Skip to content

Conversation

@Rob-Leggett
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 9 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • websocket-api/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Path Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230373
  649   org.springframework:spring-webmvc:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit
medium severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8399269
  601   org.springframework.security:spring-security-config:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-core:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-messaging:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-web:
5.3.0.RELEASE -> 6.2.7
No Known Exploit
medium severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8399272
  601   org.springframework.security:spring-security-config:
5.3.0.RELEASE -> 6.2.7
No Known Exploit
medium severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8399278
  601   org.springframework.security:spring-security-web:
5.3.0.RELEASE -> 6.2.7
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230364
  329   org.springframework.security:spring-security-config:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-core:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-messaging:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-web:
5.3.0.RELEASE -> 6.2.7
org.springframework:spring-context:
5.3.7 -> 6.1.14
org.springframework:spring-context-support:
5.3.7 -> 6.1.14
org.springframework:spring-webmvc:
5.3.7 -> 6.1.14
org.springframework:spring-websocket:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230365
  329   org.springframework.security:spring-security-config:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-core:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-messaging:
5.3.0.RELEASE -> 6.2.7
org.springframework.security:spring-security-web:
5.3.0.RELEASE -> 6.2.7
org.springframework:spring-context:
5.3.7 -> 6.1.14
org.springframework:spring-context-support:
5.3.7 -> 6.1.14
org.springframework:spring-expression:
5.3.7 -> 6.1.14
org.springframework:spring-messaging:
5.3.7 -> 6.1.14
org.springframework:spring-orm:
5.3.7 -> 6.1.14
org.springframework:spring-web:
5.3.7 -> 6.1.14
org.springframework:spring-webmvc:
5.3.7 -> 6.1.14
org.springframework:spring-websocket:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230366
  329   org.springframework.security:spring-security-web:
5.3.0.RELEASE -> 6.2.7
org.springframework:spring-web:
5.3.7 -> 6.1.14
org.springframework:spring-webmvc:
5.3.7 -> 6.1.14
org.springframework:spring-websocket:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230368
  329   org.springframework:spring-webmvc:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230369
  329   org.springframework:spring-websocket:
5.3.7 -> 6.1.14
Major version upgrade No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Path Traversal

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants