Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: commons-codec:commons-codec, commons-validator:commons-validator, dnsjava:dnsjava, net.bytebuddy:byte-buddy, org.apache.commons:commons-lang3, org.apache.logging.log4j:log4j-1.2-api, org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j-slf4j-impl, org.ehcache:ehcache, org.freemarker:freemarker, org.hibernate:hibernate-agroal, org.mockito:mockito-core, org.neo4j:neo4j-cypher-commons, org.springframework:spring-context, org.springframework:spring-aop, org.springframework:spring-beans, org.springframework:spring-core, org.springframework.security:spring-security-core, org.springframework:spring-context-support, org.springframework:spring-jdbc, org.springframework:spring-orm, org.springframework:spring-tx, org.springframework:spring-oxm, org.springframework.security:spring-security-web, org.springframework:spring-webmvc, org.springframework.security:spring-security-config, org.springframework.security:spring-security-acl, org.springframework.security:spring-security-taglibs #1075

Open
wants to merge 1 commit into
base: development
Choose a base branch
from

Conversation

NOUIY
Copy link
Owner

@NOUIY NOUIY commented Sep 17, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

commons-codec:commons-codec
from 1.9 to 1.17.1 | 10 versions ahead of your current version | 2 months ago
on 2024-07-12
commons-validator:commons-validator
from 1.6 to 1.9.0 | 3 versions ahead of your current version | 4 months ago
on 2024-05-25
dnsjava:dnsjava
from 2.1.6 to 2.1.9 | 3 versions ahead of your current version | 5 years ago
on 2019-05-25
net.bytebuddy:byte-buddy
from 1.10.5 to 1.14.19 | 84 versions ahead of your current version | a month ago
on 2024-08-15
org.apache.commons:commons-lang3
from 3.2 to 3.16.0 | 18 versions ahead of your current version | 2 months ago
on 2024-08-01
org.apache.logging.log4j:log4j-1.2-api
from 2.17.1 to 2.23.1 | 10 versions ahead of your current version | 6 months ago
on 2024-03-06
org.apache.logging.log4j:log4j-core
from 2.17.1 to 2.23.1 | 10 versions ahead of your current version | 6 months ago
on 2024-03-06
org.apache.logging.log4j:log4j-slf4j-impl
from 2.17.1 to 2.23.1 | 10 versions ahead of your current version | 6 months ago
on 2024-03-06
org.ehcache:ehcache
from 3.5.2 to 3.10.8 | 34 versions ahead of your current version | 2 years ago
on 2022-11-21
org.freemarker:freemarker
from 2.3.25-incubating to 2.3.33 | 8 versions ahead of your current version | 4 months ago
on 2024-05-08
org.hibernate:hibernate-agroal
from 5.4.27.Final to 5.6.15.Final | 40 versions ahead of your current version | 2 years ago
on 2023-02-06
org.mockito:mockito-core
from 3.3.0 to 3.12.4 | 31 versions ahead of your current version | 3 years ago
on 2021-08-25
org.neo4j:neo4j-cypher-commons
from 2.1.2 to 2.1.8 | 6 versions ahead of your current version | 9 years ago
on 2015-04-01
org.springframework:spring-context
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-aop
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-beans
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-core
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework.security:spring-security-core
from 5.6.2 to 5.8.13 | 37 versions ahead of your current version | 3 months ago
on 2024-06-17
org.springframework:spring-context-support
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-jdbc
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-orm
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-tx
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework:spring-oxm
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework.security:spring-security-web
from 5.6.2 to 5.8.14 | 38 versions ahead of your current version | a month ago
on 2024-08-19
org.springframework:spring-webmvc
from 5.3.20 to 5.3.39 | 19 versions ahead of your current version | a month ago
on 2024-08-14
org.springframework.security:spring-security-config
from 5.6.2 to 5.8.14 | 38 versions ahead of your current version | a month ago
on 2024-08-19
org.springframework.security:spring-security-acl
from 5.6.2 to 5.8.14 | 38 versions ahead of your current version | a month ago
on 2024-08-19
org.springframework.security:spring-security-taglibs
from 5.6.2 to 5.8.14 | 38 versions ahead of your current version | a month ago
on 2024-08-19

