Skip to content

[Snyk] Fix for 74 vulnerabilities#181

Open
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-1a1eb115db18622f2553d21e85571866
Open

[Snyk] Fix for 74 vulnerabilities#181
snyk-bot wants to merge 1 commit into
masterfrom
snyk-fix-1a1eb115db18622f2553d21e85571866

Conversation

@snyk-bot

Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • spring-boot-admin/spring-boot-admin-server/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
medium severity 454/1000
Why? Has a fix available, CVSS 4.8
Insufficient Hostname Verification
SNYK-JAVA-CHQOSLOGBACK-1726923
Yes No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Execution
SNYK-JAVA-CHQOSLOGBACK-30208
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Arbitrary Code Execution
SNYK-JAVA-CHQOSLOGBACK-31407
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
Yes No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 834/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Mature
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Mature
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No Proof of Concept
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
high severity 630/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
XML External Entity (XXE) Injection
SNYK-JAVA-COMHAZELCAST-1018909
No No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMHAZELCAST-174772
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMHAZELCAST-1922239
No No Known Exploit
high severity 644/1000
Why? Has a fix available, CVSS 8.6
Improper Input Validation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1009832
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Information Exposure
SNYK-JAVA-ORGSPRINGFRAMEWORK-31689
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Multipart Content Pollution
SNYK-JAVA-ORGSPRINGFRAMEWORK-32199
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Directory Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-32202
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Cross-Site Tracing (XST)
SNYK-JAVA-ORGSPRINGFRAMEWORK-451604
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Multipart Content Pollution
SNYK-JAVA-ORGSPRINGFRAMEWORK-460644
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
Yes No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Information Exposure
SNYK-JAVA-ORGSPRINGFRAMEWORK-467268
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-72470
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
No No Known Exploit
medium severity 591/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
Denial of Service (DoS)
SNYK-JAVA-ORGYAML-537645
de.codecentric:spring-boot-admin-server:
1.5.4 -> 2.3.0
de.codecentric:spring-boot-admin-starter-client:
1.5.4 -> 1.5.7
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade com.hazelcast:hazelcast@3.7.8 to com.hazelcast:hazelcast@3.12.11; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.8.RELEASE/spring-boot-dependencies-1.5.8.RELEASE.pom
    • Could not upgrade org.springframework.boot:spring-boot-starter@1.5.8.RELEASE to org.springframework.boot:spring-boot-starter@2.3.0.RELEASE; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.8.RELEASE/spring-boot-dependencies-1.5.8.RELEASE.pom
    • Could not upgrade org.springframework.boot:spring-boot-starter-security@1.5.8.RELEASE to org.springframework.boot:spring-boot-starter-security@2.3.0.RELEASE; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.8.RELEASE/spring-boot-dependencies-1.5.8.RELEASE.pom

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

…nerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-1726923
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-30208
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-31407
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
- https://snyk.io/vuln/SNYK-JAVA-COMHAZELCAST-1018909
- https://snyk.io/vuln/SNYK-JAVA-COMHAZELCAST-174772
- https://snyk.io/vuln/SNYK-JAVA-COMHAZELCAST-1922239
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-1009832
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-31689
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-32199
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-32202
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-451604
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-460644
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-467268
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-72470
- https://snyk.io/vuln/SNYK-JAVA-ORGYAML-537645
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant