO] Download Complete for NVD CVE - 2019  (1848 ms)
[INFO] Processing Started for NVD CVE - 2019
[INFO] Processing Complete for NVD CVE - 2018  (7272 ms)
[INFO] Download Started for NVD CVE - 2020
[INFO] Download Complete for NVD CVE - 2020  (1880 ms)
[INFO] Processing Started for NVD CVE - 2020
[INFO] Processing Complete for NVD CVE - 2019  (7025 ms)
[INFO] Download Started for NVD CVE - 2021
[INFO] Download Complete for NVD CVE - 2021  (2057 ms)
[INFO] Processing Started for NVD CVE - 2021
[INFO] Processing Complete for NVD CVE - 2020  (9019 ms)
[INFO] Download Started for NVD CVE - 2022
[INFO] Download Complete for NVD CVE - 2022  (1959 ms)
[INFO] Processing Started for NVD CVE - 2022
[INFO] Processing Complete for NVD CVE - 2021  (9913 ms)
[INFO] Download Started for NVD CVE - 2023
[INFO] Download Complete for NVD CVE - 2023  (1662 ms)
[INFO] Processing Started for NVD CVE - 2023
[INFO] Processing Complete for NVD CVE - 2022  (11136 ms)
[INFO] Processing Complete for NVD CVE - 2023  (7587 ms)
[INFO] Download Started for NVD CVE - Modified
[INFO] Download Complete for NVD CVE - Modified  (849 ms)
[INFO] Processing Started for NVD CVE - Modified
[INFO] Processing Complete for NVD CVE - Modified  (1768 ms)
[INFO] Begin database maintenance
[INFO] Updated the CPE ecosystem on 136584 NVD records
[INFO] Removed the CPE ecosystem on 3935 NVD records
[INFO] Cleaned up 1 orphaned NVD records
[INFO] End database maintenance (14768 ms)
[WARNING] A new version of dependency-check is available. Consider updating to version 8.4.2.
[INFO] Updating CISA Known Exploited Vulnerability list: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
[INFO] Begin database defrag
[INFO] End database defrag (3751 ms)
[INFO] Check for updates complete (152073 ms)
[INFO] 

Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.


   About ODC: https://jeremylong.github.io/DependencyCheck/general/internals.html
   False Positives: https://jeremylong.github.io/DependencyCheck/general/suppression.html

