Update dependency org.springframework.data:spring-data-jpa to v1.11.11.RELEASE #4
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2023-1932Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/hibernate-validator/5.2.1.Final/hibernate-validator-5.2.1.Final.jar Dependency Hierarchy: -> ❌ hibernate-validator-5.2.1.Final.jar (Vulnerable Library) |
Medium | 6.1 | hibernate-validator-5.2.1.Final.jar | Upgrade to version: org.hibernate.validator:hibernate-validator:6.2.0.Final | #17 | |
CVE-2018-1259Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-commons/1.13.11.RELEASE/spring-data-commons-1.13.11.RELEASE.jar Dependency Hierarchy: -> spring-data-jpa-1.11.11.RELEASE.jar (Root Library) -> ❌ spring-data-commons-1.13.11.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-data-commons-1.13.11.RELEASE.jar | Upgrade to version: 1.13.12,2.0.7 | None | |
CVE-2019-3802Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-jpa/1.11.11.RELEASE/spring-data-jpa-1.11.11.RELEASE.jar Dependency Hierarchy: -> ❌ spring-data-jpa-1.11.11.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-data-jpa-1.11.11.RELEASE.jar | Upgrade to version: 1.11.22.RELEASE,2.1.8.RELEASE | None | |
CVE-2019-3797Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-jpa/1.11.11.RELEASE/spring-data-jpa-1.11.11.RELEASE.jar Dependency Hierarchy: -> ❌ spring-data-jpa-1.11.11.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-data-jpa-1.11.11.RELEASE.jar | Upgrade to version: 1.11.20, 2.0.14, 2.1.6 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2018-1273 | spring-data-commons-1.10.1.RELEASE.jar |
CVE-2016-6652 | spring-data-jpa-1.8.1.RELEASE.jar |
Base branch total remaining vulnerabilities: 198
Base branch commit: 643a7fad08d6608eaf25b22f87aee4b43387f2fc
Total libraries scanned: 108
Scan token: 325ccf9aea4a440487b7f54d671cc268