Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade org.springframework.boot:spring-boot-starter-web from 2.1.1.RELEASE to 2.7.10 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

jonvnieu
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade org.springframework.boot:spring-boot-starter-web from 2.1.1.RELEASE to 2.7.10.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 99 versions ahead of your current version.
  • The recommended version was released a month ago, on 2023-03-23.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Remote Code Execution
SNYK-JAVA-ORGAPACHETOMCATEMBED-451343
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451459
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Reflected File Download (RFD)
SNYK-JAVA-ORGSPRINGFRAMEWORK-559346
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-COMFASTERXMLJACKSONDATATYPE-173759
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1080637
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728264
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728268
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Privilege Escalation
SNYK-JAVA-ORGAPACHETOMCATEMBED-2414084
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451342
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Insecure Temporary File
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-2438287
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHETOMCATEMBED-570072
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Improper Input Validation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1009832
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Improper Output Neutralization for Logs
SNYK-JAVA-ORGSPRINGFRAMEWORK-2329097
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Insufficient Hostname Verification
SNYK-JAVA-CHQOSLOGBACK-1726923
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGYAML-537645
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1017119
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-1048292
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Information Disclosure
SNYK-JAVA-ORGAPACHETOMCATEMBED-1061939
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1080638
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728265
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728266
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-3326459
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Unprotected Transport of Credentials
SNYK-JAVA-ORGAPACHETOMCATEMBED-3369687
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGSPRINGFRAMEWORK-2330878
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-2434828
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-2823313
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-584427
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JAVA-ORGHIBERNATEVALIDATOR-541187
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGHIBERNATEVALIDATOR-568163
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Privilege Escalation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451458
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-3035793
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-3097829
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Remote Code Execution
SNYK-JAVA-ORGSPRINGFRAMEWORK-2436751
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Session Fixation
SNYK-JAVA-ORGAPACHETOMCATEMBED-538488
675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

…1.1.RELEASE to 2.7.10

Snyk has created this PR to upgrade org.springframework.boot:spring-boot-starter-web from 2.1.1.RELEASE to 2.7.10.

See this package in Maven Repository:
https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web/

See this project in Snyk:
https://app.snyk.io/org/jonvnieu/project/6fd7548b-c4aa-45b2-a5a7-0237b3067a62?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants