🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: eizen_agen_gateway_1
Branch: ldev
Build: #183
Date: 2026-03-13 11:19:22

2

Critical

21

High

22

Medium

0

Low

0

Secrets

0

Misconfig

🔴 Vulnerabilities (45)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2024-12798 ch.qos.logback:logback-core 1.5.6 1.5.13, 1.3.15 logback-core: arbitrary code execution via JaninoEventEvaluator
MEDIUM CVE-2025-11226 ch.qos.logback:logback-core 1.5.6 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core
HIGH GHSA-72hv-8253-57qq com.fasterxml.jackson.core:jackson-core 2.17.1 2.18.6, 2.21.1, 3.1.0 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
HIGH CVE-2025-48734 commons-beanutils:commons-beanutils 1.9.4 1.11.0 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declare
MEDIUM CVE-2025-58057 io.netty:netty-codec 4.1.111.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.111.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-55163 io.netty:netty-codec-http2 4.1.111.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
MEDIUM CVE-2024-47535 io.netty:netty-common 4.1.111.Final 4.1.115.Final netty: Denial of Service attack on windows app using Netty
MEDIUM CVE-2025-25193 io.netty:netty-common 4.1.111.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty
HIGH CVE-2025-24970 io.netty:netty-handler 4.1.111.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash
MEDIUM CVE-2025-22227 io.projectreactor.netty:reactor-netty-http 1.1.20 1.3.0-M5, 1.2.8 io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM CVE-2025-48924 org.apache.commons:commons-lang3 3.14.0 3.18.0 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in
MEDIUM CVE-2024-31141 org.apache.kafka:kafka-clients 3.7.0 3.7.1 kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider
MEDIUM CVE-2025-27817 org.apache.kafka:kafka-clients 3.7.0 3.9.1 org.apache.kafka: Kafka Client Arbitrary File Read SSRF
CRITICAL CVE-2025-66516 org.apache.tika:tika-core 2.9.1 3.2.2 tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika
CRITICAL CVE-2025-24813 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.3, 10.1.35, 9.0.99 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
HIGH CVE-2024-50379 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.2, 10.1.34, 9.0.98 tomcat: RCE due to TOCTOU issue in JSP compilation
HIGH CVE-2024-56337 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.2, 10.1.34, 9.0.98 tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation
HIGH CVE-2025-48988 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-52520 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.9, 10.1.43, 9.0.107 tomcat: Apache Tomcat denial of service
HIGH CVE-2025-53506 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 9.0.107, 10.1.43, 11.0.9 tomcat: Apache Tomcat denial of service
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
MEDIUM CVE-2025-31650 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
MEDIUM CVE-2025-49124 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability
MEDIUM CVE-2025-49125 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.25 11.0.15, 10.1.50, 9.0.113 tomcat: Client certificate verification bypass due to virtual host mapping
HIGH CVE-2023-6841 org.keycloak:keycloak-core 23.0.4 24.0.0 keycloak: Amount of attributes per object is not limited and it may lead to DOS
HIGH CVE-2024-10039 org.keycloak:keycloak-core 23.0.4 26.0.6 keycloak-core: mTLS passthrough
MEDIUM CVE-2024-7260 org.keycloak:keycloak-core 23.0.4 24.0.7 keycloak-core: Open Redirect on Account page
MEDIUM CVE-2024-7318 org.keycloak:keycloak-core 23.0.4 24.0.7, 25.0.4 keycloak-core: One Time Passcode (OTP) is valid longer than expiration timeSeverity
HIGH CVE-2025-12183 org.lz4:lz4-java 1.8.0 1.8.1 lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclo
HIGH CVE-2025-66566 org.lz4:lz4-java 1.8.0 No fix lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH CVE-2025-22235 org.springframework.boot:spring-boot 3.3.1 3.3.11, 3.4.5 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actu
MEDIUM CVE-2024-38820 org.springframework:spring-context 6.1.10 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
HIGH CVE-2025-41249 org.springframework:spring-core 6.1.10 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
MEDIUM CVE-2024-38809 org.springframework:spring-web 6.1.10 5.3.38, 6.0.23, 6.1.12 org.springframework:spring-web: Spring Framework DoS via conditional HTTP request
MEDIUM CVE-2024-38820 org.springframework:spring-web 6.1.10 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
MEDIUM CVE-2025-41234 org.springframework:spring-web 6.1.10 6.2.8, 6.1.21 springframework: Reflected download attack in Spring Framework with non-ASCII headers
HIGH CVE-2024-38816 org.springframework:spring-webflux 6.1.10 6.1.13 spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSys
HIGH CVE-2024-38819 org.springframework:spring-webflux 6.1.10 6.1.14 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks
HIGH CVE-2024-38816 org.springframework:spring-webmvc 6.1.10 6.1.13 spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSys
HIGH CVE-2024-38819 org.springframework:spring-webmvc 6.1.10 6.1.14 org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks
MEDIUM CVE-2025-41242 org.springframework:spring-webmvc 6.1.10 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability
MEDIUM CVE-2025-41254 org.springframework:spring-websocket 6.1.10 6.2.12 org.springframework/spring-core: Spring Framework STOMP CSRF Vulnerability
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (0)
SeverityIDCheckFileMessage
✅ No misconfigurations found
📄 Raw JSON Report (click to expand)