🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen-dms-service
Branch: ldev
Build: #230
Date: 2026-04-13 12:24:05

4

Critical

22

High

23

Medium

0

Low

0

Secrets

3

Misconfig

🔴 Vulnerabilities (46)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2024-12798 ch.qos.logback:logback-core 1.5.7 1.5.13, 1.3.15 logback-core: arbitrary code execution via JaninoEventEvaluator
MEDIUM CVE-2025-11226 ch.qos.logback:logback-core 1.5.7 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
MEDIUM CVE-2022-30187 com.azure:azure-storage-blob 12.10.0 12.18.0 Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
MEDIUM GHSA-72hv-8253-57qq com.fasterxml.jackson.core:jackson-core 2.17.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM CVE-2025-58057 io.netty:netty-codec 4.1.112.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style
HIGH CVE-2026-33870 io.netty:netty-codec-http 4.1.112.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transf
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.112.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-55163 io.netty:netty-codec-http2 4.1.112.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH CVE-2026-33871 io.netty:netty-codec-http2 4.1.112.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
MEDIUM CVE-2024-47535 io.netty:netty-common 4.1.112.Final 4.1.115.Final netty: Denial of Service attack on windows app using Netty
MEDIUM CVE-2025-25193 io.netty:netty-common 4.1.112.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty
HIGH CVE-2025-24970 io.netty:netty-handler 4.1.112.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash
MEDIUM CVE-2025-22227 io.projectreactor.netty:reactor-netty-http 1.1.22 1.3.0-M5, 1.2.8 io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
CRITICAL CVE-2025-24813 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.3, 10.1.35, 9.0.99 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CRITICAL CVE-2026-29145 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.116, 10.1.53, 11.0.20 CLIENT_CERT authentication does not fail as expected for some scenario ...
HIGH CVE-2024-50379 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.2, 10.1.34, 9.0.98 tomcat: RCE due to TOCTOU issue in JSP compilation
HIGH CVE-2024-56337 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.2, 10.1.34, 9.0.98 tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation
HIGH CVE-2025-48988 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-52520 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.9, 10.1.43, 9.0.107 tomcat: Apache Tomcat denial of service
HIGH CVE-2025-53506 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.107, 10.1.43, 11.0.9 tomcat: Apache Tomcat denial of service
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
HIGH CVE-2026-24734 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.18, 10.1.52, 9.0.115 tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation
HIGH CVE-2026-24880 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.116, 10.1.52, 11.0.20 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...
HIGH CVE-2026-34483 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.116, 10.1.54, 11.0.21 Improper Encoding or Escaping of Output vulnerability in the JsonAcces ...
HIGH CVE-2026-34487 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.117, 10.1.54, 11.0.21 Insertion of Sensitive Information into Log File vulnerability in the ...
MEDIUM CVE-2024-52317 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.96, 10.1.31, 11.0.0 tomcat: Apache Tomcat: Request/response mix-up with HTTP/2
MEDIUM CVE-2025-31650 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
MEDIUM CVE-2025-49124 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability
MEDIUM CVE-2025-49125 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 11.0.15, 10.1.50, 9.0.113 tomcat: Client certificate verification bypass due to virtual host mapping
MEDIUM CVE-2026-25854 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.116, 10.1.53, 11.0.20 Occasional URL redirection to untrusted Site ('Open Redirect') vulnera ...
MEDIUM CVE-2026-34500 org.apache.tomcat.embed:tomcat-embed-core 10.1.28 9.0.117, 10.1.54, 11.0.21 CLIENT_CERT authentication does not fail as expected for some scenario ...
HIGH CVE-2025-22235 org.springframework.boot:spring-boot 3.3.3 3.3.11, 3.4.5 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actu
MEDIUM CVE-2024-38827 org.springframework.security:spring-security-core 6.3.3 5.7.14, 5.8.16, 6.0.14, 6.1.12, 6.2.8, 6.3.5 spring-security: authorization bypass for case sensitive comparisons
HIGH CVE-2025-22228 org.springframework.security:spring-security-crypto 6.3.3 6.3.8, 6.4.4, 6.2.10, 6.1.14, 6.0.16, 5.8.18, 5.7.16 spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length
CRITICAL CVE-2024-38821 org.springframework.security:spring-security-web 6.3.3 5.7.13, 5.8.15, 6.2.7, 6.0.13, 6.1.11, 6.3.4 Spring-WebFlux: Authorization Bypass of Static Resources in WebFlux Applications
CRITICAL CVE-2026-22732 org.springframework.security:spring-security-web 6.3.3 6.5.9, 7.0.4 Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten
MEDIUM CVE-2024-38820 org.springframework:spring-context 6.1.12 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
HIGH CVE-2025-41249 org.springframework:spring-core 6.1.12 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
MEDIUM CVE-2024-38820 org.springframework:spring-web 6.1.12 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
MEDIUM CVE-2025-41234 org.springframework:spring-web 6.1.12 6.2.8, 6.1.21 springframework: Reflected download attack in Spring Framework with non-ASCII headers
HIGH CVE-2024-38816 org.springframework:spring-webmvc 6.1.12 6.1.13 spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSys
HIGH CVE-2024-38819 org.springframework:spring-webmvc 6.1.12 6.1.14 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks
MEDIUM CVE-2025-41242 org.springframework:spring-webmvc 6.1.12 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability
MEDIUM CVE-2026-22737 org.springframework:spring-webmvc 6.1.12 7.0.6, 6.2.17 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled templat
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (3)
SeverityIDCheckFileMessage
HIGH DS002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
MEDIUM DS001 ':latest' tag used nginx/Dockerfile Specify a tag in the 'FROM' statement for image 'nginx'
HIGH DS002 Image user should not be 'root' nginx/Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)