Skip to content

Conversation

@art-vandelay-sec
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Relative Path Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931
  110   org.springframework.data:spring-data-commons:
1.13.11.RELEASE -> 3.4.9
org.springframework.security:spring-security-config:
4.2.12.RELEASE -> 6.4.9
org.springframework.security:spring-security-web:
4.2.12.RELEASE -> 6.4.9
Major version upgrade No Path Found No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:[email protected] to org.springframework.boot:[email protected]; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.1.RELEASE/spring-boot-dependencies-1.5.1.RELEASE.pom

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Relative Path Traversal

@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedorg.springframework.data/​spring-data-commons@​1.13.11.RELEASE ⏵ 3.4.936100 +168910080
Updatedorg.springframework.security/​spring-security-config@​4.2.12.RELEASE ⏵ 6.4.93610089100100
Updatedorg.springframework.security/​spring-security-web@​4.2.12.RELEASE ⏵ 6.4.964 +28100 +75100 +12100100

View full report

@socket-security
Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-gjmw-vf9h-g25v jackson-databind polymorphic typing issue (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10.1; >= 2.7.0 < 2.8.11.5; < 2.6.7.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-gww7-p5w4-wrfv Deserialization of Untrusted Data in jackson-databind (CRITICAL)

Affected versions: >= 2.0.0 < 2.6.7.4; >= 2.7.0 < 2.7.9.7; >= 2.8.0 < 2.8.11.5; >= 2.9.0 < 2.9.10.2

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-p43x-xfjf-5jhr jackson-databind mishandles the interaction between serialization gadgets and typing (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10.4; >= 2.8.0 < 2.8.11.6; >= 2.0.0 < 2.7.9.7

Patched version: 2.8.11.6

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-q93h-jc49-78gg jackson-databind mishandles the interaction between serialization gadgets and typing (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10.4; >= 2.8.0 < 2.8.11.6; >= 2.0.0 < 2.7.9.7

Patched version: 2.8.11.6

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-4gq5-ch57-c2mg Arbitrary Code Execution in jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.7; >= 2.8.0 < 2.8.11.3; >= 2.0.0 < 2.7.9.5

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-9mxf-g3x6-wv74 Server-Side Request Forgery (SSRF) in jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.7; >= 2.8.0 < 2.8.11.3; >= 2.7.0 < 2.7.9.5

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-f9hv-mg5h-xcw9 Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.8; >= 2.8.0 < 2.8.11.3; >= 2.7.0 < 2.7.9.5

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-mx9v-gmh4-mgqw Deserialization of Untrusted Data in jackson-databind (CRITICAL)

Affected versions: >= 2.7.0 < 2.7.9.5; >= 2.9.0 < 2.9.8; >= 2.8.0 < 2.8.11.3

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-6fpp-rgj9-8rwc Deserialization of untrusted data in FasterXML jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.9.2; >= 2.8.0 < 2.8.11.4; < 2.7.9.6

Patched version: 2.8.11.4

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-qr7j-h6gg-jmgc Deserialization of Untrusted Data in jackson-databind (CRITICAL)

Affected versions: >= 2.0.0 < 2.7.9.4; >= 2.8.0 < 2.8.11.2; >= 2.9.0 < 2.9.6

Patched version: 2.8.11.2

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-85cw-hj65-qqv9 Polymorphic Typing issue in FasterXML jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10; >= 2.7.0 < 2.8.11.5; < 2.6.7.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-h822-r4r5-v8jg Polymorphic Typing issue in FasterXML jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10; >= 2.7.0 < 2.8.11.5; < 2.6.7.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-mx7p-6679-8g3q Polymorphic Typing in FasterXML jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10.1; >= 2.7.0 < 2.8.11.5; >= 2.0.0 < 2.6.7.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-fmmc-742q-jg75 jackson-databind polymorphic typing issue (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10.1; >= 2.7.0 < 2.8.11.5; < 2.6.7.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-qxxx-2pp7-5hmx jackson-databind is vulnerable to a deserialization flaw (CRITICAL)

Affected versions: < 2.6.7.1; >= 2.7.0 < 2.7.9.1; >= 2.8.0 < 2.8.9

Patched version: 2.8.9

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-rfx6-vp9g-rh7v jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.4; >= 2.8.0 < 2.8.11; < 2.7.9.2

Patched version: 2.8.11

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-4w82-r329-3q67 Deserialization of Untrusted Data in jackson-databind (CRITICAL)

Affected versions: >= 2.0.0 < 2.6.7.4; >= 2.7.0 < 2.7.9.7; >= 2.8.0 < 2.8.11.5; >= 2.9.0 < 2.9.10.3

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-f3j5-rmmp-3fc5 Improper Input Validation in jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.10; < 2.8.11.5

Patched version: 2.8.11.5

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-h592-38cm-4ggp jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution (CRITICAL)

Affected versions: >= 2.8.0 < 2.8.11; >= 2.9.0 < 2.9.4; >= 2.0.0 < 2.6.7.3; >= 2.7.0 < 2.7.9.2

Patched version: 2.8.11

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-cggj-fvv3-cqwv FasterXML jackson-databind allows unauthenticated remote code execution (CRITICAL)

Affected versions: >= 2.8.0 < 2.8.11.1; >= 2.9.0 < 2.9.5; >= 2.7.0 < 2.7.9.3; < 2.6.7.5

Patched version: 2.8.11.1

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-645p-88qh-w398 Arbitrary Code Execution in jackson-databind (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.7; >= 2.8.0 < 2.8.11.3; >= 2.7.0 < 2.7.9.5; >= 2.0.0 < 2.6.7.3

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
com.fasterxml.jackson.core/[email protected] has a Critical CVE.

CVE: GHSA-c8hm-7hpq-7jhg com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data (CRITICAL)

Affected versions: >= 2.9.0 < 2.9.8; >= 2.8.0 < 2.8.11.3; >= 2.7.0 < 2.7.9.5; >= 2.0.0 < 2.6.7.3

Patched version: 2.8.11.3

From: pom.xmlmaven/org.springframework.boot/[email protected]maven/com.fasterxml.jackson.core/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/com.fasterxml.jackson.core/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 2 more rows in the dashboard

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants