Skip to content
This repository was archived by the owner on Jul 8, 2025. It is now read-only.

[Snyk] Fix for 15 vulnerabilities - #11

Open
PaulCrossan wants to merge 1 commit into
masterfrom
snyk-fix-dc62ec5b987b5e51cf09f65a7a057d25
Open

[Snyk] Fix for 15 vulnerabilities#11
PaulCrossan wants to merge 1 commit into
masterfrom
snyk-fix-dc62ec5b987b5e51cf09f65a7a057d25

Conversation

@PaulCrossan

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 15 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
critical severity Deserialization of Untrusted Data
SNYK-JAVA-ORGAPACHEACTIVEMQ-6039483
  937   org.apache.activemq:activemq-client:
5.14.1 -> 5.16.8
No Path Found Mature
medium severity Memory Allocation with Excessive Size Value
SNYK-JAVA-ORGAPACHEACTIVEMQ-10074037
  300   org.apache.activemq:activemq-client:
5.14.1 -> 5.16.8
No Path Found Mature
critical severity Arbitrary Code Execution
SNYK-JAVA-CHQOSLOGBACK-31407
  299   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
critical severity Arbitrary Code Execution
SNYK-JAVA-CHQOSLOGBACK-30208
  225   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
high severity Man-in-the-Middle (MitM)
SNYK-JAVA-ORGAPACHEACTIVEMQ-460123
  195   org.apache.activemq:activemq-client:
5.14.1 -> 5.16.8
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-CHQOSLOGBACK-6094942
  127   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
high severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-CHQOSLOGBACK-6097492
  126   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-CHQOSLOGBACK-6094943
  95   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
high severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-CHQOSLOGBACK-6097493
  95   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
medium severity Improper Neutralization of Special Elements
SNYK-JAVA-CHQOSLOGBACK-8539867
  82   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
low severity Server-side Request Forgery (SSRF)
SNYK-JAVA-CHQOSLOGBACK-8539865
  76   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
medium severity Insufficient Hostname Verification
SNYK-JAVA-CHQOSLOGBACK-1726923
  72   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
low severity Denial of Service (DoS)
SNYK-JAVA-ORGAPACHEACTIVEMQ-451539
  66   org.apache.activemq:activemq-client:
5.14.1 -> 5.16.8
Reachable No Known Exploit
medium severity Improper Neutralization of Special Elements
SNYK-JAVA-CHQOSLOGBACK-8539866
  61   ch.qos.logback:logback-classic:
1.1.2 -> 1.3.15
No Path Found No Known Exploit
low severity Information Exposure
SNYK-JAVA-COMMONSCODEC-561518
  54   commons-codec:commons-codec:
1.10 -> 1.14
No Path Found No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Insufficient Hostname Verification
🦉 Arbitrary Code Execution
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants