Update dependency org.springframework:spring-web to v6 - autoclosed #57
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 6 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2024-22262Path to dependency file: /adapters/jdbc/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.34;6.0.19,6.1.6 | None | ||
CVE-2024-22259Path to dependency file: /adapters/jdbc/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.33,6.0.18,6.1.5 | None | ||
CVE-2024-22243Path to dependency file: /adapters/jdbc/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:5.3.32,6.0.17,6.1.4 | None | ||
CVE-2023-34053Path to dependency file: /adapters/jdbc/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
7.5 | spring-web-6.0.0.jar | Upgrade to version: org.springframework:spring-web:6.0.14 | None | ||
CVE-2023-20863Path to dependency file: /hopper/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> core-1.2.35-SNAPSHOT.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | spring-expression-6.0.0.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | #48 | ||
CVE-2023-20861Path to dependency file: /hopper/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> core-1.2.35-SNAPSHOT.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | spring-expression-6.0.0.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | #48 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-22259 | spring-web-5.2.22.RELEASE.jar |
CVE-2024-22262 | spring-web-5.2.22.RELEASE.jar |
CVE-2024-22243 | spring-web-5.2.22.RELEASE.jar |
CVE-2023-20861 | spring-expression-5.2.22.RELEASE.jar |
CVE-2016-1000027 | spring-web-5.2.22.RELEASE.jar |
CVE-2023-20863 | spring-expression-5.2.22.RELEASE.jar |
Base branch total remaining vulnerabilities: 44
Base branch commit: d0c49807860a8c07c922d8e19168bd6893aad298
Total libraries scanned: 90
Scan token: f6841ac964934ba1bb198a422faf809d