[Snyk] Fix for 4 vulnerabilities #251
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-38819Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webflux:6.1.14, org.springframework:spring-webmvc:6.1.14 | #244 | |
CVE-2024-38816Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webflux:6.1.13, org.springframework:spring-webmvc:6.1.13 | #237 | |
CVE-2023-20860Path to dependency file: /pom.xml Path to vulnerable library: /pom.xml Dependency Hierarchy: -> spring-boot-starter-hateoas-2.7.18.jar (Root Library) -> spring-boot-starter-web-2.7.18.jar -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webmvc:5.3.26,6.0.7 | #142 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-38816 | spring-webmvc-5.3.39.jar |
CVE-2024-38819 | spring-webmvc-5.3.39.jar |
Base branch total remaining vulnerabilities: 37
Base branch commit: a138bba45a181433c70a0aa85e8d366706e31c7f
Total libraries scanned: 179
Scan token: 4e175c56d98d4331935e1f4599335bde