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Server-side Template Injection (SSTI)
SNYK-JAVA-ORGFREEMARKER-1076795
696 Proof of Concept
high severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-2833359
696 Proof of Concept
high severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-3092126
696 No Known Exploit
high severity Improper Access Control
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-6457293
696 No Known Exploit
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6261586
696 No Known Exploit
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6444790
696 No Known Exploit
medium severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6597980
696 No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447
696 No Known Exploit
medium severity Integer Overflow or Wraparound
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-2833360
696 Proof of Concept
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749
696 No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-5422217
696 No Known Exploit
low severity Information Exposure
SNYK-JAVA-COMMONSCODEC-561518
696 No Known Exploit
critical severity Access Control Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-5777893
696 Proof of Concept
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-7687446
696 No Known Exploit
critical severity Improper Access Control
SNYK-JAVA-ORGSPRINGFRAMEWORK-3369852
696 Proof of Concept

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - commons-codec:commons-codec from 1.9 to 1.17.1.
    See this package in maven: https://mvnrepository.com/artifact/commons-codec/commons-codec/
  - commons-validator:commons-validator from 1.6 to 1.9.0.
    See this package in maven: https://mvnrepository.com/artifact/commons-validator/commons-validator/
  - dnsjava:dnsjava from 2.1.6 to 2.1.9.
    See this package in maven: https://mvnrepository.com/artifact/dnsjava/dnsjava/
  - net.bytebuddy:byte-buddy from 1.10.5 to 1.14.19.
    See this package in maven: https://mvnrepository.com/artifact/net.bytebuddy/byte-buddy/
  - org.apache.commons:commons-lang3 from 3.2 to 3.16.0.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.commons/commons-lang3/
  - org.apache.logging.log4j:log4j-1.2-api from 2.17.1 to 2.23.1.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-1.2-api/
  - org.apache.logging.log4j:log4j-core from 2.17.1 to 2.23.1.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/
  - org.apache.logging.log4j:log4j-slf4j-impl from 2.17.1 to 2.23.1.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-slf4j-impl/
  - org.ehcache:ehcache from 3.5.2 to 3.10.8.
    See this package in maven: https://mvnrepository.com/artifact/org.ehcache/ehcache/
  - org.freemarker:freemarker from 2.3.25-incubating to 2.3.33.
    See this package in maven: https://mvnrepository.com/artifact/org.freemarker/freemarker/
  - org.hibernate:hibernate-agroal from 5.4.27.Final to 5.6.15.Final.
    See this package in maven: https://mvnrepository.com/artifact/org.hibernate/hibernate-agroal/
  - org.mockito:mockito-core from 3.3.0 to 3.12.4.
    See this package in maven: https://mvnrepository.com/artifact/org.mockito/mockito-core/
  - org.neo4j:neo4j-cypher-commons from 2.1.2 to 2.1.8.
    See this package in maven: https://mvnrepository.com/artifact/org.neo4j/neo4j-cypher-commons/
  - org.springframework:spring-context from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-context/
  - org.springframework:spring-aop from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-aop/
  - org.springframework:spring-beans from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-beans/
  - org.springframework:spring-core from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-core/
  - org.springframework.security:spring-security-core from 5.6.2 to 5.8.13.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.security/spring-security-core/
  - org.springframework:spring-context-support from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-context-support/
  - org.springframework:spring-jdbc from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-jdbc/
  - org.springframework:spring-orm from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-orm/
  - org.springframework:spring-tx from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-tx/
  - org.springframework:spring-oxm from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-oxm/
  - org.springframework.security:spring-security-web from 5.6.2 to 5.8.14.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.security/spring-security-web/
  - org.springframework:spring-webmvc from 5.3.20 to 5.3.39.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework/spring-webmvc/
  - org.springframework.security:spring-security-config from 5.6.2 to 5.8.14.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.security/spring-security-config/
  - org.springframework.security:spring-security-acl from 5.6.2 to 5.8.14.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.security/spring-security-acl/
  - org.springframework.security:spring-security-taglibs from 5.6.2 to 5.8.14.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.security/spring-security-taglibs/

See this project in Snyk:
https://app.snyk.io/org/nexuscompute/project/0920fe49-8cc5-4fc4-995d-e4d5ebb66a1b?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants