[Snyk] Fix for 5 vulnerabilities #368
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-38819Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
High | 7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webflux:6.1.14, org.springframework:spring-webmvc:6.1.14 | #361 |
CVE-2024-38816Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
High | 7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webflux:6.1.13, org.springframework:spring-webmvc:6.1.13 | #354 |
CVE-2023-20860Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
High | 7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webmvc:5.3.26,6.0.7 | #286 |
CVE-2016-7103Vulnerable Source Files: ❌ /src/main/resources/static/components/angular-ui/test/lib/jquery/jquery-ui-1.8.18.js |
Medium | 6.1 | librejslibrejs-5.0 | Upgrade to version: katello - 4.7.2 | #134 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-38816 | spring-webmvc-5.3.39.jar |
CVE-2024-38819 | spring-webmvc-5.3.39.jar |
Base branch total remaining vulnerabilities: 55
Base branch commit: a7f1d7c8847a948156fd4ef3adcd08e7ee28d718
Total libraries scanned: 231
Scan token: cd3348a3751542c19a059e0db0c3a255