💖 Sponsor: https://github.com/sponsors/jeremylong


[INFO] Analysis Started
[INFO] Finished Archive Analyzer (1 seconds)
[INFO] Finished File Name Analyzer (0 seconds)
[INFO] Finished Jar Analyzer (1 seconds)
[WARNING] Analyzing `/home/jenkins/agent/workspace/midpoint-master-security/gui/admin-gui/package-lock.json` - however, the node_modules directory does not exist. Please run `npm install` prior to running dependency-check
[WARNING] No lock file exists - this will result in false negatives; please run `npm install --package-lock`
[WARNING] Analyzing `/tmp/dctemp0c1747a0-5956-4634-a17f-8b263cb25a69/check11491897589607784242tmp/302/META-INF/resources/webjars/chartjs/4.1.2/auto/package.json` - however, the node_modules directory does not exist. Please run `npm install` prior to running dependency-check
[WARNING] No lock file exists - this will result in false negatives; please run `npm install --package-lock`
[WARNING] Analyzing `/tmp/dctemp0c1747a0-5956-4634-a17f-8b263cb25a69/check11491897589607784242tmp/302/META-INF/resources/webjars/chartjs/4.1.2/package.json` - however, the node_modules directory does not exist. Please run `npm install` prior to running dependency-check
[WARNING] No lock file exists - this will result in false negatives; please run `npm install --package-lock`
[WARNING] Analyzing `/tmp/dctemp0c1747a0-5956-4634-a17f-8b263cb25a69/check11491897589607784242tmp/302/META-INF/resources/webjars/chartjs/4.1.2/helpers/package.json` - however, the node_modules directory does not exist. Please run `npm install` prior to running dependency-check
[INFO] Finished Node.js Package Analyzer (0 seconds)
[INFO] Finished Dependency Merging Analyzer (0 seconds)
[INFO] Finished Version Filter Analyzer (0 seconds)
[INFO] Finished Hint Analyzer (0 seconds)
[INFO] Created CPE Index (2 seconds)
[INFO] Finished CPE Analyzer (5 seconds)
[INFO] Finished False Positive Analyzer (0 seconds)
[INFO] Finished NVD CVE Analyzer (0 seconds)
[WARNING] Unsupported CVSS vector format in NPM Audit results, please file a feature request at https://github.com/jeremylong/DependencyCheck/issues/new/choose to support vector format 'null' 
[INFO] Finished Node Audit Analyzer (0 seconds)
[ERROR] Exception occurred initializing RetireJS Analyzer.
[INFO] Finished Sonatype OSS Index Analyzer (3 seconds)
[INFO] Finished Vulnerability Suppression Analyzer (0 seconds)
[INFO] Finished Known Exploited Vulnerability Analyzer (0 seconds)
[INFO] Finished Dependency Bundling Analyzer (0 seconds)
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2021-23334,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-46161,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-34034,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-31692,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-23913,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-0217,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-0401,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-0464,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-0216,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-3996,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-4450,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-0286,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-24729,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-42004,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-42003,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-31129,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-24785,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-41881,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-3171,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-3509,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-3510,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-26520,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2023-20860,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2017-15719,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2018-1325,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-28391,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2022-30065,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2016-10735,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2018-20676,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2019-8331,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2018-20677,}}
[INFO] Suppression Rule had zero matches: SuppressionRule{cve={CVE-2020-11023,}}
[INFO] Finished Unused Suppression Rule Analyzer (0 seconds)
[INFO] Analysis Complete (15 seconds)
[INFO] Writing report to: /home/jenkins/agent/workspace/midpoint-master-security/target/dependency-check-report.xml
[INFO] Writing report to: /home/jenkins/agent/workspace/midpoint-master-security/target/dependency-check-report.html
[INFO] Writing report to: /home/jenkins/agent/workspace/midpoint-master-security/target/dependency-check-report.json
[INFO] Writing report to: /home/jenkins/agent/workspace/midpoint-master-security/target/dependency-check-jenkins.html
[WARNING] 

One or more dependencies were identified with known vulnerabilities in midPoint Project:

amqp-client-5.16.1.jar (pkg:maven/com.rabbitmq/amqp-client at 5.16.1, cpe:2.3:a:vmware:rabbitmq:5.16.1:*:*:*:*:*:*:*) : CVE-2023-46120
bcprov-jdk15on-1.70.jar (pkg:maven/org.bouncycastle/bcprov-jdk15on at 1.70, cpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.70:*:*:*:*:*:*:*) : CVE-2023-33201
connector-ldap-3.7.jar: mina-core-2.2.2.jar (pkg:maven/org.apache.mina/mina-core at 2.2.2, cpe:2.3:a:apache:mina:2.2.2:*:*:*:*:*:*:*) : CVE-2023-35887
package-lock.json?crypto-js (pkg:npm/crypto-js at 4.1.1) : GHSA-xwcq-pm8m-c4vf
jakarta.mail-1.0.0.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml (pkg:maven/org.eclipse.angus/angus-core at 1.0.0) : CVE-2021-44549
jakarta.mail-1.0.0.jar/META-INF/maven/org.eclipse.angus/angus-mail/pom.xml (pkg:maven/org.eclipse.angus/angus-mail at 1.0.0) : CVE-2021-44549
netty-transport-4.1.97.Final.jar (pkg:maven/io.netty/netty-transport at 4.1.97.Final, cpe:2.3:a:netty:netty:4.1.97:*:*:*:*:*:*:*) : CVE-2023-4586
nimbus-jose-jwt-9.15.2.jar/META-INF/maven/net.minidev/json-smart/pom.xml (pkg:maven/net.minidev/json-smart at 2.4.7, cpe:2.3:a:json-smart_project:json-smart:2.4.7:*:*:*:*:*:*:*, cpe:2.3:a:json-smart_project:json-smart-v2:2.4.7:*:*:*:*:*:*:*) : CVE-2023-1370
okio-jvm-3.0.0.jar (pkg:maven/com.squareup.okio/okio-jvm at 3.0.0, cpe:2.3:a:squareup:okio:3.0.0:*:*:*:*:*:*:*) : CVE-2023-3635
package-lock.json?postcss (pkg:npm/postcss at 8.4.19) : CVE-2023-44270, GHSA-7fh5-64p2-3v2j
package-lock.json?semver (pkg:npm/semver at 5.7.1) : CVE-2022-25883, GHSA-c2qf-rxjj-qqgw
package-lock.json?semver (pkg:npm/semver at 6.3.0) : CVE-2022-25883, GHSA-c2qf-rxjj-qqgw
package-lock.json?semver (pkg:npm/semver at 7.3.8) : CVE-2022-25883, GHSA-c2qf-rxjj-qqgw
spring-amqp-3.0.8.jar (pkg:maven/org.springframework.amqp/spring-amqp at 3.0.8, cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:3.0.8:*:*:*:*:*:*:*, cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:3.0.8:*:*:*:*:*:*:*) : CVE-2023-34050
spring-security-config-6.0.6.jar (pkg:maven/org.springframework.security/spring-security-config at 6.0.6, cpe:2.3:a:pivotal_software:spring_security:6.0.6:*:*:*:*:*:*:*, cpe:2.3:a:vmware:spring_security:6.0.6:*:*:*:*:*:*:*) : CVE-2023-34042
package-lock.json?sweetalert2 (pkg:npm/sweetalert2 at 11.4.13) : GHSA-qq6h-5g6j-q3cm
tomcat-embed-core-10.1.12.jar (pkg:maven/org.apache.tomcat.embed/tomcat-embed-core at 10.1.12, cpe:2.3:a:apache:tomcat:10.1.12:*:*:*:*:*:*:*, cpe:2.3:a:apache_tomcat:apache_tomcat:10.1.12:*:*:*:*:*:*:*) : CVE-2023-41080, CVE-2023-42795, CVE-2023-45648
wicket-datetime-8.0.0-M7.jar (pkg:maven/org.apache.wicket/wicket-datetime at 8.0.0-M7, cpe:2.3:a:apache:wicket:8.0.0:m7:*:*:*:*:*:*) : CVE-2020-11976
package-lock.json?word-wrap (pkg:npm/word-wrap at 1.2.3) : CVE-2023-26115, GHSA-j8xg-fqg3-53r7
xercesImpl-2.12.2.jar (pkg:maven/xerces/xercesImpl at 2.12.2, cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*, cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*) : CVE-2017-10355
xmlsec-2.2.4.jar (pkg:maven/org.apache.santuario/xmlsec at 2.2.4, cpe:2.3:a:apache:santuario_xml_security_for_java:2.2.4:*:*:*:*:*:*:*, cpe:2.3:a:apache:xml_security_for_java:2.2.4:*:*:*:*:*:*:*) : CVE-2023-44483


See the dependency-check report for more details.


