Update Azure BlobServiceClient to use workloadIdentity #12469
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-52428Path to dependency file: /test/fixtures/hdfs-fixture/build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.nimbusds/nimbus-jose-jwt/9.8.1/2af7f734313320e4b156522d22ce32b775633909/nimbus-jose-jwt-9.8.1.jar Dependency Hierarchy: -> hadoop-minicluster-3.3.6.jar (Root Library) -> hadoop-common-3.3.6.jar -> hadoop-auth-3.3.6.jar -> ❌ nimbus-jose-jwt-9.8.1.jar (Vulnerable Library) |
High | 7.5 | nimbus-jose-jwt-9.8.1.jar | Upgrade to version: com.nimbusds:nimbus-jose-jwt:9.37.2 | None |
CVE-2021-27568Path to dependency file: /plugins/repository-azure/build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/net.minidev/json-smart/1.0.6.3/1cee1ee494742154cff38e525c54d89cb15e1c8/json-smart-1.0.6.3.jar Dependency Hierarchy: -> ❌ json-smart-1.0.6.3.jar (Vulnerable Library) |
Medium | 5.9 | json-smart-1.0.6.3.jar | Upgrade to version: net.minidev:json-smart-mini:1.3.2;net.minidev:json-smart:1.3.2,2.3.1,2.4.2;net.minidev:json-smart-action:2.3.1,2.4.2 | None |
CVE-2024-35255Path to dependency file: /plugins/repository-azure/build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.azure/azure-identity/1.11.2/31a85e3a591a2513736bf5cf787eeab9cd542590/azure-identity-1.11.2.jar Dependency Hierarchy: -> ❌ azure-identity-1.11.2.jar (Vulnerable Library) |
Medium | 5.5 | azure-identity-1.11.2.jar | Upgrade to version: @azure/identity (npm) - 4.2.1, @azure/msal-node (npm) - 2.9.1, Azure.Identity (NuGet) - 1.11.4, Microsoft.Identity.Client (NuGet) - 4.61.3, azure-identity (pip) - 1.16.1, com.azure:azure-identity:1.12.2 (Maven), github.com/Azure/azure-sdk-for-go/sdk/azidentity (go) - 1.6.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-52428 | nimbus-jose-jwt-9.31.jar |
Base branch total remaining vulnerabilities: 5
Base branch commit: 5c8623f15f1fbec40328f05f53814404e3438ff7
Total libraries scanned: 613
Scan token: 554005faaeb84a43af5b849102276834