Skip to content

Conversation

@struce2
Copy link
Owner

@struce2 struce2 commented Mar 7, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade org.apache.tomcat.embed:tomcat-embed-core from 9.0.31 to 9.0.86.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 46 versions ahead of your current version.
  • The recommended version was released 23 days ago, on 2024-02-14.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHETOMCATEMBED-570072
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-5953331
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Mature
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728264
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728268
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Privilege Escalation
SNYK-JAVA-ORGAPACHETOMCATEMBED-2414084
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGAPACHETOMCATEMBED-6092281
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHETOMCATEMBED-1080637
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-584427
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Access Restriction Bypass
SNYK-JAVA-ORGAPACHETOMCATEMBED-5862028
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGAPACHETOMCATEMBED-5959654
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1080638
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Improper Input Validation
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728265
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1728266
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Incomplete Cleanup
SNYK-JAVA-ORGAPACHETOMCATEMBED-5959972
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-6183062
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-3326459
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Unprotected Transport of Credentials
SNYK-JAVA-ORGAPACHETOMCATEMBED-3369687
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-1017119
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-1048292
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Proof of Concept
Information Disclosure
SNYK-JAVA-ORGAPACHETOMCATEMBED-1061939
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
Information Exposure
SNYK-JAVA-ORGAPACHETOMCATEMBED-3035793
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit
HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-3097829
791/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants