secor
secor copied to clipboard
[Snyk] Fix for 10 vulnerabilities
Snyk has created this PR to fix 10 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xml
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | Upgrade | |
|---|---|---|---|
| Denial of Service (DoS) SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424 |
146 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 Proof of Concept |
|
| Denial of Service (DoS) SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426 |
146 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 Proof of Concept |
|
| Denial of Service (DoS) SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538 |
125 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
|
| Improper Verification of Cryptographic Signature SNYK-JAVA-COMGOOGLEOAUTHCLIENT-2807808 |
124 | com.google.cloud:google-cloud-storage: 1.117.1 -> 2.6.1 Major version upgrade No Known Exploit |
|
| Denial of Service (DoS) SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244 |
114 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
|
| Allocation of Resources Without Limits or Throttling SNYK-JAVA-SOFTWAREAMAZONION-6153869 |
114 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
|
| Denial of Service (DoS) SNYK-JAVA-COMFASTERXMLJACKSONCORE-2326698 |
101 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
|
| Information Exposure SNYK-JAVA-COMFASTERXMLJACKSONCORE-10332631 |
55 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 Proof of Concept |
|
| Directory Traversal SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-31517 |
46 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
|
| Improper Input Validation SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1048058 |
45 | com.amazonaws:aws-java-sdk-s3: 1.12.211 -> 1.12.787 No Known Exploit |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Information Exposure 🦉 Denial of Service (DoS) 🦉 Improper Input Validation 🦉 More lessons are available in Snyk Learn