[Snyk] SNOW-1327598: Fix for 3 vulnerabilities #734
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
SNOW-1327598
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
SNYK-JAVA-ORGBOUNCYCASTLE-6612984
org.bouncycastle:bcpkix-jdk18on:
1.77 -> 1.78
org.bouncycastle:bcprov-jdk18on:
1.77 -> 1.78
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.9
SNYK-JAVA-ORGBOUNCYCASTLE-6613076
org.bouncycastle:bcpkix-jdk18on:
1.77 -> 1.78
org.bouncycastle:bcprov-jdk18on:
1.77 -> 1.78
Why? Recently disclosed, Has a fix available, CVSS 5.3
SNYK-JAVA-ORGBOUNCYCASTLE-6613079
org.bouncycastle:bcpkix-jdk18on:
1.77 -> 1.78
org.bouncycastle:bcprov-jdk18on:
1.77 -> 1.78
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling