topcoder-platform / tc-project-service

16 stars 55 forks source link

[Snyk] Security upgrade org.apache.jmeter:ApacheJMeter_core from 5.1 to 5.4.3 #727

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity Reachability
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 705/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Mature No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 675/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Mature No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 563/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
low severity 335/1000
Why? Has a fix available, CVSS 3.7
Information Exposure
SNYK-JAVA-COMMONSCODEC-561518
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 535/1000
Why? Mature exploit, Has a fix available, CVSS 5.3
Directory Traversal
SNYK-JAVA-COMMONSIO-1277109
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Mature No Path Found
high severity 655/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.6
Deserialization of Untrusted Data
SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1040458
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
medium severity 490/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Arbitrary File Deletion
SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1051966
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
medium severity 595/1000
Why? Mature exploit, Has a fix available, CVSS 6.5
Server-Side Request Forgery (SSRF)
SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1051967
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Mature No Path Found
low severity 370/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 2.9
Information Exposure
SNYK-JAVA-JUNIT-1017047
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 560/1000
Why? Has a fix available, CVSS 8.2
Denial of Service (DoS)
SNYK-JAVA-NETMINIDEV-1078499
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-NETMINIDEV-1298655
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHECOMMONS-460507
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
low severity 300/1000
Why? Has a fix available, CVSS 3
Information Exposure
SNYK-JAVA-ORGAPACHECOMMONS-559327
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 483/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHECXF-480439
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 475/1000
Why? Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHECXF-542666
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1048058
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
critical severity 833/1000
Why? Currently trending on Twitter, Mature exploit, Has a fix available, CVSS 10
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2314720
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Mature No Path Found
critical severity 675/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
medium severity 555/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.6
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
low severity 335/1000
Why? Has a fix available, CVSS 3.7
Man-in-the-Middle (MitM)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-567761
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 400/1000
Why? Has a fix available, CVSS 5
XML External Entity (XXE) Injection
SNYK-JAVA-ORGAPACHEPOI-548686
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
low severity 335/1000
Why? Has a fix available, CVSS 3.7
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETIKA-1038323
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Stack Overflow
SNYK-JAVA-ORGAPACHETIKA-456557
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 445/1000
Why? Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETIKA-456559
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETIKA-560935
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETIKA-560936
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETIKA-567759
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Information Exposure
SNYK-JAVA-ORGBOUNCYCASTLE-1035561
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Timing Attack
SNYK-JAVA-ORGBOUNCYCASTLE-1296075
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Server-side Template Injection (SSTI)
SNYK-JAVA-ORGFREEMARKER-1076795
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No Proof of Concept No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGJSOUP-1567345
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found
high severity 568/1000
Why? Has a fix available, CVSS 8.2
XML External Entity (XXE) Injection
SNYK-JAVA-ORGMOZILLA-1314295
org.apache.jmeter:ApacheJMeter_core:
5.1 -> 5.4.3
No No Known Exploit No Path Found

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Arbitrary File Deletion 🦉 Server-Side Request Forgery (SSRF) 🦉 Cross-site Scripting (XSS) 🦉 More lessons are available in Snyk Learn