Skip to content

[Snyk] Fix for 12 vulnerabilities#626

Open
AntonioG70 wants to merge 1 commit intomasterfrom
snyk-fix-7556374aefd08d6943c5effeac7ff380
Open

[Snyk] Fix for 12 vulnerabilities#626
AntonioG70 wants to merge 1 commit intomasterfrom
snyk-fix-7556374aefd08d6943c5effeac7ff380

Conversation

@AntonioG70
Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 12 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
low severity Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755
  ****   org.springframework.boot:spring-boot-starter-jersey:
3.4.10 -> 3.5.12
org.springframework.boot:spring-boot-starter-web:
3.4.10 -> 3.5.12
`` No Known Exploit
low severity Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701756
  ****   org.springframework.boot:spring-boot-starter-web:
3.4.10 -> 3.5.12
`` No Known Exploit
high severity Directory Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701845
  ****   org.springframework.boot:spring-boot-starter-web:
3.4.10 -> 3.5.12
`` No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701835
  ****   `` No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701836
  ****   `` No Known Exploit
medium severity Uncontrolled Recursion
SNYK-JAVA-COMNIMBUSDS-10691768
  420   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found Proof of Concept
medium severity Observable Discrepancy
SNYK-JAVA-ORGBOUNCYCASTLE-8731360
  370   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found Proof of Concept
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-11777856
  315   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-11789705
  315   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found No Known Exploit
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-ORGBOUNCYCASTLE-6084022
  275   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-6613080
  265   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found No Known Exploit
medium severity Information Exposure
SNYK-JAVA-ORGBOUNCYCASTLE-5771339
  235   org.apereo.cas.client:cas-client-core:
4.0.4 -> 4.1.0
No Path Found No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:spring-boot-starter-actuator@3.2.5 to org.springframework.boot:spring-boot-starter-actuator@3.5.12; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/3.2.5/spring-boot-dependencies-3.2.5.pom

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Information Exposure
🦉 Uncontrolled Resource Consumption ('Resource Exhaustion')
🦉 More lessons are available in Snyk Learn

@dosubot dosubot bot added size:XS This PR changes 0-9 lines, ignoring generated files. security labels Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants