The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master
branch but not yet published.
Affected versions of this package are vulnerable to Unsafe Dependency Resolution such that the usage of long IDs for PGP keys is unsafe and is subject to collision attacks.
Note: Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a trusted-key
or pgp
element in their dependency verification metadata file.
Users who are unable to upgrade should use only full fingerprint IDs for trusted-key
or pgp
element in the metadata is a protection against this issue.