Update dependency org.springframework:spring-webmvc to v4.3.15.RELEASE - autoclosed #56
Security Report
You have successfully remediated 28 vulnerabilities, but introduced 22 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2022-22965Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/4.3.15.RELEASE/spring-beans-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-aop-4.3.15.RELEASE.jar -> ❌ spring-beans-4.3.15.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-beans-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-beans:5.2.20.RELEASE,5.3.18 | None | |
CVE-2024-22262Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 8.1 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.3.34;6.0.19,6.1.6 | None | |
CVE-2024-22259Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 8.1 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.3.33,6.0.18,6.1.5 | None | |
CVE-2024-22243Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 8.1 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.3.32,6.0.17,6.1.4 | None | |
CVE-2018-15756Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: 4.3.20,5.0.10,5.1.1 | None | |
CVE-2018-11040Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.0.7.RELEASE,4.3.18.RELEASE,org.springframework:spring-webmvc:5.0.7.RELEASE,4.3.18.RELEASE,org.springframework:spring-websocket:5.0.7.RELEASE,4.3.18.RELEASE | None | |
CVE-2024-38809Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.3.38,6.0.23,6.1.12 | None | |
CVE-2023-20863Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/4.3.15.RELEASE/spring-expression-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-context-4.3.15.RELEASE.jar -> ❌ spring-expression-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 | None | |
CVE-2023-20861Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/4.3.15.RELEASE/spring-expression-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-context-4.3.15.RELEASE.jar -> ❌ spring-expression-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 | None | |
CVE-2022-22950Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/4.3.15.RELEASE/spring-expression-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-context-4.3.15.RELEASE.jar -> ❌ spring-expression-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-expression-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:5.2.20,5.3.17 | None | |
CVE-2020-5421Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 6.5 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:4.3.29,5.0.19,5.1.18,5.2.9 | None | |
CVE-2024-38808Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/4.3.15.RELEASE/spring-expression-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-context-4.3.15.RELEASE.jar -> ❌ spring-expression-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 5.5 | spring-expression-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-expression:5.3.39 | None | |
CVE-2022-22970Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/4.3.15.RELEASE/spring-core-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-aop-4.3.15.RELEASE.jar -> spring-beans-4.3.15.RELEASE.jar -> ❌ spring-core-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-core-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None | |
CVE-2022-22970Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/4.3.15.RELEASE/spring-beans-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-aop-4.3.15.RELEASE.jar -> ❌ spring-beans-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-beans-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-beans:5.2.22,5.3.20;org.springframework:spring-core:5.2.22,5.3.20 | None | |
CVE-2022-22968Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/4.3.15.RELEASE/spring-context-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> ❌ spring-context-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 5.3 | spring-context-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-context:5.2.21,5.3.19 | None | |
CVE-2021-22096Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/4.3.15.RELEASE/spring-core-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-aop-4.3.15.RELEASE.jar -> spring-beans-4.3.15.RELEASE.jar -> ❌ spring-core-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 4.3 | spring-core-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-core:5.2.18.RELEASE,5.3.12;org.springframework:spring-web:5.2.18.RELEASE,5.3.12;org.springframework:spring-webmvc:5.2.18.RELEASE,5.3.12;org.springframework:spring-webflux:5.2.18.RELEASE,5.3.12 | None | |
CVE-2021-22096Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 4.3 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-core:5.2.18.RELEASE,5.3.12;org.springframework:spring-web:5.2.18.RELEASE,5.3.12;org.springframework:spring-webmvc:5.2.18.RELEASE,5.3.12;org.springframework:spring-webflux:5.2.18.RELEASE,5.3.12 | None | |
CVE-2021-22096Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/4.3.15.RELEASE/spring-webmvc-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-webmvc-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 4.3 | spring-webmvc-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-core:5.2.18.RELEASE,5.3.12;org.springframework:spring-web:5.2.18.RELEASE,5.3.12;org.springframework:spring-webmvc:5.2.18.RELEASE,5.3.12;org.springframework:spring-webflux:5.2.18.RELEASE,5.3.12 | None | |
CVE-2021-22060Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/4.3.15.RELEASE/spring-core-4.3.15.RELEASE.jar Dependency Hierarchy: -> spring-web-4.3.15.RELEASE.jar (Root Library) -> spring-aop-4.3.15.RELEASE.jar -> spring-beans-4.3.15.RELEASE.jar -> ❌ spring-core-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 4.3 | spring-core-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-core:5.2.19, 5.3.14;org.springframework:spring-web:5.2.19, 5.3.14 | None | |
CVE-2016-1000027Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
Critical | 9.8 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:6.0.0 | None | |
CVE-2018-11040Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/4.3.15.RELEASE/spring-webmvc-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-webmvc-4.3.15.RELEASE.jar (Vulnerable Library) |
High | 7.5 | spring-webmvc-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.0.7.RELEASE,4.3.18.RELEASE,org.springframework:spring-webmvc:5.0.7.RELEASE,4.3.18.RELEASE,org.springframework:spring-websocket:5.0.7.RELEASE,4.3.18.RELEASE | None | |
CVE-2018-11039Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.3.15.RELEASE/spring-web-4.3.15.RELEASE.jar Dependency Hierarchy: -> ❌ spring-web-4.3.15.RELEASE.jar (Vulnerable Library) |
Medium | 5.9 | spring-web-4.3.15.RELEASE.jar | Upgrade to version: org.springframework:spring-web:5.0.7.RELEASE,4.3.18.RELEASE,org.apache.servicemix.bundles:org.apache.servicemix.bundles.spring-web:5.0.7.RELEASE,4.3.18.RELEASE | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-22262 | spring-web-4.2.0.RELEASE.jar |
CVE-2021-22060 | spring-core-4.2.0.RELEASE.jar |
CVE-2023-20861 | spring-expression-4.2.0.RELEASE.jar |
CVE-2015-5211 | spring-web-4.2.0.RELEASE.jar |
CVE-2020-5421 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22970 | spring-beans-4.2.0.RELEASE.jar |
CVE-2024-22259 | spring-web-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22968 | spring-context-4.2.0.RELEASE.jar |
CVE-2022-22950 | spring-expression-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-core-4.2.0.RELEASE.jar |
CVE-2018-15756 | spring-web-4.2.0.RELEASE.jar |
CVE-2024-38808 | spring-expression-4.2.0.RELEASE.jar |
CVE-2016-1000027 | spring-web-4.2.0.RELEASE.jar |
CVE-2016-5007 | spring-webmvc-4.2.0.RELEASE.jar |
WS-2021-0170 | spring-core-4.2.0.RELEASE.jar |
CVE-2018-1271 | spring-webmvc-4.2.0.RELEASE.jar |
WS-2016-7112 | spring-context-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2018-1272 | spring-core-4.2.0.RELEASE.jar |
CVE-2023-20863 | spring-expression-4.2.0.RELEASE.jar |
CVE-2024-22243 | spring-web-4.2.0.RELEASE.jar |
CVE-2015-5211 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2024-38809 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22965 | spring-beans-4.2.0.RELEASE.jar |
CVE-2016-9878 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2018-1199 | spring-core-4.2.0.RELEASE.jar |
CVE-2022-22970 | spring-core-4.2.0.RELEASE.jar |
Base branch total remaining vulnerabilities: 201
Base branch commit: 643a7fad08d6608eaf25b22f87aee4b43387f2fc
Total libraries scanned: 108
Scan token: 592549132ad8418e9da5590f4adcc66c