[Snyk] Security upgrade com.spring4all:swagger-spring-boot-starter from 1.8.0.RELEASE to 2.0.0.RELEASE #113
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-20873Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator-autoconfigure/2.0.9.RELEASE/spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator-autoconfigure/2.0.9.RELEASE/spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar Dependency Hierarchy: -> spring-cloud-starter-security-2.0.2.RELEASE.jar (Root Library) -> spring-boot-starter-actuator-2.0.9.RELEASE.jar -> ❌ spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-actuator-autoconfigure:2.7.11,3.0.6 | None |
CVE-2020-10683Path to dependency file: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/dom4j/dom4j/2.1.1/dom4j-2.1.1.jar Dependency Hierarchy: -> weixin-java-mp-3.4.0.jar (Root Library) -> weixin-java-common-3.4.0.jar -> ❌ dom4j-2.1.1.jar (Vulnerable Library) |
Critical | 9.8 | dom4j-2.1.1.jar | Upgrade to version: org.dom4j:dom4j:2.1.3,org.dom4j:dom4j:2.0.3 | None |
WS-2021-0419Path to dependency file: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:2.8.9 | None |
CVE-2023-3635Path to dependency file: /black-shop-common/black-shop-common-util/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar,/home/wss-scanner/.m2/repository/com/squareup/okio/okio/1.13.0/okio-1.13.0.jar Dependency Hierarchy: -> feign-okhttp-9.7.0.jar (Root Library) -> okhttp-3.8.1.jar -> ❌ okio-1.13.0.jar (Vulnerable Library) |
High | 7.5 | okio-1.13.0.jar | Upgrade to version: com.squareup.okio:okio-jvm:3.4.0 | None |
CVE-2023-20883Path to dependency file: /black-shop-basic/black-shop-basic-scheduler/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.0.9.RELEASE/spring-boot-autoconfigure-2.0.9.RELEASE.jar Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> ❌ spring-boot-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-boot-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-autoconfigure:2.5.12,2.6.12,2.7.12,3.0.7 | None |
CVE-2022-25647Path to dependency file: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.5 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:gson-parent-2.8.9 | None |
CVE-2022-0084Path to dependency file: /black-shop-portal/black-shop-portal-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/jboss/xnio/xnio-api/3.3.8.Final/xnio-api-3.3.8.Final.jar,/home/wss-scanner/.m2/repository/org/jboss/xnio/xnio-api/3.3.8.Final/xnio-api-3.3.8.Final.jar,/home/wss-scanner/.m2/repository/org/jboss/xnio/xnio-api/3.3.8.Final/xnio-api-3.3.8.Final.jar,/home/wss-scanner/.m2/repository/org/jboss/xnio/xnio-api/3.3.8.Final/xnio-api-3.3.8.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> undertow-core-1.4.27.Final.jar -> ❌ xnio-api-3.3.8.Final.jar (Vulnerable Library) |
High | 7.5 | xnio-api-3.3.8.Final.jar | Upgrade to version: org.jboss.xnio:xnio-api:3.8.8.Final | None |
CVE-2021-3690Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-websockets-jsr/1.4.27.Final/undertow-websockets-jsr-1.4.27.Final.jar,/home/wss-scanner/.m2/repository/io/undertow/undertow-websockets-jsr/1.4.27.Final/undertow-websockets-jsr-1.4.27.Final.jar,/home/wss-scanner/.m2/repository/io/undertow/undertow-websockets-jsr/1.4.27.Final/undertow-websockets-jsr-1.4.27.Final.jar,/home/wss-scanner/.m2/repository/io/undertow/undertow-websockets-jsr/1.4.27.Final/undertow-websockets-jsr-1.4.27.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ undertow-websockets-jsr-1.4.27.Final.jar (Vulnerable Library) |
High | 7.5 | undertow-websockets-jsr-1.4.27.Final.jar | Upgrade to version: io.undertow:undertow-websockets-jsr:2.0.40.Final, 2.2.10.Final | None |
WS-2019-0379Path to dependency file: /black-shop-basic/black-shop-basic-scheduler/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar,/home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.11/commons-codec-1.11.jar Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-alibaba-nacos-discovery-0.2.2.RELEASE.jar -> spring-cloud-alibaba-nacos-discovery-0.2.2.RELEASE.jar -> nacos-client-1.0.0.jar -> ❌ commons-codec-1.11.jar (Vulnerable Library) |
Medium | 6.5 | commons-codec-1.11.jar | Upgrade to version: commons-codec:commons-codec:1.13 | None |
CVE-2019-10219Path to dependency file: /black-shop-basic/black-shop-basic-scheduler/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: 6.0.18.Final | None |
CVE-2022-22946Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> ❌ spring-cloud-gateway-core-2.0.4.RELEASE.jar (Vulnerable Library) |
Medium | 5.5 | spring-cloud-gateway-core-2.0.4.RELEASE.jar | Upgrade to version: org.springframework.cloud:spring-cloud-gateway-server:3.1.1 | None |
CVE-2022-22968Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar,/home/wss-scanner/.m2/repository/org/springframework/spring-context/5.0.13.RELEASE/spring-context-5.0.13.RELEASE.jar Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> spring-boot-2.0.9.RELEASE.jar -> ❌ spring-context-5.0.13.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-context-5.0.13.RELEASE.jar | Upgrade to version: org.springframework:spring-context:5.2.21,5.3.19 | None |
CVE-2020-10693Path to dependency file: /black-shop-basic/black-shop-basic-scheduler/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar,/home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.16.Final/hibernate-validator-6.0.16.Final.jar Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 5.3 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate:hibernate-validator:6.0.20.Final,6.1.5.Final | None |
CVE-2021-29425Path to dependency file: /black-shop-basic/black-shop-basic-apolloconfig/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar,/home/wss-scanner/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
Medium | 4.8 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.7 | None |
WS-2020-0407Path to dependency file: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar,/home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar,/home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar,/home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar,/home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar,/home/wss-scanner/.m2/repository/io/springfox/springfox-swagger2/3.0.0/springfox-swagger2-3.0.0.jar Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> swagger-spring-boot-starter-2.0.0.RELEASE.jar -> springfox-boot-starter-3.0.0.jar -> ❌ springfox-swagger2-3.0.0.jar (Vulnerable Library) |
Medium | 4.3 | springfox-swagger2-3.0.0.jar | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
WS-2021-0419 | com-google-gson-RELEASE113.jar |
CVE-2022-25647 | com-google-gson-RELEASE113.jar |
Base branch total remaining vulnerabilities: 200
Base branch commit: null
Total libraries scanned: 292
Scan token: c6b84aa3d5b848d1a803a0501af305c6