Update dependency com.nimbusds:nimbus-jose-jwt to v9 #4
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-22259Path to dependency file: /build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework/spring-web/5.3.6/f9290db7324194921c236ad9a940467f55304fa7/spring-web-5.3.6.jar Dependency Hierarchy: -> spring-boot-starter-data-jpa-2.3.1.RELEASE.jar (Root Library) -> spring-boot-dependencies-2.3.1.RELEASE.pom -> ❌ spring-web-5.3.6.jar (Vulnerable Library) |
High | 8.1 | spring-web-5.3.6.jar | Upgrade to version: org.springframework:spring-web:5.3.33,6.0.18,6.1.5 | None |
CVE-2024-24549Path to dependency file: /build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/9.0.45/8fb7d78b14e2deb8fec430498c64418ec0a2d983/tomcat-embed-core-9.0.45.jar Dependency Hierarchy: -> spring-boot-starter-data-jpa-2.3.1.RELEASE.jar (Root Library) -> spring-boot-dependencies-2.3.1.RELEASE.pom -> ❌ tomcat-embed-core-9.0.45.jar (Vulnerable Library) |
High | 7.5 | tomcat-embed-core-9.0.45.jar | Upgrade to version: org.apache.tomcat:tomcat-coyote:8.5.99,9.0.86,10.1.19,11.0.0-M17, org.apache.tomcat.embed:tomcat-embed-core:8.5.99,9.0.86,10.1.19,11.0.0-M17 | None |
CVE-2024-23672Path to dependency file: /build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-websocket/9.0.45/5cefd0aab62e2938f51110ebeb557b30ed5abab/tomcat-embed-websocket-9.0.45.jar Dependency Hierarchy: -> spring-boot-starter-data-jpa-2.3.1.RELEASE.jar (Root Library) -> spring-boot-dependencies-2.3.1.RELEASE.pom -> ❌ tomcat-embed-websocket-9.0.45.jar (Vulnerable Library) |
High | 7.5 | tomcat-embed-websocket-9.0.45.jar | Upgrade to version: org.apache.tomcat:tomcat-websocket:8.5.99,9.0.86,10.1.19,11.0.0-M17 ,org.apache.tomcat.embed:tomcat-embed-websocket:8.5.99,9.0.86,10.1.19,11.0.0-M17 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-52428 | nimbus-jose-jwt-8.3.jar |
CVE-2023-1370 | json-smart-2.3.jar |
CVE-2021-27568 | json-smart-2.3.jar |
Base branch total remaining vulnerabilities: 57
Base branch commit: b7c0e6219921628db214a8f1eb399b4fa2797794
Total libraries scanned: 192
Scan token: b2367fd2015c4d2094cdb3a31be85bb6