orion
orion copied to clipboard
[Snyk] Security upgrade io.dropwizard:dropwizard-core from 1.3.17 to 3.0.4
Snyk has created this PR to fix 8 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
orion-server/pom.xml
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | Upgrade | |
|---|---|---|---|
| Denial of Service (DoS) SNYK-JAVA-ORGECLIPSEJETTY-1090340 |
177 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade Proof of Concept |
|
| Information Exposure SNYK-JAVA-ORGECLIPSEJETTY-1300835 |
117 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade Proof of Concept |
|
| Denial of Service (DoS) SNYK-JAVA-ORGECLIPSEJETTY-5958847 |
115 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade No Known Exploit |
|
| Improper Handling of Length Parameter Inconsistency SNYK-JAVA-ORGECLIPSEJETTY-5902998 |
65 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade Proof of Concept |
|
| Arbitrary Code Execution SNYK-JAVA-ORGECLIPSEJETTY-5903003 |
55 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade Proof of Concept |
|
| Denial of Service (DoS) SNYK-JAVA-ORGECLIPSEJETTY-8186168 |
49 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade No Known Exploit |
|
| Information Exposure SNYK-JAVA-ORGECLIPSEJETTY-5426161 |
47 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade Proof of Concept |
|
| Improper Input Validation SNYK-JAVA-ORGECLIPSEJETTY-2945452 |
40 | io.dropwizard:dropwizard-core: 1.3.17 -> 3.0.4 Major version upgrade No Known Exploit |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons: