OpenESPI-DataCustodian-java icon indicating copy to clipboard operation
OpenESPI-DataCustodian-java copied to clipboard

[Snyk] Fix for 44 vulnerabilities

Open dfcoffin opened this issue 2 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity Reachability
low severity 390/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.3
Information Disclosure
SNYK-JAVA-COMGOOGLEGUAVA-1015415
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
medium severity 445/1000
Why? Has a fix available, CVSS 5.9
Deserialization of Untrusted Data
SNYK-JAVA-COMGOOGLEGUAVA-32236
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
low severity 315/1000
Why? Has a fix available, CVSS 3.3
Creation of Temporary File in Directory with Insecure Permissions
SNYK-JAVA-COMGOOGLEGUAVA-5710356
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
low severity 335/1000
Why? Has a fix available, CVSS 3.7
Information Exposure
SNYK-JAVA-COMMONSCODEC-561518
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
critical severity 790/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-30078
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Mature No Path Found
medium severity 505/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-472711
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
medium severity 535/1000
Why? Mature exploit, Has a fix available, CVSS 5.3
Directory Traversal
SNYK-JAVA-COMMONSIO-1277109
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Mature No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
XML External Entity (XXE) Injection
SNYK-JAVA-DOM4J-174153
org.hibernate:hibernate-entitymanager:
4.2.1.Final -> 5.1.17.Final
Yes Proof of Concept No Path Found
high severity 520/1000
Why? Has a fix available, CVSS 7.4
XML External Entity (XXE) Injection
SNYK-JAVA-DOM4J-2812975
org.hibernate:hibernate-entitymanager:
4.2.1.Final -> 5.1.17.Final
Yes No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Information Exposure
SNYK-JAVA-IONETTY-30430
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 550/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
HTTP Request Smuggling
SNYK-JAVA-IONETTY-473694
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
low severity 335/1000
Why? Has a fix available, CVSS 3.7
Man-in-the-Middle (MitM)
SNYK-JAVA-LOG4J-1300176
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No No Known Exploit No Path Found
medium severity 555/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.6
Arbitrary Code Execution
SNYK-JAVA-LOG4J-2316893
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No Proof of Concept No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
SQL Injection
SNYK-JAVA-LOG4J-2342645
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342646
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No No Known Exploit No Path Found
high severity 555/1000
Why? Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342647
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No No Known Exploit No Path Found
medium severity 445/1000
Why? Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JAVA-LOG4J-3358774
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No No Known Exploit No Path Found
critical severity 715/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-LOG4J-572732
org.slf4j:slf4j-log4j12:
1.7.5 -> 1.7.34
No Proof of Concept No Path Found
critical severity 715/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
medium severity 438/1000
Why? Has a fix available, CVSS 5.6
Remote Code Execution (RCE)
SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-548471
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-5603110
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-NETSOURCEFORGENEKOHTML-2621454
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 350/1000
Why? Has a fix available, CVSS 4
Memory Allocation with Excessive Size Value
SNYK-JAVA-NETSOURCEFORGENEKOHTML-2774754
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 350/1000
Why? Has a fix available, CVSS 4
Heap-based Buffer Overflow
SNYK-JAVA-NETSOURCEFORGENEKOHTML-2803036
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1048058
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 495/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.4
Man-in-the-Middle (MitM)
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-30646
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
medium severity 365/1000
Why? Has a fix available, CVSS 4.3
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-30647
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Directory Traversal
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-31517
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 520/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJACKSON-3038425
org.springframework.security.oauth:spring-security-oauth2:
2.0.2.RELEASE -> 2.4.0.RELEASE
No Proof of Concept No Path Found
medium severity 520/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Denial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJACKSON-3038427
org.springframework.security.oauth:spring-security-oauth2:
2.0.2.RELEASE -> 2.4.0.RELEASE
No Proof of Concept No Path Found
critical severity 640/1000
Why? Has a fix available, CVSS 9.8
Improper Input Validation
SNYK-JAVA-ORGCODEHAUSJACKSON-3326362
org.springframework.security.oauth:spring-security-oauth2:
2.0.2.RELEASE -> 2.4.0.RELEASE
No No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
XML External Entity (XXE) Injection
SNYK-JAVA-ORGCODEHAUSJACKSON-534878
org.springframework.security.oauth:spring-security-oauth2:
2.0.2.RELEASE -> 2.4.0.RELEASE
No No Known Exploit No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGECLIPSEJETTY-1090340
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
low severity 285/1000
Why? Has a fix available, CVSS 2.7
Improper Input Validation
SNYK-JAVA-ORGECLIPSEJETTY-2945452
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Timing Attack
SNYK-JAVA-ORGECLIPSEJETTY-32151
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
low severity 270/1000
Why? Has a fix available, CVSS 2.4
Information Exposure
SNYK-JAVA-ORGECLIPSEJETTY-5426161
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGJSON-2841369
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGJSON-5488379
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
critical severity 715/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Arbitrary Code Execution
SNYK-JAVA-XALAN-2953385
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No Proof of Concept No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-XERCES-2359991
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 475/1000
Why? Has a fix available, CVSS 6.5
Denial of Service (DoS)
SNYK-JAVA-XERCES-30183
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
high severity 525/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-XERCES-31585
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Denial of Service (DoS)
SNYK-JAVA-XERCES-5920442
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found
medium severity 415/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JAVA-XERCES-608891
org.seleniumhq.selenium:selenium-java:
2.34.0 -> 2.53.0
No No Known Exploit No Path Found

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Creation of Temporary File in Directory with Insecure Permissions 🦉 Deserialization of Untrusted Data 🦉 Directory Traversal 🦉 More lessons are available in Snyk Learn

dfcoffin avatar Oct 03 '23 09:10 dfcoffin