elkman / keycloak-radius-plugin

Make the radius server as part of keycloak SSO
Apache License 2.0
11 stars 3 forks source link

[Snyk] Upgrade org.keycloak:keycloak-authz-client from 23.0.6 to 24.0.3 #125

Closed elkman closed 1 month ago

elkman commented 1 month ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade org.keycloak:keycloak-authz-client from 23.0.6 to 24.0.3.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
*Warning:* This is a major version upgrade, and may be a breaking change. - The recommended version is **5 versions** ahead of your current version. - The recommended version was released **a month ago**, on 2024-04-16. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Cross-site Scripting (XSS)
[SNYK-JAVA-ORGKEYCLOAK-6618061](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618061) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Origin Validation Error
[SNYK-JAVA-ORGKEYCLOAK-6631362](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6631362) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Path Traversal
[SNYK-JAVA-ORGKEYCLOAK-6618056](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618056) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Path Traversal
[SNYK-JAVA-ORGKEYCLOAK-6618057](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618057) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Open Redirect
[SNYK-JAVA-ORGKEYCLOAK-6618058](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618058) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Arbitrary Code Execution
[SNYK-JAVA-ORGYAML-3152153](https://snyk.io/vuln/SNYK-JAVA-ORGYAML-3152153) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | Proof of Concept | Missing Critical Step in Authentication
[SNYK-JAVA-ORGKEYCLOAK-6616016](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6616016) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Missing Critical Step in Authentication
[SNYK-JAVA-ORGKEYCLOAK-6616017](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6616017) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Authorization Bypass Through User-Controlled Key
[SNYK-JAVA-ORGKEYCLOAK-6618054](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618054) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit | Authentication Bypass
[SNYK-JAVA-ORGKEYCLOAK-6618060](https://snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6618060) | **584/1000**
**Why?** Has a fix available, CVSS 7.4 | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/elkman/project/90d5ab00-9f45-4704-a996-07c75e2e1723?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/elkman/project/90d5ab00-9f45-4704-a996-07c75e2e1723/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/elkman/project/90d5ab00-9f45-4704-a996-07c75e2e1723/settings/integration?pkg=org.keycloak:keycloak-authz-client&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)
elkman commented 1 month ago

superseded by Keycloak 24.0.4