The product has a dependency on a third-party component that contains one or more known vulnerabilities.