This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade org.springdoc:springdoc-openapi-data-rest from 1.6.15 to 1.7.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **1 version** ahead of your current version.
- The recommended version was released **4 months ago**, on 2023-04-01.
The recommended version fixes:
Severity | Issue | PriorityScore (*) | Exploit Maturity |
:-------------------------:|:-------------------------|-------------------------|:-------------------------
| Denial of Service (DoS) [SNYK-JAVA-ORGAPACHETHRIFT-474610](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-474610) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| XML External Entity (XXE) Injection [SNYK-JAVA-ORGAPACHEJENA-1586035](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-1586035) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| XML External Entity (XXE) Injection [SNYK-JAVA-ORGAPACHEJENA-2808937](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-2808937) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| XML External Entity (XXE) Injection [SNYK-JAVA-ORGAPACHEJENA-1586046](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-1586046) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Denial of Service (DoS) [SNYK-JAVA-XERCES-2359991](https://snyk.io/vuln/SNYK-JAVA-XERCES-2359991) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Denial of Service (DoS) [SNYK-JAVA-ORGAPACHETHRIFT-1074898](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-1074898) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Authentication Bypass [SNYK-JAVA-ORGAPACHETHRIFT-451680](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-451680) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Denial of Service (DoS) [SNYK-JAVA-XERCES-31585](https://snyk.io/vuln/SNYK-JAVA-XERCES-31585) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Insufficient Validation [SNYK-JAVA-ORGAPACHETHRIFT-564358](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-564358) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') [SNYK-JAVA-ORGAPACHEJENA-5458967](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-5458967) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Denial of Service (DoS) [SNYK-JAVA-XERCES-30183](https://snyk.io/vuln/SNYK-JAVA-XERCES-30183) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Improper Access Control [SNYK-JAVA-ORGAPACHETHRIFT-173706](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-173706) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
| Improper Input Validation [SNYK-JAVA-XERCES-608891](https://snyk.io/vuln/SNYK-JAVA-XERCES-608891) | **635/1000** **Why?** Has a fix available, CVSS 8.2 | No Known Exploit
(*) Note that the real score may have changed since the PR was raised.
**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.*
For more information:
🧐 [View latest project report](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e?utm_source=github&utm_medium=referral&page=upgrade-pr)
🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr)
🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e/settings/integration?pkg=org.springdoc:springdoc-openapi-data-rest&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade org.springdoc:springdoc-openapi-data-rest from 1.6.15 to 1.7.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.- The recommended version is **1 version** ahead of your current version. - The recommended version was released **4 months ago**, on 2023-04-01. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Denial of Service (DoS)
[SNYK-JAVA-ORGAPACHETHRIFT-474610](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-474610) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | XML External Entity (XXE) Injection
[SNYK-JAVA-ORGAPACHEJENA-1586035](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-1586035) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | XML External Entity (XXE) Injection
[SNYK-JAVA-ORGAPACHEJENA-2808937](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-2808937) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | XML External Entity (XXE) Injection
[SNYK-JAVA-ORGAPACHEJENA-1586046](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-1586046) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Denial of Service (DoS)
[SNYK-JAVA-XERCES-2359991](https://snyk.io/vuln/SNYK-JAVA-XERCES-2359991) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Denial of Service (DoS)
[SNYK-JAVA-ORGAPACHETHRIFT-1074898](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-1074898) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Authentication Bypass
[SNYK-JAVA-ORGAPACHETHRIFT-451680](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-451680) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Denial of Service (DoS)
[SNYK-JAVA-XERCES-31585](https://snyk.io/vuln/SNYK-JAVA-XERCES-31585) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Insufficient Validation
[SNYK-JAVA-ORGAPACHETHRIFT-564358](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-564358) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
[SNYK-JAVA-ORGAPACHEJENA-5458967](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEJENA-5458967) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Denial of Service (DoS)
[SNYK-JAVA-XERCES-30183](https://snyk.io/vuln/SNYK-JAVA-XERCES-30183) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Improper Access Control
[SNYK-JAVA-ORGAPACHETHRIFT-173706](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETHRIFT-173706) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit | Improper Input Validation
[SNYK-JAVA-XERCES-608891](https://snyk.io/vuln/SNYK-JAVA-XERCES-608891) | **635/1000**
**Why?** Has a fix available, CVSS 8.2 | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/anbo-de/project/afdcc669-8063-47e4-a68d-1f665311554e/settings/integration?pkg=org.springdoc:springdoc-openapi-data-rest&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)