Skip to content

Conversation

@arikregev
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade org.springframework.boot:spring-boot-starter-actuator from 1.4.7.RELEASE to 1.5.22.RELEASE.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 23 versions ahead of your current version.
  • The recommended version was released 4 years ago, on 2019-08-06.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Directory Traversal
SNYK-JAVA-ORGAPACHETOMCATEMBED-451518
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31507
525/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-31573
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043
525/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Remote Code Execution
SNYK-JAVA-ORGAPACHETOMCATEMBED-451343
525/1000
Why? Has a fix available, CVSS 7.5
Mature
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451459
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451508
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHETOMCATEMBED-451515
525/1000
Why? Has a fix available, CVSS 7.5
Mature
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451342
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Open Redirect
SNYK-JAVA-ORGAPACHETOMCATEMBED-451503
525/1000
Why? Has a fix available, CVSS 7.5
Mature
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-451504
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Access Restriction Bypass
SNYK-JAVA-ORGAPACHETOMCATEMBED-451511
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Information Exposure
SNYK-JAVA-ORGSPRINGFRAMEWORK-31689
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Cross-Site Tracing (XST)
SNYK-JAVA-ORGSPRINGFRAMEWORK-451604
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-451458
525/1000
Why? Has a fix available, CVSS 7.5
Mature
Insecure Defaults
SNYK-JAVA-ORGAPACHETOMCATEMBED-451505
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Directory Traversal
SNYK-JAVA-ORGAPACHETOMCATEMBED-451510
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Multipart Content Pollution
SNYK-JAVA-ORGSPRINGFRAMEWORK-460644
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Multipart Content Pollution
SNYK-JAVA-ORGSPRINGFRAMEWORK-32199
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Directory Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-32202
525/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Information Exposure
SNYK-JAVA-ORGSPRINGFRAMEWORK-467268
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-72470
525/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

…om 1.4.7.RELEASE to 1.5.22.RELEASE

Snyk has created this PR to upgrade org.springframework.boot:spring-boot-starter-actuator from 1.4.7.RELEASE to 1.5.22.RELEASE.

See this package in Maven Repository:
https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator/

See this project in Snyk:
https://app.snyk.io/org/arikregev/project/3856ec4f-dba2-4501-9441-0c3c99046d65?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants