[Snyk] Fix for 4 vulnerabilities #132
Security Report
You have successfully remediated 41 vulnerabilities, but introduced 13 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-20873Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /black-shop-auth/pom.xml,/black-shop-common/black-shop-common-security/pom.xml Dependency Hierarchy: -> spring-cloud-starter-security-2.0.2.RELEASE.jar (Root Library) -> spring-boot-starter-actuator-2.0.9.RELEASE.jar -> ❌ spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-actuator-autoconfigure:2.7.11,3.0.6 | None |
CVE-2020-10683Path to dependency file: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Path to vulnerable library: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Dependency Hierarchy: -> weixin-java-mp-3.4.0.jar (Root Library) -> weixin-java-common-3.4.0.jar -> ❌ dom4j-2.1.1.jar (Vulnerable Library) |
Critical | 9.8 | dom4j-2.1.1.jar | Upgrade to version: org.dom4j:dom4j:2.1.3,org.dom4j:dom4j:2.0.3 | None |
WS-2021-0419Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:2.8.9 | None |
CVE-2022-25647Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:gson-parent-2.8.9 | None |
CVE-2024-47554Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /black-shop-auth/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
High | 7.5 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.14.0 | None |
CVE-2023-20883Path to dependency file: /black-shop-gateway/pom.xml Path to vulnerable library: /black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-auth/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> ❌ spring-boot-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-boot-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-autoconfigure:2.5.12,2.6.12,2.7.12,3.0.7 | None |
CVE-2021-3690Path to dependency file: /black-shop-portal/black-shop-portal-web/pom.xml Path to vulnerable library: /black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ undertow-websockets-jsr-1.4.27.Final.jar (Vulnerable Library) |
High | 7.5 | undertow-websockets-jsr-1.4.27.Final.jar | Upgrade to version: io.undertow:undertow-websockets-jsr:2.0.40.Final, 2.2.10.Final | None |
CVE-2023-1932Path to dependency file: /black-shop-basic/black-shop-basic-zipkin/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-auth/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate.validator:hibernate-validator:6.2.0.Final | None |
CVE-2019-10219Path to dependency file: /black-shop-basic/black-shop-basic-zipkin/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-auth/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: 6.0.18.Final | None |
CVE-2022-22946Path to dependency file: /black-shop-gateway/pom.xml Path to vulnerable library: /black-shop-gateway/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> ❌ spring-cloud-gateway-core-2.0.4.RELEASE.jar (Vulnerable Library) |
Medium | 5.5 | spring-cloud-gateway-core-2.0.4.RELEASE.jar | Upgrade to version: org.springframework.cloud:spring-cloud-gateway-server:3.1.1 | None |
CVE-2021-28170Path to dependency file: /black-shop-common/black-shop-common-web/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ javax.el-3.0.0.jar (Vulnerable Library) |
Medium | 5.3 | javax.el-3.0.0.jar | Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 | None |
CVE-2020-10693Path to dependency file: /black-shop-basic/black-shop-basic-zipkin/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-auth/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 5.3 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate:hibernate-validator:6.0.20.Final,6.1.5.Final | None |
CVE-2021-29425Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /black-shop-auth/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-common/black-shop-common-web/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
Medium | 4.8 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.7 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2021-39140 | xstream-1.4.10.jar |
CVE-2013-7285 | xstream-1.4.10.jar |
CVE-2024-47554 | org-apache-commons-io-RELEASE113.jar |
CVE-2021-39154 | xstream-1.4.10.jar |
CVE-2021-21342 | xstream-1.4.10.jar |
CVE-2020-26259 | xstream-1.4.10.jar |
CVE-2021-39148 | xstream-1.4.10.jar |
CVE-2021-39146 | xstream-1.4.10.jar |
CVE-2021-21351 | xstream-1.4.10.jar |
CVE-2021-21350 | xstream-1.4.10.jar |
CVE-2022-40151 | xstream-1.4.10.jar |
CVE-2021-39139 | xstream-1.4.10.jar |
CVE-2021-21347 | xstream-1.4.10.jar |
CVE-2021-21345 | xstream-1.4.10.jar |
CVE-2021-21344 | xstream-1.4.10.jar |
CVE-2021-39149 | xstream-1.4.10.jar |
CVE-2019-11269 | spring-security-oauth2-2.2.3.RELEASE.jar |
CVE-2021-39145 | xstream-1.4.10.jar |
CVE-2024-47072 | xstream-1.4.10.jar |
CVE-2019-3778 | spring-security-oauth2-2.2.3.RELEASE.jar |
CVE-2021-39151 | xstream-1.4.10.jar |
CVE-2021-39152 | xstream-1.4.10.jar |
CVE-2021-43859 | xstream-1.4.10.jar |
CVE-2021-21343 | xstream-1.4.10.jar |
CVE-2021-39147 | xstream-1.4.10.jar |
CVE-2021-39144 | xstream-1.4.10.jar |
CVE-2020-26217 | xstream-1.4.10.jar |
CVE-2021-39150 | xstream-1.4.10.jar |
WS-2021-0419 | com-google-gson-RELEASE113.jar |
CVE-2021-39153 | xstream-1.4.10.jar |
CVE-2021-39141 | xstream-1.4.10.jar |
CVE-2021-21346 | xstream-1.4.10.jar |
CVE-2021-21349 | xstream-1.4.10.jar |
CVE-2021-21348 | xstream-1.4.10.jar |
CVE-2021-29505 | xstream-1.4.10.jar |
CVE-2020-26258 | xstream-1.4.10.jar |
CVE-2021-21341 | xstream-1.4.10.jar |
CVE-2022-25647 | com-google-gson-RELEASE113.jar |
CVE-2022-41966 | xstream-1.4.10.jar |
CVE-2021-29425 | org-apache-commons-io-RELEASE113.jar |
CVE-2019-10173 | xstream-1.4.10.jar |
Base branch total remaining vulnerabilities: 246
Base branch commit: null
Total libraries scanned: 275
Scan token: 1ea89bc6685545f6a11515af7a6448e4