Skip to content

[Snyk] Upgrade org.apache.sling:maven-sling-plugin from 2.0.4-incubator to 2.4.2#3

Open
henrypost wants to merge 1 commit intomainfrom
snyk-upgrade-c064b2775b9a5e7868e13437ad332b77
Open

[Snyk] Upgrade org.apache.sling:maven-sling-plugin from 2.0.4-incubator to 2.4.2#3
henrypost wants to merge 1 commit intomainfrom
snyk-upgrade-c064b2775b9a5e7868e13437ad332b77

Conversation

@henrypost
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade org.apache.sling:maven-sling-plugin from 2.0.4-incubator to 2.4.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 15 versions ahead of your current version.
  • The recommended version was released 4 years ago, on 2019-06-03.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Improper Input Validation
SNYK-JAVA-ORGAPACHESLING-5535052
265/1000
Why? CVSS 5.3
No Known Exploit
Log Manipulation
SNYK-JAVA-ORGAPACHESLING-2934398
265/1000
Why? CVSS 5.3
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHESLING-30727
265/1000
Why? CVSS 5.3
No Known Exploit
Directory Traversal
SNYK-JAVA-ORGCODEHAUSPLEXUS-31521
265/1000
Why? CVSS 5.3
No Known Exploit
Improper Certificate Validation
SNYK-JAVA-COMMONSHTTPCLIENT-30083
265/1000
Why? CVSS 5.3
No Known Exploit
Man-in-the-Middle (MitM)
SNYK-JAVA-COMMONSHTTPCLIENT-31660
265/1000
Why? CVSS 5.3
No Known Exploit
Information Exposure
SNYK-JAVA-JUNIT-1017047
265/1000
Why? CVSS 5.3
Proof of Concept
Shell Command Injection
SNYK-JAVA-ORGCODEHAUSPLEXUS-31522
265/1000
Why? CVSS 5.3
No Known Exploit
Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JAVA-ORGCODEHAUSPLEXUS-31680
265/1000
Why? CVSS 5.3
No Known Exploit
XML External Entity (XXE) Injection
SNYK-JAVA-ORGCODEHAUSPLEXUS-461102
265/1000
Why? CVSS 5.3
No Known Exploit
Directory Traversal
SNYK-JAVA-ORGCODEHAUSPLEXUS-5805290
265/1000
Why? CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants