DeepViolet
DeepViolet copied to clipboard
[Snyk] Security upgrade ch.qos.logback:logback-classic from 1.2.3 to 1.5.13
Snyk has created this PR to fix 3 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
-
pom.xml
Vulnerabilities that will be fixed with an upgrade:
Issue | Score | Upgrade | |
---|---|---|---|
![]() |
Improper Neutralization of Special Elements SNYK-JAVA-CHQOSLOGBACK-8539866 |
581 | ch.qos.logback:logback-classic: 1.2.3 -> 1.5.13 No Known Exploit |
![]() |
Improper Neutralization of Special Elements SNYK-JAVA-CHQOSLOGBACK-8539867 |
581 | ch.qos.logback:logback-classic: 1.2.3 -> 1.5.13 No Known Exploit |
![]() |
Server-side Request Forgery (SSRF) SNYK-JAVA-CHQOSLOGBACK-8539865 |
406 | ch.qos.logback:logback-classic: 1.2.3 -> 1.5.13 No Known Exploit |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons: