Skip to content

SWI-3723 [Snyk] Fix for 82 vulnerabilities #34

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

bwappsec
Copy link

snyk-top-banner

Snyk has created this PR to fix 82 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
  670   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Mature
medium severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-1317097
  410   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
  387   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
  381   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
  352   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
  339   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
  287   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
  276   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
  262   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
  257   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
  254   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
  253   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
  250   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
  246   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
  243   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
  243   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
  242   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
  242   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
  239   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
  200   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
  192   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-6056407
  189   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
  187   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
  187   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
  185   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
  183   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
  181   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
  180   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
  180   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
  180   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
  179   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
  177   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
  176   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
  175   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
critical severity XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLWOODSTOX-2928754
  175   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
No Path Found No Known Exploit
medium severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
  174   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
  174   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
  172   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
  172   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
  171   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
  171   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
  170   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
  170   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
  169   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
  168   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
  168   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
  167   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
  167   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
  167   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
  167   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
  166   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
  166   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
  165   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
  165   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-543669
  163   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found Proof of Concept
high severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-543490
  160   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found Proof of Concept
high severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-6056419
  159   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
  146   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
medium severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-2314893
  145   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
Major version upgrade Reachable No Known Exploit
high severity Uncontrolled Memory Allocation
SNYK-JAVA-IONETTY-564897
  137   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found No Known Exploit
high severity XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
  133   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
  125   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-1584063
  115   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
Major version upgrade No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
  114   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-1584064
  114   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
Major version upgrade No Path Found No Known Exploit
medium severity HTTP Request Smuggling
SNYK-JAVA-IONETTY-469234
  113   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-1020439
  105   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-5725787
  104   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
Major version upgrade No Path Found No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1070799
  85   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1082235
  85   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1082236
  85   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
No Path Found No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-IONETTY-6483812
  63   org.asynchttpclient:async-http-client:
2.6.0 -> 3.0.0
Major version upgrade No Path Found Proof of Concept
low severity Information Exposure
SNYK-JAVA-JUNIT-1017047
  61   junit:junit:
4.12 -> 4.13.1
No Path Found Proof of Concept
medium severity Information Exposure
SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
  55   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:
2.8.6 -> 2.15.0
No Path Found Proof of Concept
low severity Information Disclosure
SNYK-JAVA-COMGOOGLEGUAVA-1015415
  47   com.google.guava:guava:
27.0-jre -> 32.0.0-jre
No Path Found Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLWOODSTOX-3091135
  45   com.fasterxml.jackson.dataformat:jackson-dataformat-xml:
2.9.4 -> 2.15.0
No Path Found No Known Exploit
low severity Creation of Temporary File in Directory with Insecure Permissions
SNYK-JAVA-COMGOOGLEGUAVA-5710356
  30   com.google.guava:guava:
27.0-jre -> 32.0.0-jre
No Path Found No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Deserialization of Untrusted Data
🦉 XML External Entity (XXE) Injection
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1317097
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-6056407
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLWOODSTOX-2928754
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-543669
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-543490
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-6056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-2314893
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-564897
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1584063
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1584064
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-469234
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1020439
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-5725787
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1070799
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1082235
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1082236
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-6483812
- https://snyk.io/vuln/SNYK-JAVA-JUNIT-1017047
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLWOODSTOX-3091135
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-5710356
@bwappsec
Copy link
Author

bwappsec commented Jun 19, 2025

Snyk checks have failed. 1 issues have been found so far.

Icon Severity Issues
Critical 0
High 1
Medium 0
Low 0

security/snyk check is complete. 1 issues have been found. (View Details)

license/snyk check is complete. No issues have been found. (View Details)

code/snyk check is complete. No issues have been found. (View Details)

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@bwappsec bwappsec changed the title [Snyk] Fix for 82 vulnerabilities SWI-3723 [Snyk] Fix for 82 vulnerabilities Jun 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants