forked from cn-panda/JavaCodeAudit
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 109 vulnerabilities #1
Open
snyk-bot
wants to merge
1
commit into
master
Choose a base branch
from
snyk-fix-5452861b4db692618ab3865fa35c3794
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…cms-admin/pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222 - https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-570967 - https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-73578 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31507 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31519 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31573 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236 - https://snyk.io/vuln/SNYK-JAVA-COMJFINAL-2848105 - https://snyk.io/vuln/SNYK-JAVA-COMMCHANGE-174481 - https://snyk.io/vuln/SNYK-JAVA-COMMCHANGE-451675 - https://snyk.io/vuln/SNYK-JAVA-COMMONSBEANUTILS-30077 - https://snyk.io/vuln/SNYK-JAVA-COMMONSCODEC-561518 - https://snyk.io/vuln/SNYK-JAVA-COMMONSIO-1277109 - https://snyk.io/vuln/SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-174574 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-1766958 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-2386864 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-31399 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-31449 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-31580 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-451460 - https://snyk.io/vuln/SNYK-JAVA-MYSQL-451464 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-30027 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-30698 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-31387 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-31438 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-32049 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEPOI-548686 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-1070410 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-1656679 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-174083 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-2944236 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-3043119 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-573173 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-598867 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHESHIRO-608688 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEXMLBEANS-1060048 - https://snyk.io/vuln/SNYK-JAVA-ORGFREEMARKER-1076795 - https://snyk.io/vuln/SNYK-JAVA-ORGJAVAWEBSOCKET-568685 - https://snyk.io/vuln/SNYK-JAVA-ORGQUARTZSCHEDULER-461170 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2329097 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2330878 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2434828 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2436751 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2823313 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-31326
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMALIBABA-2859222
com.alibaba:fastjson:
1.1.41 -> 1.2.83
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMALIBABA-570967
com.alibaba:fastjson:
1.1.41 -> 1.2.83
Why? Mature exploit, Has a fix available, CVSS 9
SNYK-JAVA-COMALIBABA-73578
com.alibaba:fastjson:
1.1.41 -> 1.2.83
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31507
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31519
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31573
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Mature exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Mature exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
net.sf.jasperreports:jasperreports:
5.6.1 -> 6.20.0
Why? Has a fix available, CVSS 6.5
SNYK-JAVA-COMGOOGLECODEGSON-1730327
com.google.code.gson:gson:
2.8.0 -> 2.8.9
Why? Proof of Concept exploit, Has a fix available, CVSS 3.3
SNYK-JAVA-COMGOOGLEGUAVA-1015415
com.google.guava:guava:
18.0 -> 30.0-android
Why? Has a fix available, CVSS 5.9
SNYK-JAVA-COMGOOGLEGUAVA-32236
com.google.guava:guava:
18.0 -> 30.0-android
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-COMJFINAL-2848105
com.jfinal:jfinal:
3.2 -> 4.5
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-COMMCHANGE-174481
org.quartz-scheduler:quartz:
2.3.0 -> 2.3.2
Why? Has a fix available, CVSS 9.8
SNYK-JAVA-COMMCHANGE-451675
org.quartz-scheduler:quartz:
2.3.0 -> 2.3.2
Why? Mature exploit, Has a fix available, CVSS 7.3
SNYK-JAVA-COMMONSBEANUTILS-30077
org.apache.shiro:shiro-core:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 3.7
SNYK-JAVA-COMMONSCODEC-561518
commons-codec:commons-codec:
1.10 -> 1.13
org.apache.poi:poi:
3.10.1 -> 4.1.1
Why? Mature exploit, Has a fix available, CVSS 5.3
SNYK-JAVA-COMMONSIO-1277109
commons-io:commons-io:
2.4 -> 2.7
Why? Proof of Concept exploit, Has a fix available, CVSS 8.2
SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044
com.squareup.okhttp3:okhttp:
3.8.1 -> 4.9.2
Why? Has a fix available, CVSS 6.3
SNYK-JAVA-MYSQL-174574
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
SNYK-JAVA-MYSQL-1766958
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 6.6
SNYK-JAVA-MYSQL-2386864
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 8.5
SNYK-JAVA-MYSQL-31399
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 3.3
SNYK-JAVA-MYSQL-31449
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 6.4
SNYK-JAVA-MYSQL-31580
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Mature exploit, Has a fix available, CVSS 5.4
SNYK-JAVA-MYSQL-451460
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 8.8
SNYK-JAVA-MYSQL-451464
mysql:mysql-connector-java:
5.1.20 -> 8.0.28
Why? Has a fix available, CVSS 4.3
SNYK-JAVA-ORGAPACHEPOI-30027
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-ORGAPACHEPOI-30698
org.apache.poi:poi:
3.10.1 -> 4.1.1
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Has a fix available, CVSS 5.5
SNYK-JAVA-ORGAPACHEPOI-31387
org.apache.poi:poi:
3.10.1 -> 4.1.1
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Has a fix available, CVSS 5.5
SNYK-JAVA-ORGAPACHEPOI-31438
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHEPOI-32049
org.apache.poi:poi:
3.10.1 -> 4.1.1
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Has a fix available, CVSS 5
SNYK-JAVA-ORGAPACHEPOI-548686
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHESHIRO-1070410
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHESHIRO-1656679
org.apache.shiro:shiro-core:
1.3.2 -> 1.10.0
org.apache.shiro:shiro-ehcache:
1.3.2 -> 1.4.0
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 4.3
SNYK-JAVA-ORGAPACHESHIRO-174083
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHESHIRO-2944236
org.apache.shiro:shiro-core:
1.3.2 -> 1.10.0
org.apache.shiro:shiro-ehcache:
1.3.2 -> 1.4.0
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 7.6
SNYK-JAVA-ORGAPACHESHIRO-3043119
org.apache.shiro:shiro-core:
1.3.2 -> 1.10.0
org.apache.shiro:shiro-ehcache:
1.3.2 -> 1.4.0
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 9.8
SNYK-JAVA-ORGAPACHESHIRO-573173
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Proof of Concept exploit, Has a fix available, CVSS 7.4
SNYK-JAVA-ORGAPACHESHIRO-598867
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 5.9
SNYK-JAVA-ORGAPACHESHIRO-608688
org.apache.shiro:shiro-web:
1.3.2 -> 1.10.0
Why? Has a fix available, CVSS 8.3
SNYK-JAVA-ORGAPACHEXMLBEANS-1060048
org.apache.poi:poi-ooxml:
3.10.1 -> 4.1.0
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-ORGFREEMARKER-1076795
org.freemarker:freemarker:
2.3.21 -> 2.3.30
Why?
SNYK-JAVA-ORGJAVAWEBSOCKET-568685
org.java-websocket:Java-WebSocket:
1.3.7 -> 1.5.0
Why?
SNYK-JAVA-ORGQUARTZSCHEDULER-461170
org.quartz-scheduler:quartz:
2.3.0 -> 2.3.2
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2329097
org.springframework:spring-aop:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-jdbc:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-orm:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-tx:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2330878
org.springframework:spring-aop:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-jdbc:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-orm:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-tx:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2434828
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2436751
org.springframework:spring-aop:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-jdbc:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-orm:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-tx:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-2823313
org.springframework:spring-aop:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-jdbc:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-orm:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-tx:
3.2.9.RELEASE -> 5.2.22.RELEASE
Why?
SNYK-JAVA-ORGSPRINGFRAMEWORK-31326
org.springframework:spring-aop:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-context-support:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-jdbc:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-orm:
3.2.9.RELEASE -> 5.2.22.RELEASE
org.springframework:spring-tx:
3.2.9.RELEASE -> 5.2.22.RELEASE
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Deserialization of Untrusted Data
🦉 Deserialization of Untrusted Data
🦉 Remote Code Execution
🦉 More lessons are available in Snyk Learn