core-geonetwork icon indicating copy to clipboard operation
core-geonetwork copied to clipboard

[Snyk] Upgrade org.apache.activemq:activemq-pool from 5.6.0 to 5.18.0

Open snyk-bot opened this issue 2 years ago • 1 comments

Snyk has created this PR to upgrade org.apache.activemq:activemq-pool from 5.6.0 to 5.18.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 57 versions ahead of your current version.
  • The recommended version was released a month ago, on 2023-03-18.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Improper Authentication
SNYK-JAVA-ORGAPACHEACTIVEMQ-30487
365/1000
Why? CVSS 7.3
No Known Exploit
XML External Entity (XXE) Injection
SNYK-JAVA-ORGCODEHAUSJACKSON-534878
365/1000
Why? CVSS 7.3
No Known Exploit
Privilege Escalation
SNYK-JAVA-ORGMORTBAYJETTY-1021919
365/1000
Why? CVSS 7.3
Proof of Concept
Insecure Default
SNYK-JAVA-ANT-1316199
365/1000
Why? CVSS 7.3
No Known Exploit
Improper Authentication
SNYK-JAVA-ORGAPACHEACTIVEMQ-30486
365/1000
Why? CVSS 7.3
No Known Exploit
Cryptographic Issues
SNYK-JAVA-ORGMORTBAYJETTY-173762
365/1000
Why? CVSS 7.3
No Known Exploit
Improper Authentication
SNYK-JAVA-ORGAPACHEHADOOP-30629
365/1000
Why? CVSS 7.3
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJACKSON-3038425
365/1000
Why? CVSS 7.3
Proof of Concept
Denial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJACKSON-3038427
365/1000
Why? CVSS 7.3
Proof of Concept
Arbitrary Code Injection
SNYK-JAVA-ORGFUSESOURCEHAWTJNI-30093
365/1000
Why? CVSS 7.3
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGFUSESOURCEMQTTCLIENT-1046568
365/1000
Why? CVSS 7.3
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ANT-1317065
365/1000
Why? CVSS 7.3
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ANT-1317066
365/1000
Why? CVSS 7.3
No Known Exploit
Cryptographic Weakness
SNYK-JAVA-ORGAPACHEHADOOP-31574
365/1000
Why? CVSS 7.3
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGCODEHAUSJACKSON-3326362
365/1000
Why? CVSS 7.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

snyk-bot avatar Apr 22 '23 18:04 snyk-bot

CLA assistant check
All committers have signed the CLA.

CLAassistant avatar Dec 08 '24 03:12 CLAassistant