Update dependency org.springframework:spring-web to v6 - autoclosed #88
Security Report
You have successfully remediated 22 vulnerabilities, but introduced 27 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2018-1275Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-messaging/4.3.7.RELEASE/spring-messaging-4.3.7.RELEASE.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> ❌ spring-messaging-4.3.7.RELEASE.jar (Vulnerable Library) |
9.8 | spring-messaging-4.3.7.RELEASE.jar | Upgrade to version: 5.0.5,4.3.16 | #26 | ||
CVE-2018-1270Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-messaging/4.3.7.RELEASE/spring-messaging-4.3.7.RELEASE.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> ❌ spring-messaging-4.3.7.RELEASE.jar (Vulnerable Library) |
9.8 | spring-messaging-4.3.7.RELEASE.jar | Upgrade to version: 5.0.5,4.3.15 | #26 | ||
CVE-2024-22262Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.34;6.0.19,6.1.6 | None | ||
CVE-2024-22243Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.32,6.0.17,6.1.4 | None | ||
CVE-2023-20860Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | spring-webmvc-6.0.0.jar | Upgrade to version: org.springframework:spring-webmvc:5.3.26,6.0.7 | None | ||
CVE-2017-7536Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/hibernate-validator/5.2.1.Final/hibernate-validator-5.2.1.Final.jar Dependency Hierarchy: -> ❌ hibernate-validator-5.2.1.Final.jar (Vulnerable Library) |
7.0 | hibernate-validator-5.2.1.Final.jar | Upgrade to version: org.hibernate:hibernate-validator:5.3.6.Final,5.4.2.Final | #17 | ||
CVE-2023-20863Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> spring-webmvc-6.0.0.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | spring-expression-6.0.0.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | None | ||
CVE-2023-20861Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> spring-webmvc-6.0.0.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | spring-expression-6.0.0.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | None | ||
CVE-2024-23080Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/joda-time/joda-time/2.9.5/joda-time-2.9.5.jar Dependency Hierarchy: -> elasticsearch-5.6.4.jar (Root Library) -> ❌ joda-time-2.9.5.jar (Vulnerable Library) |
5.5 | joda-time-2.9.5.jar | #16 | |||
CVE-2017-8045Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/amqp/spring-amqp/1.7.1.RELEASE/spring-amqp-1.7.1.RELEASE.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> ❌ spring-amqp-1.7.1.RELEASE.jar (Vulnerable Library) |
9.8 | spring-amqp-1.7.1.RELEASE.jar | Upgrade to version: org.springframework.amqp:spring-amqp:1.5.7,1.6.11,1.7.4 | #26 | ||
CVE-2017-5929Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.1.3/logback-classic-1.1.3.jar Dependency Hierarchy: -> ❌ logback-classic-1.1.3.jar (Vulnerable Library) |
9.8 | logback-classic-1.1.3.jar | Upgrade to version: ch.qos.logback:logback-core:1.2.0;ch.qos.logback:logback-access:1.2.0;ch.qos.logback:logback-classic:1.2.0 | #32 | ||
CVE-2017-5929Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.1.3/logback-core-1.1.3.jar Dependency Hierarchy: -> logback-classic-1.1.3.jar (Root Library) -> ❌ logback-core-1.1.3.jar (Vulnerable Library) |
9.8 | logback-core-1.1.3.jar | Upgrade to version: ch.qos.logback:logback-core:1.2.0;ch.qos.logback:logback-access:1.2.0;ch.qos.logback:logback-classic:1.2.0 | #32 | ||
CVE-2017-3523Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/5.1.35/mysql-connector-java-5.1.35.jar Dependency Hierarchy: -> ❌ mysql-connector-java-5.1.35.jar (Vulnerable Library) |
8.5 | mysql-connector-java-5.1.35.jar | Upgrade to version: mysql:mysql-connector-java:5.1.41 | #39 | ||
CVE-2024-22259Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.33,6.0.18,6.1.5 | None | ||
CVE-2023-34053Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
7.5 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:6.0.14 | None | ||
CVE-2018-1000632Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar Dependency Hierarchy: -> hibernate-entitymanager-4.3.11.Final.jar (Root Library) -> hibernate-core-4.3.11.Final.jar -> ❌ dom4j-1.6.1.jar (Vulnerable Library) |
7.5 | dom4j-1.6.1.jar | Upgrade to version: org.dom4j:dom4j:2.0.3 | #27 | ||
WS-2020-0408Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/netty/netty-handler/4.1.13.Final/netty-handler-4.1.13.Final.jar Dependency Hierarchy: -> transport-5.6.4.jar (Root Library) -> transport-netty4-client-5.6.4.jar -> ❌ netty-handler-4.1.13.Final.jar (Vulnerable Library) |
