Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

DependencyTrack — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting DependencyTrack. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DependencyTrack is an open-source software composition analysis platform that identifies and tracks vulnerabilities in third-party dependencies. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation flaws. The platform currently has six CVEs on record, with notable security characteristics including its focus on SBOM generation and dependency mapping. While no major incidents have been widely documented, the CVEs highlight potential risks in its functionality, particularly around authentication and input validation. The tool remains valuable for organizations seeking to manage supply chain security despite these vulnerabilities, emphasizing the need for regular updates and careful configuration in production environments.

Top products by DependencyTrack: dependency-track frontend

This page lists every published CVE security advisory associated with DependencyTrack. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.