[Snyk] Fix for 4 vulnerabilities #133
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-20873Path to dependency file: /black-shop-common/black-shop-common-security/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-security/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> spring-cloud-starter-security-2.0.2.RELEASE.jar (Root Library) -> spring-boot-starter-actuator-2.0.9.RELEASE.jar -> ❌ spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-boot-actuator-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-actuator-autoconfigure:2.7.11,3.0.6 | None |
CVE-2020-10683Path to dependency file: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Path to vulnerable library: /black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml Dependency Hierarchy: -> weixin-java-mp-3.4.0.jar (Root Library) -> weixin-java-common-3.4.0.jar -> ❌ dom4j-2.1.1.jar (Vulnerable Library) |
Critical | 9.8 | dom4j-2.1.1.jar | Upgrade to version: org.dom4j:dom4j:2.1.3,org.dom4j:dom4j:2.0.3 | None |
WS-2021-0419Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:2.8.9 | None |
CVE-2022-25647Path to dependency file: /black-shop-common/black-shop-common-datasource/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> apollo-client-1.4.0.jar -> apollo-core-1.4.0.jar -> ❌ gson-2.8.5.jar (Vulnerable Library) |
High | 7.7 | gson-2.8.5.jar | Upgrade to version: com.google.code.gson:gson:gson-parent-2.8.9 | None |
CVE-2024-47554Path to dependency file: /black-shop-common/black-shop-common-security/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-gateway/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-auth/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
High | 7.5 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.14.0 | None |
CVE-2023-20883Path to dependency file: /black-shop-basic/black-shop-basic-apolloconfig/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-gateway/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> spring-cloud-starter-2.0.4.RELEASE.jar -> spring-boot-starter-2.0.9.RELEASE.jar -> ❌ spring-boot-autoconfigure-2.0.9.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-boot-autoconfigure-2.0.9.RELEASE.jar | Upgrade to version: org.springframework.boot:spring-boot-autoconfigure:2.5.12,2.6.12,2.7.12,3.0.7 | None |
CVE-2021-47621Path to dependency file: /black-shop-auth/pom.xml Path to vulnerable library: /black-shop-auth/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> swagger-spring-boot-starter-2.0.0.RELEASE.jar -> springfox-boot-starter-3.0.0.jar -> springfox-oas-3.0.0.jar -> springfox-spring-web-3.0.0.jar -> ❌ classgraph-4.8.83.jar (Vulnerable Library) |
High | 7.5 | classgraph-4.8.83.jar | Upgrade to version: io.github.classgraph:classgraph:4.8.112 | None |
CVE-2021-3690Path to dependency file: /black-shop-portal/black-shop-portal-web/pom.xml Path to vulnerable library: /black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ undertow-websockets-jsr-1.4.27.Final.jar (Vulnerable Library) |
High | 7.5 | undertow-websockets-jsr-1.4.27.Final.jar | Upgrade to version: io.undertow:undertow-websockets-jsr:2.0.40.Final, 2.2.10.Final | None |
CVE-2023-1932Path to dependency file: /black-shop-basic/black-shop-basic-redis/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-gateway/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate.validator:hibernate-validator:6.2.0.Final | None |
CVE-2019-10219Path to dependency file: /black-shop-basic/black-shop-basic-redis/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-gateway/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: 6.0.18.Final | None |
CVE-2022-22946Path to dependency file: /black-shop-gateway/pom.xml Path to vulnerable library: /black-shop-gateway/pom.xml Dependency Hierarchy: -> spring-cloud-starter-gateway-2.0.4.RELEASE.jar (Root Library) -> ❌ spring-cloud-gateway-core-2.0.4.RELEASE.jar (Vulnerable Library) |
Medium | 5.5 | spring-cloud-gateway-core-2.0.4.RELEASE.jar | Upgrade to version: org.springframework.cloud:spring-cloud-gateway-server:3.1.1 | None |
