core-geonetwork
core-geonetwork copied to clipboard
[Snyk] Upgrade org.apache.activemq:activemq-pool from 5.6.0 to 5.18.0
Snyk has created this PR to upgrade org.apache.activemq:activemq-pool from 5.6.0 to 5.18.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is 57 versions ahead of your current version.
- The recommended version was released a month ago, on 2023-03-18.
The recommended version fixes:
| Severity | Issue | PriorityScore (*) | Exploit Maturity |
|---|---|---|---|
| Improper Authentication SNYK-JAVA-ORGAPACHEACTIVEMQ-30487 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| XML External Entity (XXE) Injection SNYK-JAVA-ORGCODEHAUSJACKSON-534878 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Privilege Escalation SNYK-JAVA-ORGMORTBAYJETTY-1021919 |
365/1000 Why? CVSS 7.3 |
Proof of Concept | |
| Insecure Default SNYK-JAVA-ANT-1316199 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Improper Authentication SNYK-JAVA-ORGAPACHEACTIVEMQ-30486 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Cryptographic Issues SNYK-JAVA-ORGMORTBAYJETTY-173762 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Improper Authentication SNYK-JAVA-ORGAPACHEHADOOP-30629 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Denial of Service (DoS) SNYK-JAVA-ORGCODEHAUSJACKSON-3038425 |
365/1000 Why? CVSS 7.3 |
Proof of Concept | |
| Denial of Service (DoS) SNYK-JAVA-ORGCODEHAUSJACKSON-3038427 |
365/1000 Why? CVSS 7.3 |
Proof of Concept | |
| Arbitrary Code Injection SNYK-JAVA-ORGFUSESOURCEHAWTJNI-30093 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Denial of Service (DoS) SNYK-JAVA-ORGFUSESOURCEMQTTCLIENT-1046568 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Denial of Service (DoS) SNYK-JAVA-ANT-1317065 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Denial of Service (DoS) SNYK-JAVA-ANT-1317066 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Cryptographic Weakness SNYK-JAVA-ORGAPACHEHADOOP-31574 |
365/1000 Why? CVSS 7.3 |
No Known Exploit | |
| Improper Input Validation SNYK-JAVA-ORGCODEHAUSJACKSON-3326362 |
365/1000 Why? CVSS 7.3 |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🔕 Ignore this dependency or unsubscribe from future upgrade PRs