Update version.springframework (major) #27
Security Report
You have successfully remediated 17 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|
CVE-2023-20863Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.21.RELEASE/spring-expression-5.2.21.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.21.RELEASE.jar (Root Library) -> ❌ spring-expression-5.2.21.RELEASE.jar (Vulnerable Library) |
6.5 | spring-expression-5.2.21.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | None | ||
CVE-2023-20861Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.21.RELEASE/spring-expression-5.2.21.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.21.RELEASE.jar (Root Library) -> ❌ spring-expression-5.2.21.RELEASE.jar (Vulnerable Library) |
6.5 | spring-expression-5.2.21.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | None | ||
CVE-2022-22970Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.2.21.RELEASE/spring-core-5.2.21.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.21.RELEASE.jar (Root Library) -> spring-aop-5.2.21.RELEASE.jar -> spring-beans-5.2.21.RELEASE.jar -> ❌ spring-core-5.2.21.RELEASE.jar (Vulnerable Library) |
5.3 | spring-core-5.2.21.RELEASE.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None | ||
CVE-2022-22970Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.2.21.RELEASE/spring-beans-5.2.21.RELEASE.jar Dependency Hierarchy: -> spring-context-5.2.21.RELEASE.jar (Root Library) -> spring-aop-5.2.21.RELEASE.jar -> ❌ spring-beans-5.2.21.RELEASE.jar (Vulnerable Library) |
5.3 | spring-beans-5.2.21.RELEASE.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| CVE-2022-22965 | spring-beans-4.3.30.RELEASE.jar |
| CVE-2016-10735 | bootstrap-3.3.4.min.js |
| CVE-2021-22096 | spring-web-4.3.30.RELEASE.jar |
| CVE-2018-20677 | bootstrap-3.3.4.min.js |
| CVE-2022-22970 | spring-core-4.3.30.RELEASE.jar |
| CVE-2022-22968 | spring-context-4.3.30.RELEASE.jar |
| CVE-2021-22060 | spring-core-4.3.30.RELEASE.jar |
| CVE-2018-14040 | bootstrap-3.3.4.min.js |
| CVE-2023-20861 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2022-22950 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2021-22096 | spring-core-4.3.30.RELEASE.jar |
| CVE-2018-20676 | bootstrap-3.3.4.min.js |
| CVE-2022-22970 | spring-beans-4.3.30.RELEASE.jar |
| CVE-2021-22096 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2023-20863 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2019-8331 | bootstrap-3.3.4.min.js |
| CVE-2018-14042 | bootstrap-3.3.4.min.js |
Base branch total remaining vulnerabilities: 49
Base branch commit: null
Total libraries scanned: 98
Scan token: 37ace9076091453a9eff5d8c5782c2db