CVE-2021-28170Path to dependency file: /black-shop-common/black-shop-common-web/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-web/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> spring-boot-starter-undertow-2.0.9.RELEASE.jar (Root Library) -> ❌ javax.el-3.0.0.jar (Vulnerable Library) |
Medium | 5.3 | javax.el-3.0.0.jar | Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 | None |
CVE-2020-10693Path to dependency file: /black-shop-basic/black-shop-basic-redis/pom.xml Path to vulnerable library: /black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-gateway/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-auth/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-boot-starter-validation-2.0.9.RELEASE.jar -> ❌ hibernate-validator-6.0.16.Final.jar (Vulnerable Library) |
Medium | 5.3 | hibernate-validator-6.0.16.Final.jar | Upgrade to version: org.hibernate:hibernate-validator:6.0.20.Final,6.1.5.Final | None |
CVE-2021-29425Path to dependency file: /black-shop-common/black-shop-common-security/pom.xml Path to vulnerable library: /black-shop-common/black-shop-common-security/pom.xml,/black-shop-common/black-shop-common-feign/pom.xml,/black-shop-model/black-shop-model-product/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-api/pom.xml,/black-shop-model/black-shop-model-common/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml,/black-shop-common/black-shop-common-datasource/pom.xml,/black-shop-basic/black-shop-basic-redis/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-common/black-shop-common-core/pom.xml,/black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-gateway/pom.xml,/black-shop-common/black-shop-common-data/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-basic/black-shop-basic-zipkin/pom.xml,/black-shop-model/black-shop-model-shoppingcart/pom.xml,/black-shop-basic/black-shop-basic-apolloconfig/pom.xml,/black-shop-model/black-shop-model-order/pom.xml,/black-shop-basic/black-shop-basic-scheduler/pom.xml,/black-shop-common/black-shop-common-web/pom.xml,/black-shop-basic/black-shop-basic-elasticsearch/pom.xml,/black-shop-common/black-shop-common-util/pom.xml,/black-shop-auth/pom.xml,/black-shop-portal/black-shop-portal-pay/pom.xml Dependency Hierarchy: -> black-shop-basic-apolloconfig-1.0.0.jar (Root Library) -> black-shop-common-core-1.0.0.jar -> spring-cloud-starter-openfeign-2.0.4.RELEASE.jar -> spring-cloud-openfeign-core-2.0.4.RELEASE.jar -> feign-form-spring-3.3.0.jar -> commons-fileupload-1.3.3.jar -> ❌ commons-io-2.6.jar (Vulnerable Library) |
Medium | 4.8 | commons-io-2.6.jar | Upgrade to version: commons-io:commons-io:2.7 | None |
WS-2020-0407Path to dependency file: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml Path to vulnerable library: /black-shop-service/black-shop-user/black-shop-user-service/pom.xml,/black-shop-service/black-shop-thirdparty/black-shop-wechat/black-shop-wechat-service/pom.xml,/black-shop-portal/black-shop-portal-web/pom.xml,/black-shop-auth/pom.xml,/black-shop-common/black-shop-common-security/pom.xml,/black-shop-service/black-shop-user/black-shop-user-api/pom.xml Dependency Hierarchy: -> black-shop-user-api-1.0.0.jar (Root Library) -> swagger-spring-boot-starter-2.0.0.RELEASE.jar -> springfox-boot-starter-3.0.0.jar -> ❌ springfox-swagger2-3.0.0.jar (Vulnerable Library) |
Medium | 4.3 | springfox-swagger2-3.0.0.jar | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-47554 | org-apache-commons-io-RELEASE113.jar |
CVE-2019-11269 | spring-security-oauth2-2.2.3.RELEASE.jar |
CVE-2019-3778 | spring-security-oauth2-2.2.3.RELEASE.jar |
WS-2021-0419 | com-google-gson-RELEASE113.jar |
CVE-2022-25647 | com-google-gson-RELEASE113.jar |
CVE-2021-29425 | org-apache-commons-io-RELEASE113.jar |
Base branch total remaining vulnerabilities: 246
Base branch commit: null
Total libraries scanned: 292
Scan token: 26db6b0c0920465b89d661202f9dff63