Exception during dependency check

916 views
Skip to first unread message

Kiran Hariyapuraju

unread,
May 10, 2021, 12:59:59 AM5/10/21
to Jeremy Long, Dependency Check
Hi Team,

Getting below exception when running dependency check using maven.

org.owasp.dependencycheck.exception.ExceptionCollection: One or more exceptions occurred during analysis:
        The execution of the download was interrupted
        No documents exist
        at org.owasp.dependencycheck.Engine.throwFatalExceptionCollection(Engine.java:1178)
        at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:673)
        at org.owasp.dependencycheck.taskdefs.Check.callExecuteAnalysis(Check.java:1685)
        at org.owasp.dependencycheck.taskdefs.Check.execute(Check.java:1642)
        at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:292)
        at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:99)
        at org.apache.tools.ant.Task.perform(Task.java:350)
        at org.apache.tools.ant.Target.execute(Target.java:449)
        at org.apache.tools.ant.Target.performTasks(Target.java:470)
        at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1391)
        at org.apache.tools.ant.Project.executeTarget(Project.java:1364)
        at org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41)
        at org.apache.tools.ant.Project.executeTargets(Project.java:1254)
        at org.apache.tools.ant.Main.runBuild(Main.java:830)
        at org.apache.tools.ant.Main.startAnt(Main.java:223)
        at org.apache.tools.ant.launch.Launcher.run(Launcher.java:284)
        at org.apache.tools.ant.launch.Launcher.main(Launcher.java:101)
Next Exception:
org.owasp.dependencycheck.data.update.exception.UpdateException: The execution of the download was interrupted
        at org.owasp.dependencycheck.data.update.NvdCveUpdater.performUpdate(NvdCveUpdater.java:317)
        at org.owasp.dependencycheck.data.update.NvdCveUpdater.update(NvdCveUpdater.java:125)
        at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:936)
        at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase(Engine.java:737)
        at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:667)
        at org.owasp.dependencycheck.taskdefs.Check.callExecuteAnalysis(Check.java:1685)
        at org.owasp.dependencycheck.taskdefs.Check.execute(Check.java:1642)
        at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:292)
        at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:99)
        at org.apache.tools.ant.Task.perform(Task.java:350)
        at org.apache.tools.ant.Target.execute(Target.java:449)
        at org.apache.tools.ant.Target.performTasks(Target.java:470)
        at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1391)
        at org.apache.tools.ant.Project.executeTarget(Project.java:1364)
        at org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41)
        at org.apache.tools.ant.Project.executeTargets(Project.java:1254)
        at org.apache.tools.ant.Main.runBuild(Main.java:830)
        at org.apache.tools.ant.Main.startAnt(Main.java:223)
        at org.apache.tools.ant.launch.Launcher.run(Launcher.java:284)
        at org.apache.tools.ant.launch.Launcher.main(Launcher.java:101)
Caused by: java.util.concurrent.ExecutionException: java.lang.NullPointerException
        at java.util.concurrent.FutureTask.report(FutureTask.java:122)
        at java.util.concurrent.FutureTask.get(FutureTask.java:192)
        at org.owasp.dependencycheck.data.update.NvdCveUpdater.performUpdate(NvdCveUpdater.java:307)
        ... 22 more
Caused by: java.lang.NullPointerException
        at org.owasp.dependencycheck.data.update.nvd.NvdCveParser.lambda$testCveCpeStartWithFilter$0(NvdCveParser.java:125)
        at java.util.stream.MatchOps$1MatchSink.accept(MatchOps.java:90)
        at java.util.ArrayList$ArrayListSpliterator.tryAdvance(ArrayList.java:1351)
        at java.util.stream.ReferencePipeline.forEachWithCancel(ReferencePipeline.java:126)
        at java.util.stream.AbstractPipeline.copyIntoWithCancel(AbstractPipeline.java:498)
        at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:485)
        at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:471)
        at java.util.stream.MatchOps$MatchOp.evaluateSequential(MatchOps.java:230)
        at java.util.stream.MatchOps$MatchOp.evaluateSequential(MatchOps.java:196)
        at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234)
        at java.util.stream.ReferencePipeline.anyMatch(ReferencePipeline.java:449)
        at org.owasp.dependencycheck.data.update.nvd.NvdCveParser.testCveCpeStartWithFilter(NvdCveParser.java:125)
        at org.owasp.dependencycheck.data.update.nvd.NvdCveParser.parse(NvdCveParser.java:98)
        at org.owasp.dependencycheck.data.update.nvd.ProcessTask.importJSON(ProcessTask.java:139)
        at org.owasp.dependencycheck.data.update.nvd.ProcessTask.processFiles(ProcessTask.java:152)
        at org.owasp.dependencycheck.data.update.nvd.ProcessTask.call(ProcessTask.java:113)
        at org.owasp.dependencycheck.data.update.nvd.ProcessTask.call(ProcessTask.java:40)
        at java.util.concurrent.FutureTask.run(FutureTask.java:266)
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
        at java.lang.Thread.run(Thread.java:745)
Next Exception:
org.owasp.dependencycheck.exception.NoDataException: No documents exist
        at org.owasp.dependencycheck.Engine.ensureDataExists(Engine.java:1160)
        at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:671)
        at org.owasp.dependencycheck.taskdefs.Check.callExecuteAnalysis(Check.java:1685)
        at org.owasp.dependencycheck.taskdefs.Check.execute(Check.java:1642)
        at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:292)
        at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:99)
        at org.apache.tools.ant.Task.perform(Task.java:350)
        at org.apache.tools.ant.Target.execute(Target.java:449)
        at org.apache.tools.ant.Target.performTasks(Target.java:470)
        at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1391)
        at org.apache.tools.ant.Project.executeTarget(Project.java:1364)
        at org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41)
        at org.apache.tools.ant.Project.executeTargets(Project.java:1254)
        at org.apache.tools.ant.Main.runBuild(Main.java:830)
        at org.apache.tools.ant.Main.startAnt(Main.java:223)
        at org.apache.tools.ant.launch.Launcher.run(Launcher.java:284)
        at org.apache.tools.ant.launch.Launcher.main(Launcher.java:101)


Thanks,
Kiran

Kiran Hariyapuraju

unread,
May 10, 2021, 4:07:37 AM5/10/21
to Jeremy Long, Dependency Check
Adding complete log details.

[dependency-check] SLF4J: Class path contains multiple SLF4J bindings.
[dependency-check] SLF4J: Found binding in [jar:file:/C:/jrs/jasperserver/target/dependency-check/dependency-check-ant/dependency-check-ant.jar!/org/slf4j/impl/StaticLoggerBinder.class]
[dependency-check] SLF4J: Found binding in [jar:file:/C:/jrs/jasperserver/target/dependency-check/dependency-check-ant/lib/dependency-check-ant-5.3.2.jar!/org/slf4j/impl/StaticLoggerBinder.class]
[dependency-check] SLF4J: See http://www.slf4j.org/codes.html#multiple_bindings for an explanation.
[dependency-check] SLF4J: Actual binding is of type [org.owasp.dependencycheck.ant.logging.AntLoggerFactory]
[dependency-check] Checking for updates
[dependency-check] NVD CVE requires several updates; this could take a couple of minutes.
[dependency-check] Download Started for NVD CVE - 2016
[dependency-check] Download Started for NVD CVE - 2019
[dependency-check] Download Complete for NVD CVE - 2016  (2847 ms)
[dependency-check] Download Started for NVD CVE - 2021
[dependency-check] Processing Started for NVD CVE - 2016
[dependency-check] Download Complete for NVD CVE - 2019  (3269 ms)
[dependency-check] Processing Started for NVD CVE - 2019
[dependency-check] Download Complete for NVD CVE - 2021  (2652 ms)
[dependency-check] Processing Started for NVD CVE - 2021
[dependency-check] java.util.concurrent.ExecutionException: java.lang.NullPointerException
[dependency-check] Skipping RetireJS update since last update was within 24 hours.
[dependency-check] Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
[dependency-check] Unable to continue dependency-check analysis.

BUILD FAILED
C:\jrs\jasperserver\buildomatic\bin\dev.xml:1408: One or more exceptions occurred during analysis:

org.owasp.dependencycheck.exception.ExceptionCollection: One or more exceptions occurred during analysis:
        java.util.concurrent.ExecutionException: java.lang.NullPointerException

        No documents exist
        at org.owasp.dependencycheck.Engine.throwFatalExceptionCollection(Engine.java:1178)
        at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:673)
        at org.owasp.dependencycheck.taskdefs.Check.callExecuteAnalysis(Check.java:1685)
        at org.owasp.dependencycheck.taskdefs.Check.execute(Check.java:1642)
        at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:292)
        at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:99)
        at org.apache.tools.ant.Task.perform(Task.java:350)
        at org.apache.tools.ant.Target.execute(Target.java:449)
        at org.apache.tools.ant.Target.performTasks(Target.java:470)
        at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1391)
        at org.apache.tools.ant.Project.executeTarget(Project.java:1364)
        at org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41)
        at org.apache.tools.ant.Project.executeTargets(Project.java:1254)
        at org.apache.tools.ant.Main.runBuild(Main.java:830)
        at org.apache.tools.ant.Main.startAnt(Main.java:223)
        at org.apache.tools.ant.launch.Launcher.run(Launcher.java:284)
        at org.apache.tools.ant.launch.Launcher.main(Launcher.java:101)
Next Exception:
org.owasp.dependencycheck.data.update.exception.UpdateException: java.util.concurrent.ExecutionException: java.lang.NullPointerException
        at org.owasp.dependencycheck.data.update.NvdCveUpdater.performUpdate(NvdCveUpdater.java:298)
        at org.owasp.dependencycheck.data.update.NvdCveUpdater.performUpdate(NvdCveUpdater.java:288)

        ... 22 more
Caused by: java.lang.NullPointerException
        at org.owasp.dependencycheck.data.nvdcve.CveDB.lambda$parseCpes$1(CveDB.java:1289)
        at java.util.stream.ReferencePipeline$2$1.accept(ReferencePipeline.java:174)
        at java.util.ArrayList$ArrayListSpliterator.forEachRemaining(ArrayList.java:1374)
        at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:481)
        at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:471)
        at java.util.stream.ReduceOps$ReduceOp.evaluateSequential(ReduceOps.java:708)
        at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234)
        at java.util.stream.ReferencePipeline.collect(ReferencePipeline.java:499)
        at org.owasp.dependencycheck.data.nvdcve.CveDB.parseCpes(CveDB.java:1293)
        at org.owasp.dependencycheck.data.nvdcve.CveDB.updateVulnerability(CveDB.java:880)
        at org.owasp.dependencycheck.data.update.nvd.NvdCveParser.parse(NvdCveParser.java:99)


Thanks,
Kiran

Jeremy Long

unread,
May 10, 2021, 8:31:41 AM5/10/21
to Kiran Hariyapuraju, Dependency Check
Reply all
Reply to author
Forward
0 new messages