twilio / starter-java

A starter app for Java developers embarking on their first Twilio quest!
MIT License
22 stars 37 forks source link

[Snyk] Fix for 50 vulnerabilities #47

Open twilio-product-security opened 11 months ago

twilio-product-security commented 11 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - pom.xml #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Upgrade | Breaking Change | Exploit Maturity | Reachability :-------------------------:|-------------------------|:-------------------------|:-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **560/1000**
**Why?** Has a fix available, CVSS 8.2 | XML External Entity (XXE) Injection
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **525/1000**
**Why?** Has a fix available, CVSS 7.5 | Denial of Service (DoS)
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **520/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.9 | Denial of Service (DoS)
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **520/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.9 | Denial of Service (DoS)
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **520/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.9 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **705/1000**
**Why?** Mature exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Mature | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **675/1000**
**Why?** Mature exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Mature | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **555/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **563/1000**
**Why?** Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | No Known Exploit | No Path Found ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **630/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 8.1 | Deserialization of Untrusted Data
[SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664) | `com.twilio.sdk:twilio:`
`7.40.1 -> 7.47.4`
| No | Proof of Concept | No Path Found ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **345/1000**
**Why?** Has a fix available, CVSS 3.9 | XML External Entity (XXE) Injection
[SNYK-JAVA-ORGECLIPSEJETTY-5769685](https://snyk.io/vuln/SNYK-JAVA-ORGECLIPSEJETTY-5769685) | `com.sparkjava:spark-core:`
`2.7.2 -> 2.9.4`
| No | No Known Exploit | No Path Found (*) Note that the real score may have changed since the PR was raised. Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/twilio-47w/project/b12842e4-31be-48be-9fe7-08de0e23492c?utm_source=github-enterprise&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/twilio-47w/project/b12842e4-31be-48be-9fe7-08de0e23492c?utm_source=github-enterprise&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"eed3e5bf-2b96-4f72-88f4-687dd7890a7e","prPublicId":"eed3e5bf-2b96-4f72-88f4-687dd7890a7e","dependencies":[{"name":"com.sparkjava:spark-core","from":"2.7.2","to":"2.9.4"},{"name":"com.twilio.sdk:twilio","from":"7.40.1","to":"7.47.4"}],"packageManager":"maven","projectPublicId":"b12842e4-31be-48be-9fe7-08de0e23492c","projectUrl":"https://app.snyk.io/org/twilio-47w/project/b12842e4-31be-48be-9fe7-08de0e23492c?utm_source=github-enterprise&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931","SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244","SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424","SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426","SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207","SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917","SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016","SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674","SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676","SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943","SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980","SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500","SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451","SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094","SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106","SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762","SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587","SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887","SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888","SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316","SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664","SNYK-JAVA-ORGECLIPSEJETTY-5769685"],"upgrade":["SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427","SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931","SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244","SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424","SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426","SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207","SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917","SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015","SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016","SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674","SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676","SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943","SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980","SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500","SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451","SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094","SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106","SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762","SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586","SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587","SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887","SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888","SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314","SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316","SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664","SNYK-JAVA-ORGECLIPSEJETTY-5769685"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[563,563,560,555,555,630,563,630,563,630,563,630,630,563,563,630,630,555,525,520,520,520,705,555,555,675,563,555,555,555,555,555,630,630,630,630,563,563,563,630,563,563,563,563,563,563,563,563,630,345],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Deserialization of Untrusted Data](https://learn.snyk.io/lesson/insecure-deserialization/?loc=fix-pr) 🦉 [XML External Entity (XXE) Injection](https://learn.snyk.io/lesson/xxe/?loc=fix-pr) 🦉 [Denial of Service (DoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr)