Update dependency org.apache.shiro:shiro-core to v1.10.0 #13
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> ksa-security-service-3.9.2.pom (Root Library) -> shiro-core-1.10.0.jar -> shiro-config-ogdl-1.10.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | Transitive commons-beanutils-1.9.4.jar |
ksa-security-service-3.9.2.pom | Transitive 1.11.0 |
#38 | ||
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> shiro-core-1.10.0.jar (Root Library) -> shiro-config-ogdl-1.10.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | Transitive commons-beanutils-1.9.4.jar |
shiro-core-1.10.0.jar | Transitive 1.11.0 |
None | ||
CVE-2023-46749Path to dependency file: /ksa-service-root/ksa-security-service/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.10.0/shiro-core-1.10.0.jar Dependency Hierarchy: -> ❌ shiro-core-1.10.0.jar (Vulnerable Library) |
6.5 | Direct shiro-core-1.10.0.jar |
shiro-core-1.10.0.jar | org.apache.shiro:shiro-core:1.13.0 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-15250 | junit-4.8.2.jar |
Base branch total remaining vulnerabilities: 121
Base branch commit: b4849d22848515902fbd02cf19d698089bd7f3a4
Total libraries scanned: 85
Scan token: 68903dd597d149aebb1a7da92aec1fbd