7.4 | netty-handler-4.1.13.Final.jar | Upgrade to version: io.netty:netty-all - 4.1.68.Final-redhat-00001,4.0.0.Final,4.1.67.Final-redhat-00002;io.netty:netty-handler - 4.1.68.Final-redhat-00001,4.1.67.Final-redhat-00001 | #20 | ||
CVE-2016-1000031Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-fileupload/commons-fileupload/1.3.1/commons-fileupload-1.3.1.jar Dependency Hierarchy: -> ❌ commons-fileupload-1.3.1.jar (Vulnerable Library) |
7.3 | commons-fileupload-1.3.1.jar | Upgrade to version: 1.3.3 | #31 | ||
CVE-2017-3586Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/5.1.35/mysql-connector-java-5.1.35.jar Dependency Hierarchy: -> ❌ mysql-connector-java-5.1.35.jar (Vulnerable Library) |
6.4 | mysql-connector-java-5.1.35.jar | Upgrade to version: 5.1.42 | #39 | ||
CVE-2018-11087Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/rabbitmq/amqp-client/4.0.2/amqp-client-4.0.2.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> ❌ amqp-client-4.0.2.jar (Vulnerable Library) |
5.9 | amqp-client-4.0.2.jar | Upgrade to version: 1.7.10.RELEASE,2.0.6.RELEASE | #26 | ||
CVE-2018-11087Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/amqp/spring-amqp/1.7.1.RELEASE/spring-amqp-1.7.1.RELEASE.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> ❌ spring-amqp-1.7.1.RELEASE.jar (Vulnerable Library) |
5.9 | spring-amqp-1.7.1.RELEASE.jar | Upgrade to version: 1.7.10.RELEASE,2.0.6.RELEASE | #26 | ||
CVE-2018-11087Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/amqp/spring-rabbit/1.7.1.RELEASE/spring-rabbit-1.7.1.RELEASE.jar Dependency Hierarchy: -> ❌ spring-rabbit-1.7.1.RELEASE.jar (Vulnerable Library) |
5.9 | spring-rabbit-1.7.1.RELEASE.jar | Upgrade to version: 1.7.10.RELEASE,2.0.6.RELEASE | #26 | ||
CVE-2016-6652Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-jpa/1.8.1.RELEASE/spring-data-jpa-1.8.1.RELEASE.jar Dependency Hierarchy: -> ❌ spring-data-jpa-1.8.1.RELEASE.jar (Vulnerable Library) |
5.6 | spring-data-jpa-1.8.1.RELEASE.jar | Upgrade to version: org.springframework.data:spring-data-jpa:1.9.6,1.10.4 | #33 | ||
CVE-2017-3589Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/5.1.35/mysql-connector-java-5.1.35.jar Dependency Hierarchy: -> ❌ mysql-connector-java-5.1.35.jar (Vulnerable Library) |
3.3 | mysql-connector-java-5.1.35.jar | Upgrade to version: 5.1.42 | #39 | ||
CVE-2020-23064Path to dependency file: /src/main/webapp/WEB-INF/views/upload.jsp Path to vulnerable library: /src/main/webapp/WEB-INF/views/upload.jsp Dependency Hierarchy: -> ❌ jquery-3.2.1.min.js (Vulnerable Library) |
6.1 | jquery-3.2.1.min.js | Upgrade to version: jquery - 3.5.0 | #21 | ||
CVE-2020-11023Path to dependency file: /src/main/webapp/WEB-INF/views/upload.jsp Path to vulnerable library: /src/main/webapp/WEB-INF/views/upload.jsp Dependency Hierarchy: -> ❌ jquery-3.2.1.min.js (Vulnerable Library) |
6.1 | jquery-3.2.1.min.js | Upgrade to version: jquery - 3.5.0;jquery-rails - 4.4.0 | #21 | ||
CVE-2018-14040Path to dependency file: /src/main/webapp/WEB-INF/views/upload.jsp Path to vulnerable library: /src/main/webapp/WEB-INF/views/upload.jsp Dependency Hierarchy: -> ❌ bootstrap-3.3.7.min.js (Vulnerable Library) |
3.7 | bootstrap-3.3.7.min.js | Upgrade to version: bootstrap - 3.4.0,4.1.2 | #15 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-22950 | spring-expression-4.2.1.RELEASE.jar |
CVE-2016-1000027 | spring-web-4.2.1.RELEASE.jar |
CVE-2021-22096 | spring-core-4.2.1.RELEASE.jar |
CVE-2021-22060 | spring-core-4.2.1.RELEASE.jar |
CVE-2024-22262 | spring-web-4.2.1.RELEASE.jar |
CVE-2018-15756 | spring-web-4.2.1.RELEASE.jar |
CVE-2023-20861 | spring-expression-4.2.1.RELEASE.jar |
CVE-2022-22968 | spring-context-4.2.1.RELEASE.jar |
WS-2021-0170 | spring-core-4.2.1.RELEASE.jar |
CVE-2016-5007 | spring-webmvc-4.2.1.RELEASE.jar |
CVE-2020-5421 | spring-web-4.2.1.RELEASE.jar |
WS-2016-7112 | spring-context-4.2.1.RELEASE.jar |
CVE-2018-1272 | spring-core-4.2.1.RELEASE.jar |
CVE-2022-22970 | spring-beans-4.2.1.RELEASE.jar |
CVE-2021-22096 | spring-webmvc-4.2.1.RELEASE.jar |
CVE-2023-20863 | spring-expression-4.2.1.RELEASE.jar |
CVE-2024-22259 | spring-web-4.2.1.RELEASE.jar |
CVE-2024-22243 | spring-web-4.2.1.RELEASE.jar |
CVE-2022-22965 | spring-beans-4.2.1.RELEASE.jar |
CVE-2021-22096 | spring-web-4.2.1.RELEASE.jar |
CVE-2022-22970 | spring-core-4.2.1.RELEASE.jar |
CVE-2018-1199 | spring-core-4.2.1.RELEASE.jar |
Base branch total remaining vulnerabilities: 171
Base branch commit: c7ee49b4ed6b956bb9f0c4d21c5015ee42c9776b
Total libraries scanned: 110
Scan token: 0c7374c62c3a4c2a9fcd8f228905d4a0