Skip to content

SWI-3723 [Snyk] Fix for 57 vulnerabilities #466

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

bwappsec
Copy link

snyk-top-banner

Snyk has created this PR to fix 57 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • samples/client/petstore/scala-akka/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
  670   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Mature
high severity Denial of Service (DoS)
SNYK-JAVA-COMTYPESAFEAKKA-6483265
  423   com.typesafe.akka:akka-http_2.12:
10.2.3 -> 10.5.3
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
  410   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
  387   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
  381   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
  352   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
  339   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Improper Resource Shutdown or Release
SNYK-JAVA-COMTYPESAFEAKKA-2336361
  333   com.typesafe.akka:akka-http_2.12:
10.2.3 -> 10.5.3
No Path Found Mature
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
  287   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
  276   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
  262   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
  257   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
  254   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
  253   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
  250   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
  243   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Major version upgrade Reachable Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
  243   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
  242   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
  242   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
  239   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
  192   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-6056407
  189   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
  187   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
  185   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
  183   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
  181   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
  180   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
  179   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
  177   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
  175   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
medium severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
  174   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found Proof of Concept
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
  171   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
  170   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
  170   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
  169   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
  168   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
  168   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
  167   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
  167   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
  167   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
  167   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
  166   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
  166   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
  165   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
  165   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
  146   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Major version upgrade No Path Found Proof of Concept
medium severity Generation of Predictable Numbers or Identifiers
SNYK-JAVA-COMTYPESAFEAKKA-5518120
  137   com.typesafe.akka:akka-stream_2.12:
2.6.12 -> 2.8.1
No Path Found Proof of Concept
high severity XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
  133   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
  125   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Major version upgrade No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
  114   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Major version upgrade No Path Found No Known Exploit
medium severity HTTP Request Smuggling
SNYK-JAVA-COMTYPESAFEAKKA-2315411
  70   com.typesafe.akka:akka-http_2.12:
10.2.3 -> 10.5.3
No Path Found No Known Exploit
medium severity Information Exposure
SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
  55   org.json4s:json4s-jackson_2.12:
3.6.7 -> 4.0.0
Major version upgrade No Path Found Proof of Concept

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Deserialization of Untrusted Data
🦉 XML External Entity (XXE) Injection
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

…ties

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-COMTYPESAFEAKKA-6483265
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
- https://snyk.io/vuln/SNYK-JAVA-COMTYPESAFEAKKA-2336361
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-6056407
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
- https://snyk.io/vuln/SNYK-JAVA-COMTYPESAFEAKKA-5518120
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
- https://snyk.io/vuln/SNYK-JAVA-COMTYPESAFEAKKA-2315411
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631
@bwappsec bwappsec changed the title [Snyk] Fix for 57 vulnerabilities SWI-3723 [Snyk] Fix for 57 vulnerabilities Jun 19, 2025
@bwappsec
Copy link
Author

bwappsec commented Jun 19, 2025

Snyk checks have failed. 6 issues have been found so far.

Icon Severity Issues
Critical 0
High 6
Medium 0
Low 0

security/snyk check is complete. No issues have been found. (View Details)

license/snyk check is complete. 6 issues have been found. (View Details)

code/snyk check is complete. No issues have been found. (View Details)

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants