jvlstuff / Cx-JVL

GNU General Public License v2.0
0 stars 0 forks source link

[Snyk] Fix for 31 vulnerabilities #52

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
critical severity 876/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-30078
org.hibernate:hibernate-core:
4.0.1.Final -> 5.4.24.Final
No Mature
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-472711
org.hibernate:hibernate-core:
4.0.1.Final -> 5.4.24.Final
No Proof of Concept
high severity 655/1000
Why? Has a fix available, CVSS 8.6
HTTP Request Smuggling
SNYK-JAVA-IOUNDERTOW-1012559
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JAVA-IOUNDERTOW-1304915
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Information Exposure
SNYK-JAVA-IOUNDERTOW-174583
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-IOUNDERTOW-2391283
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
medium severity /1000
Why?
Denial of Service (DoS)
SNYK-JAVA-IOUNDERTOW-2847922
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
critical severity 704/1000
Why? Has a fix available, CVSS 9.8
Information Exposure
SNYK-JAVA-IOUNDERTOW-451626
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
medium severity 454/1000
Why? Has a fix available, CVSS 4.8
Information Exposure
SNYK-JAVA-IOUNDERTOW-471684
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
high severity 801/1000
Why? Mature exploit, Has a fix available, CVSS 8.3
Arbitrary File Upload
SNYK-JAVA-IOUNDERTOW-567770
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No Mature
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-IOUNDERTOW-568918
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
high severity 605/1000
Why? Has a fix available, CVSS 7.6
HTTP Request Smuggling
SNYK-JAVA-IOUNDERTOW-570455
io.undertow:undertow-core:
2.0.9.Final -> 2.2.15.Final
No No Known Exploit
medium severity 529/1000
Why? Has a fix available, CVSS 6.3
Privilege Escalation
SNYK-JAVA-MYSQL-174574
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
Yes No Known Exploit
medium severity 616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
XML External Entity (XXE) Injection
SNYK-JAVA-MYSQL-1766958
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
Yes Proof of Concept
medium severity 544/1000
Why? Has a fix available, CVSS 6.6
Improper Authorization
SNYK-JAVA-MYSQL-2386864
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
Yes No Known Exploit
high severity 639/1000
Why? Has a fix available, CVSS 8.5
Improper Access Control
SNYK-JAVA-MYSQL-31399
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
No No Known Exploit
low severity 379/1000
Why? Has a fix available, CVSS 3.3
Improper Access Control
SNYK-JAVA-MYSQL-31449
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
No No Known Exploit
medium severity 534/1000
Why? Has a fix available, CVSS 6.4
Arbitrary Code Execution
SNYK-JAVA-MYSQL-31580
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
No No Known Exploit
medium severity 656/1000
Why? Mature exploit, Has a fix available, CVSS 5.4
SQL Injection
SNYK-JAVA-MYSQL-451460
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
No Mature
high severity 654/1000
Why? Has a fix available, CVSS 8.8
Access Control Bypass
SNYK-JAVA-MYSQL-451464
mysql:mysql-connector-java:
5.1.26 -> 8.0.28
Yes No Known Exploit
medium severity 494/1000
Why? Has a fix available, CVSS 5.6
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCAT-1017114
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCAT-1316668
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCAT-1728262
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No No Known Exploit
medium severity 509/1000
Why? Has a fix available, CVSS 5.9
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCAT-1728263
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No No Known Exploit
high severity 826/1000
Why? Currently trending on Twitter, Mature exploit, Has a fix available, CVSS 8.3
Arbitrary File Upload
SNYK-JAVA-ORGAPACHETOMCAT-551990
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No Mature
high severity 826/1000
Why? Currently trending on Twitter, Mature exploit, Has a fix available, CVSS 8.3
Arbitrary File Upload
SNYK-JAVA-ORGAPACHETOMCAT-551994
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No Mature
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCAT-574692
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCAT-584421
org.apache.tomcat:tomcat-coyote:
9.0.22 -> 9.0.48
No No Known Exploit
high severity 635/1000
Why? Has a fix available, CVSS 8.2
SQL Injection
SNYK-JAVA-ORGHIBERNATE-1041788
org.hibernate:hibernate-core:
4.0.1.Final -> 5.4.24.Final
Yes No Known Exploit
high severity 619/1000
Why? Has a fix available, CVSS 8.1
SQL Injection
SNYK-JAVA-ORGHIBERNATE-584563
org.hibernate:hibernate-core:
4.0.1.Final -> 5.4.24.Final
Yes No Known Exploit
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGJSON-2841369
org.json:json:
20131018 -> 20180130
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Deserialization of Untrusted Data 🦉 Deserialization of Untrusted Data 🦉 SQL Injection 🦉 More lessons are available in Snyk Learn