[Snyk] Security upgrade com.github.binarywang:weixin-java-mp from 3.4.0 to 4.6.1.B #123
Security Report
You have successfully remediated 5 vulnerabilities, but introduced 12 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-20873Path to dependency file: /black-shop-common/black-shop-common-security/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-security/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> spring-cloud-starter-security-2.0.2.RELEASE.jar (Root Library) -> spring-boot-starter-actuator-2.0.9.RELEASE.jar -> ❌ spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-actuator-autoconfigure:2.7.11,3.0.6 | None |
WS-2021-0419Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:2.8.9 | None |
CVE-2023-20883Path to dependency file: /black-shop-common/black-shop-common-security/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-auth/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-gateway/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> ❌ spring-boot-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-boot-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-autoconfigure:2.5.12,2.6.12,2.7.12,3.0.7 | None |
CVE-2022-25647Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.5 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:gson-parent-2.8.9 | None |
CVE-2022-0084Path to dependency file: /black-shop-common/black-shop-common-web/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-web/pom.xml,/black-shop-auth/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> undertow-core-1.4.27.Final.jar -> ❌ xnio-api-3.3.8.Final.jar (Vulnerable Library) |
High | 7.5 | xnio-api-3.3.8.Final.jar | Upgrade to version: org.jboss.xnio:xnio-api:3.8.8.Final | None |
CVE-2021-3690Path to dependency file: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml Path to vulnerable library: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ undertow-websockets-jsr-1.4.27.Final.jar (Vulnerable Library) |
High | 7.5 | undertow-websockets-jsr-1.4.27.Final.jar | Upgrade to version: io.undertow:undertow-websockets-jsr:2.0.40.Final, 2.2.10.Final | None |
CVE-2019-10219Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-gateway/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-auth/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: 6.0.18.Final | None |
CVE-2022-22946Path to dependency file: /black-shop-gateway/pom.xml Path to vulnerable library: /black-shop-gateway/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> ❌ spring-cloud-gateway-core-2.0.4.RELEASE.jar (Vulnerable Library) |
Medium | 5.5 | spring-cloud-gateway-core-2.0.4.RELEASE.jar | Upgrade to version: org.springframework.cloud:spring-cloud-gateway-server:3.1.1 | None |
CVE-2022-22968Path to dependency file: /black-shop-common/black-shop-common-feign/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-feign/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-auth/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> spring-boot-2.0.9.RELEASE.jar -> ❌ spring-context-5.0.13.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-context-5.0.13.RELEASE.jar | Upgrade to version: org.springframework:spring-context:5.2.21,5.3.19 | None |
CVE-2021-28170Path to dependency file: /black-shop-portal/black-shop-portal-web/pom.xml Path to vulnerable library: /black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ javax.el-3.0.0.jar (Vulnerable Library) |
Medium | 5.3 | javax.el-3.0.0.jar | Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 | None |
CVE-2020-10693Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-gateway/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-auth/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 5.3 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate:hibernate-validator:6.0.20.Final,6.1.5.Final | None |
CVE-2021-29425Path to dependency file: /black-shop-basic/black-shop-basic-apolloconfig/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
Medium | 4.8 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.7 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2019-11269 | spring-security-oauth2-2.2.3.RELEASE.jar |
CVE-2019-3778 | spring-security-oauth2-2.2.3.RELEASE.jar |
WS-2021-0419 | com-google-gson-RELEASE113.jar |
CVE-2022-25647 | com-google-gson-RELEASE113.jar |
CVE-2021-29425 | org-apache-commons-io-RELEASE113.jar |
Base branch total remaining vulnerabilities: 209
Base branch commit: null
Total libraries scanned: 275
Scan token: b434aa2139d743db960b04bdbdd67391