Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 68 vulnerabilities #20

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 624/1000
Why? Has a fix available, CVSS 8.2
XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 651/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.6
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 919/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Mature
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 876/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Mature
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 364/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No Proof of Concept
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 375/1000
Why? Has a fix available, Low severity
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1048058
com.amazonaws:aws-java-sdk-dynamodb:
1.11.34 -> 1.11.538
No No Known Exploit
high severity 644/1000
Why? Has a fix available, CVSS 8.6
Improper Input Validation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1009832
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 434/1000
Why? Has a fix available, CVSS 4.4
Privilege Escalation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Regular Expression Denial of Service (ReDoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-31674
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Information Exposure
SNYK-JAVA-ORGSPRINGFRAMEWORK-31689
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Cross-Site Tracing (XST)
SNYK-JAVA-ORGSPRINGFRAMEWORK-451604
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-72470
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit
medium severity 495/1000
Why? Has a fix available, CVSS 5.4
Denial of Service (DoS)
SNYK-JAVA-ORGYAML-537645
org.springframework.cloud:spring-cloud-function-adapter-aws:
1.0.0.RC2 -> 3.1.0
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1048058
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-1009832
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-31674
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-31689
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-451604
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-72470
- https://snyk.io/vuln/SNYK-JAVA-ORGYAML-537645
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant