There is a high severity vulnerability in two of the dependencies, logback-core and logback-classic. These are used by spring boot, and to update them, we need to update spring boot to version 2. However, this version is not a stable version, so it has to be verified that there would be no issues with updating to the newer version.