[INFO] ------------------------------------------------------------------------
[INFO] Reactor Summary for midPoint Project 4.9-SNAPSHOT:
[INFO] 
[INFO] midPoint Project ................................... FAILURE [04:21 min]
[INFO] midPoint Infrastructure ............................ SKIPPED
[INFO] midPoint Infrastructure - schema ................... SKIPPED
[INFO] midPoint Repository ................................ SKIPPED
[INFO] midPoint Repository - api .......................... SKIPPED
[INFO] midPoint Task Manager - api ........................ SKIPPED
[INFO] midPoint Infrastructure - testing utils (lvl 2) .... SKIPPED
[INFO] midPoint Infrastructure - common ................... SKIPPED
[INFO] midPoint Audit - api ............................... SKIPPED
[INFO] midPoint Security - api ............................ SKIPPED
[INFO] midPoint Repository - SQL common support ........... SKIPPED
[INFO] midPoint Repository - sql repository ............... SKIPPED
[INFO] midPoint System Initialization ..................... SKIPPED
[INFO] midPoint Repository - new SQL repository ........... SKIPPED
[INFO] midPoint Repository - sql repository test .......... SKIPPED
[INFO] midPoint Repository Cache .......................... SKIPPED
[INFO] midPoint Audit - logging impl ...................... SKIPPED
[INFO] midPoint Icf Connectors ............................ SKIPPED
[INFO] Dummy Resource ..................................... SKIPPED
[INFO] midPoint Repository - test utils ................... SKIPPED
[INFO] midPoint Security - impl ........................... SKIPPED
[INFO] midPoint Task Manager - Quartz impl ................ SKIPPED
[INFO] midPoint Tools ..................................... SKIPPED
[INFO] midPoint Tools - Ninja ............................. SKIPPED
[INFO] midPoint Tools - custom Spring Boot JAR layout ..... SKIPPED
[INFO] midPoint Infrastructure - pure JAXB schema ......... SKIPPED
[INFO] midPoint Repo Commons .............................. SKIPPED
[INFO] midPoint Security Enforcer - api ................... SKIPPED
[INFO] midPoint Security Enforcer - impl .................. SKIPPED
[INFO] midPoint Provisioning .............................. SKIPPED
[INFO] midPoint Provisioning - api ........................ SKIPPED
[INFO] Unified Connector Framework - api .................. SKIPPED
[INFO] Dummy Connector .................................... SKIPPED
[INFO] Unified Connector Framework - ConnId impl .......... SKIPPED
[INFO] Unified Connector Framework - Built-in impl ........ SKIPPED
[INFO] midPoint Provisioning - impl ....................... SKIPPED
[INFO] midPoint Model ..................................... SKIPPED
[INFO] midPoint Model - api ............................... SKIPPED
[INFO] midPoint Model - common ............................ SKIPPED
[INFO] midPoint Notifications - api ....................... SKIPPED
[INFO] Dummy Connector Fake ............................... SKIPPED
[INFO] midPoint Authentication - api ...................... SKIPPED
[INFO] midPoint Model - test .............................. SKIPPED
[INFO] midPoint Report - api .............................. SKIPPED
[INFO] midPoint Cases - api ............................... SKIPPED
[INFO] midPoint Access Certification - api ................ SKIPPED
[INFO] midPoint Model - impl .............................. SKIPPED
[INFO] midPoint Notifications - impl ...................... SKIPPED
[INFO] midPoint Report - impl ............................. SKIPPED
[INFO] midPoint Model - integration tests ................. SKIPPED
[INFO] midPoint Workflow - api ............................ SKIPPED
[INFO] midPoint Cases - impl .............................. SKIPPED
[INFO] midPoint Workflow - impl ........................... SKIPPED
[INFO] midPoint Access Certification - impl ............... SKIPPED
[INFO] midPoint Authentication - impl ..................... SKIPPED
[INFO] midPoint REST-ish service implementation ........... SKIPPED
[INFO] midPoint Customizations ............................ SKIPPED
[INFO] midPoint User Interface ............................ SKIPPED
[INFO] midPoint User Interface - admin web gui ............ SKIPPED
[INFO] midPoint Spring Boot JAR ........................... SKIPPED
[INFO] midPoint Testing Infrastructure .................... SKIPPED
[INFO] midPoint Testing - Resource Connection Tests ....... SKIPPED
[INFO] midPoint Testing - Long Tests ...................... SKIPPED
[INFO] midPoint Testing - Story Tests ..................... SKIPPED
[INFO] midPoint Testing - REST API ........................ SKIPPED
[INFO] midPoint Distribution .............................. SKIPPED
[INFO] midPoint API Distribution .......................... SKIPPED
[INFO] midPoint JavaDoc ................................... SKIPPED
[INFO] ------------------------------------------------------------------------
[INFO] BUILD FAILURE
[INFO] ------------------------------------------------------------------------
[INFO] Total time:  04:24 min
[INFO] Finished at: 2023-11-01T06:55:54Z
[INFO] ------------------------------------------------------------------------
[ERROR] Failed to execute goal org.owasp:dependency-check-maven:8.2.1:aggregate (default-cli) on project midpoint: One or more exceptions occurred during dependency-check analysis: One or more exceptions occurred during analysis:
[ERROR] 	InitializationException: Failed to initialize the RetireJS repo: `/tmp/dctemp0c1747a0-5956-4634-a17f-8b263cb25a69/jsrepository.json` appears to be malformed. Please delete the file or run the dependency-check purge command and re-try running dependency-check.
[ERROR] 		caused by JSONException: No value for info
[ERROR] -> [Help 1]
[ERROR] 
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR] 
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException
[Pipeline] }
[Pipeline] // container
[Pipeline] }
[Pipeline] // stage
[Pipeline] error
[Pipeline] step


More information about the midPoint-ci mailing list