benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781
spdxMetadata
- Name
-
benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781
- Namespace
-
https://konflux-ci.dev/sbom/acme-corp/benefits-mgmt-app/9b416d7055d8de529f2255ff2b1db1ca22bc5781
- Data License
-
CC0-1.0
Creation
- Created
-
Aug 17, 2026
- Supplier
-
Acme Corp
- Author
-
Organization: Anchore, Inc, Tool: syft-1.42.1, Organization: Red Hat, Tool: Mobster-1.2.0
Statistics
- Size
-
0.71 MB
- Packages
-
156
- Labels
-
- type=spdx
Package
- Name
-
benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781
- Version
-
9b416d7055d8de529f2255ff2b1db1ca22bc5781
- External References
-
- pkg:oci/benefits-mgmt-app@sha256:2f4b8838eedd4ffb580f1766d20504f367ffe835b319910852dd55fb19bb6893?arch=amd64&repository_url=quay-j9x8s-1.apps.cluster-j9x8s.dyn.redhatworkshops.io/tsf/lightwell-releases/benefits-mgmt-app&tag=9b416d7055d8de529f2255ff2b1db1ca22bc5781
- pkg:oci/benefits-mgmt-app@sha256:2f4b8838eedd4ffb580f1766d20504f367ffe835b319910852dd55fb19bb6893?arch=amd64&repository_url=quay-j9x8s-1.apps.cluster-j9x8s.dyn.redhatworkshops.io/tsf/lightwell-releases/benefits-mgmt-app&tag=latest
Package list not available in this demo view.
10
Total vulnerabilities
High
2
Medium
7
Low
1
- Name
- benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781
- Version
- 9b416d7055d8de529f2255ff2b1db1ca22bc5781
- Creation date
- Aug 17, 2026
| Description | Affected dependencies | ||||
|---|---|---|---|---|---|
| CVE-2018-5968 | jackson-databind: unsafe deserialization due to incomplete blacklist (incomplete fix for CVE-2017-7525 and CVE-2017-17485) |
High (8.1) |
Jan 21, 2018 | Aug 05, 2024 | |
| CVE-2019-12900 | bzip2: Data integrity error when decompressing |
Medium (4.4) |
Jun 19, 2019 | Jun 09, 2025 | |
| CVE-2020-11023 | jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods |
Medium (6.1) |
Apr 28, 2020 | Oct 21, 2025 | |
| CVE-2022-29458 | ncurses: segfaulting OOB read |
Medium (6.1) |
Apr 17, 2022 | Jun 09, 2025 | |
| CVE-2022-49043 | libxml: use-after-free in xmlXIncludeAddNode |
Medium (5.9) |
Jan 25, 2025 | Nov 03, 2025 | |
| CVE-2024-0397 | cpython: Memory race condition in ssl.SSLContext certificate store methods |
Medium (5.0) |
Jun 17, 2024 | Nov 03, 2025 | |
| CVE-2024-5642 | python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used |
Low (2.7) |
Jun 27, 2024 | Jul 31, 2026 | |
| CVE-2024-7592 | cpython: Uncontrolled CPU resource consumption when in http.cookies module |
Medium (4.8) |
Aug 19, 2024 | Nov 03, 2025 | |
| CVE-2024-8176 | libexpat: Improper Restriction of XML Entity Expansion Depth in libexpat |
High (7.5) |
Mar 14, 2025 | Jun 29, 2026 | |
| CVE-2024-9287 | python: Virtual environment (venv) activation scripts don't quote paths |
Medium (6.3) |
Oct 22, 2024 | Nov 03, 2025 |
No models associated with this SBOM.