Update dependency org.springframework:spring-webmvc to v6 #57
Mend for GitHub.com / Mend Security Check
failed
Oct 18, 2024 in 15m 58s
Security Report
You have successfully remediated 30 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2024-38820Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/6.1.14/spring-context-6.1.14.jar Dependency Hierarchy: -> spring-webmvc-6.1.14.jar (Root Library) -> ❌ spring-context-6.1.14.jar (Vulnerable Library) |
Low | 3.1 | spring-context-6.1.14.jar | Upgrade to version: org.springframework:spring-context:6.1.14 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-22262 | spring-web-4.2.0.RELEASE.jar |
CVE-2021-22060 | spring-core-4.2.0.RELEASE.jar |
CVE-2023-20861 | spring-expression-4.2.0.RELEASE.jar |
CVE-2024-38819 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2015-5211 | spring-web-4.2.0.RELEASE.jar |
CVE-2020-5421 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22970 | spring-beans-4.2.0.RELEASE.jar |
CVE-2024-22259 | spring-web-4.2.0.RELEASE.jar |
CVE-2024-38816 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22968 | spring-context-4.2.0.RELEASE.jar |
CVE-2022-22950 | spring-expression-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-core-4.2.0.RELEASE.jar |
CVE-2018-15756 | spring-web-4.2.0.RELEASE.jar |
CVE-2024-38808 | spring-expression-4.2.0.RELEASE.jar |
CVE-2016-1000027 | spring-web-4.2.0.RELEASE.jar |
CVE-2016-5007 | spring-webmvc-4.2.0.RELEASE.jar |
WS-2021-0170 | spring-core-4.2.0.RELEASE.jar |
CVE-2018-1271 | spring-webmvc-4.2.0.RELEASE.jar |
WS-2016-7112 | spring-context-4.2.0.RELEASE.jar |
CVE-2021-22096 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2018-1272 | spring-core-4.2.0.RELEASE.jar |
CVE-2023-20863 | spring-expression-4.2.0.RELEASE.jar |
CVE-2024-22243 | spring-web-4.2.0.RELEASE.jar |
CVE-2015-5211 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2024-38809 | spring-web-4.2.0.RELEASE.jar |
CVE-2022-22965 | spring-beans-4.2.0.RELEASE.jar |
CVE-2016-9878 | spring-webmvc-4.2.0.RELEASE.jar |
CVE-2018-1199 | spring-core-4.2.0.RELEASE.jar |
CVE-2022-22970 | spring-core-4.2.0.RELEASE.jar |
Base branch total remaining vulnerabilities: 204
Base branch commit: 643a7fad08d6608eaf25b22f87aee4b43387f2fc
Total libraries scanned: 111
Scan token: 077ae1d4232b4f199ea809f64b0f5bde
Loading