OHDSI / WhiteRabbit

WhiteRabbit is a small application that can be used to analyse the structure and contents of a database as preparation for designing an ETL. It comes with RabbitInAHat, an application for interactive design of an ETL to the OMOP Common Data Model with the help of the the scan report generated by White Rabbit.
http://ohdsi.github.io/WhiteRabbit
Apache License 2.0
173 stars 85 forks source link

[Snyk] Upgrade mysql:mysql-connector-java from 8.0.25 to 8.0.30 #351

Closed blootsvoets closed 11 months ago

blootsvoets commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade mysql:mysql-connector-java from 8.0.25 to 8.0.30.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **5 versions** ahead of your current version. - The recommended version was released **3 months ago**, on 2022-07-01. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Denial of Service (DoS)
[SNYK-JAVA-COMGOOGLEPROTOBUF-2331703](https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEPROTOBUF-2331703) | **589/1000**
**Why?** Has a fix available, CVSS 7.5 | No Known Exploit | Improper Authorization
[SNYK-JAVA-MYSQL-2386864](https://snyk.io/vuln/SNYK-JAVA-MYSQL-2386864) | **589/1000**
**Why?** Has a fix available, CVSS 7.5 | No Known Exploit | XML External Entity (XXE) Injection
[SNYK-JAVA-MYSQL-1766958](https://snyk.io/vuln/SNYK-JAVA-MYSQL-1766958) | **589/1000**
**Why?** Has a fix available, CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/thehyve/project/e7729804-71c9-4aea-bb72-5971af595b87?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/thehyve/project/e7729804-71c9-4aea-bb72-5971af595b87/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/thehyve/project/e7729804-71c9-4aea-bb72-5971af595b87/settings/integration?pkg=mysql:mysql-connector-java&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
janblom commented 11 months ago

Already at 8.0.33