Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 8.2
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31507
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31520
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31573
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
Why? Mature exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
Why? Has a fix available, CVSS 8.1
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
Why? Proof of Concept exploit, Has a fix available, CVSS 5.5
SNYK-JAVA-COMGOOGLEGUAVA-1015415
com.google.guava:guava:
14.0.1 -> 30.0-android
Why? Has a fix available, CVSS 5.9
SNYK-JAVA-COMGOOGLEGUAVA-32236
com.google.guava:guava:
14.0.1 -> 30.0-android
Why? Has a fix available, CVSS 3.7
SNYK-JAVA-COMMONSCODEC-561518
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-IONETTY-30430
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
SNYK-JAVA-IONETTY-473214
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-IONETTY-559515
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-IONETTY-559516
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-IOSPRAY-474268
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-IOSPRAY-474270
Why? Has a fix available, CVSS 5.9
SNYK-JAVA-IOSPRAY-474272
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-ORGAPACHEHADOOP-174575
Why? Has a fix available, CVSS 6.5
SNYK-JAVA-ORGAPACHEHADOOP-174576
Why? Has a fix available, CVSS 9.8
SNYK-JAVA-ORGAPACHEHADOOP-30627
Why? Has a fix available, CVSS 5.5
SNYK-JAVA-ORGAPACHEHADOOP-30631
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-31517
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHEMESOS-1585620
Why? Has a fix available, CVSS 5.4
SNYK-JAVA-ORGAPACHESPARK-1298181
Why? Has a fix available, CVSS 6.1
SNYK-JAVA-ORGAPACHESPARK-1298185
Why? Has a fix available, CVSS 7.8
SNYK-JAVA-ORGAPACHESPARK-1298187
Why? Has a fix available, CVSS 6.1
SNYK-JAVA-ORGAPACHESPARK-31463
Why? Has a fix available, CVSS 7.8
SNYK-JAVA-ORGAPACHESPARK-31575
Why? Has a fix available, CVSS 4.7
SNYK-JAVA-ORGAPACHESPARK-31695
Why? Has a fix available, CVSS 9.8
SNYK-JAVA-ORGAPACHESPARK-573164
Why? Has a fix available, CVSS 4.4
SNYK-JAVA-ORGAPACHESPARK-574943
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHESPARK-72494
Why? Has a fix available, CVSS 6.5
SNYK-JAVA-ORGAPACHETHRIFT-564358
Why? Proof of Concept exploit, Has a fix available, CVSS 4.3
SNYK-JAVA-ORGAPACHEZOOKEEPER-174781
Why? Has a fix available, CVSS 4
SNYK-JAVA-ORGAPACHEZOOKEEPER-31035
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGAPACHEZOOKEEPER-32301
Why? Proof of Concept exploit, Has a fix available, CVSS 7.8
SNYK-JAVA-ORGECLIPSEJETTY-1021614
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-ORGECLIPSEJETTY-1090340
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-ORGECLIPSEJETTY-1300835
Why? Has a fix available, CVSS 2.9
SNYK-JAVA-ORGECLIPSEJETTY-1313686
Why? Mature exploit, Has a fix available, CVSS 4.7
SNYK-JAVA-ORGECLIPSEJETTY-174479
Why? Has a fix available, CVSS 5.3
SNYK-JAVA-ORGECLIPSEJETTY-174560
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGECLIPSEJETTY-32151
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGECLIPSEJETTY-32383
Why? Has a fix available, CVSS 9.8
SNYK-JAVA-ORGECLIPSEJETTY-32385
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGECLIPSEJETTY-460763
Why? Mature exploit, Has a fix available, CVSS 4.7
SNYK-JAVA-ORGECLIPSEJETTY-480557
Why? Has a fix available, CVSS 7.5
SNYK-JAVA-ORGGLASSFISHJERSEYMEDIA-595972
(*) Note that the real score may have changed since the PR was raised.
Vulnerabilities that could not be fixed
org.apache.spark:[email protected]
toorg.apache.spark:[email protected]
; Reasoncould not apply upgrade, dependency is managed externally
; Location:provenance does not contain location
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic