Update dependency org.springframework.amqp:spring-rabbit to v2 #7
Security Report
You have successfully remediated 26 vulnerabilities, but introduced 9 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2022-22965Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.3.7/spring-beans-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-context-5.3.7.jar -> spring-aop-5.3.7.jar -> ❌ spring-beans-5.3.7.jar (Vulnerable Library) |
10.0 | spring-beans-5.3.7.jar | Upgrade to version: org.springframework:spring-beans:5.2.20.RELEASE,5.3.18 | None | ||
CVE-2023-20863Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.3.7/spring-expression-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-context-5.3.7.jar -> ❌ spring-expression-5.3.7.jar (Vulnerable Library) |
6.5 | spring-expression-5.3.7.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | None | ||
CVE-2023-20861Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.3.7/spring-expression-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-context-5.3.7.jar -> ❌ spring-expression-5.3.7.jar (Vulnerable Library) |
6.5 | spring-expression-5.3.7.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | None | ||
CVE-2022-22950Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.3.7/spring-expression-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-context-5.3.7.jar -> ❌ spring-expression-5.3.7.jar (Vulnerable Library) |
6.5 | spring-expression-5.3.7.jar | Upgrade to version: org.springframework:spring-expression:5.2.20,5.3.17 | None | ||
CVE-2022-22968Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/5.3.7/spring-context-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> ❌ spring-context-5.3.7.jar (Vulnerable Library) |
5.3 | spring-context-5.3.7.jar | Upgrade to version: org.springframework:spring-context:5.2.21,5.3.19 | None | ||
CVE-2022-22970Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.7/spring-core-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-amqp-2.3.7.jar -> ❌ spring-core-5.3.7.jar (Vulnerable Library) |
4.3 | spring-core-5.3.7.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None | ||
CVE-2022-22970Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.3.7/spring-beans-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-context-5.3.7.jar -> spring-aop-5.3.7.jar -> ❌ spring-beans-5.3.7.jar (Vulnerable Library) |
4.3 | spring-beans-5.3.7.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None | ||
CVE-2021-22096Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.7/spring-core-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-amqp-2.3.7.jar -> ❌ spring-core-5.3.7.jar (Vulnerable Library) |
4.3 | spring-core-5.3.7.jar | Upgrade to version: org.springframework:spring-core:5.2.18.RELEASE,5.3.12;org.springframework:spring-web:5.2.18.RELEASE,5.3.12;org.springframework:spring-webmvc:5.2.18.RELEASE,5.3.12;org.springframework:spring-webflux:5.2.18.RELEASE,5.3.12 | None | ||
CVE-2021-22060Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.7/spring-core-5.3.7.jar Dependency Hierarchy: -> spring-rabbit-2.3.7.jar (Root Library) -> spring-amqp-2.3.7.jar -> ❌ spring-core-5.3.7.jar (Vulnerable Library) |
4.3 | spring-core-5.3.7.jar | Upgrade to version: org.springframework:spring-core:5.2.19, 5.3.14;org.springframework:spring-web:5.2.19, 5.3.14 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2018-11040 | spring-web-4.3.7.RELEASE.jar |
CVE-2002-2010 | commons-codec-1.6.jar |
CVE-2022-22965 | spring-beans-4.3.7.RELEASE.jar |
CVE-2023-20863 | spring-expression-4.3.7.RELEASE.jar |
CVE-2022-22970 | spring-core-4.3.7.RELEASE.jar |
CVE-2018-1272 | spring-core-4.3.7.RELEASE.jar |
CVE-2021-22060 | spring-core-4.3.7.RELEASE.jar |
CVE-2022-22970 | spring-beans-4.3.7.RELEASE.jar |
CVE-2021-22096 | spring-core-4.3.7.RELEASE.jar |
WS-2019-0379 | commons-codec-1.6.jar |
CVE-2022-22950 | spring-expression-4.3.7.RELEASE.jar |
CVE-2018-1257 | spring-messaging-4.3.7.RELEASE.jar |
CVE-2018-11087 | spring-rabbit-1.7.1.RELEASE.jar |
CVE-2018-1275 | spring-messaging-4.3.7.RELEASE.jar |
CVE-2018-11087 | spring-amqp-1.7.1.RELEASE.jar |
WS-2017-3734 | httpclient-4.3.6.jar |
CVE-2018-1270 | spring-messaging-4.3.7.RELEASE.jar |
CVE-2016-1000027 | spring-web-4.3.7.RELEASE.jar |
CVE-2023-20861 | spring-expression-4.3.7.RELEASE.jar |
CVE-2018-15756 | spring-web-4.3.7.RELEASE.jar |
CVE-2021-22096 | spring-web-4.3.7.RELEASE.jar |
CVE-2020-5421 | spring-web-4.3.7.RELEASE.jar |
CVE-2017-8045 | spring-amqp-1.7.1.RELEASE.jar |
CVE-2018-11039 | spring-web-4.3.7.RELEASE.jar |
CVE-2020-13956 | httpclient-4.3.6.jar |
CVE-2022-22968 | spring-context-4.3.7.RELEASE.jar |
Base branch total remaining vulnerabilities: 116
Base branch commit: 294a4124bf74407d7f8b9aefdf21ae6f2aa6cd4b
Total libraries scanned: 401
Scan token: 2df1bf6d17c74c1192953570fb7e739f