Skip to content

Update dependency org.apache.shiro:shiro-web to v1.12.0

bbc2436
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.apache.shiro:shiro-web to v1.12.0 #55

Update dependency org.apache.shiro:shiro-web to v1.12.0
bbc2436
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jun 30, 2025 in 11m 6s

Security Report

You have successfully remediated 7 vulnerabilities, but introduced 8 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
CVE-2025-48734

Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar

Dependency Hierarchy:

-> ksa-logistics-web-3.9.2.pom (Root Library)

   -> ksa-security-web-3.9.2.pom

     -> ksa-security-service-3.9.2.pom

       -> shiro-core-1.12.0.jar

         -> shiro-config-ogdl-1.12.0.jar

           -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library)

High 8.8 commons-beanutils-1.9.4.jar Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 #20

Unreachable

CVE-2025-48734

Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar

Dependency Hierarchy:

-> ksa-finance-web-3.9.2.pom (Root Library)

   -> ksa-logistics-web-3.9.2.pom

     -> ksa-security-web-3.9.2.pom

       -> ksa-security-service-3.9.2.pom

         -> shiro-core-1.12.0.jar

           -> shiro-config-ogdl-1.12.0.jar

             -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library)

High 8.8 commons-beanutils-1.9.4.jar Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 #52

Unreachable

CVE-2025-48734

Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar

Dependency Hierarchy:

-> shiro-web-1.12.0.jar (Root Library)

   -> shiro-core-1.12.0.jar

     -> shiro-config-ogdl-1.12.0.jar

       -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library)

High 8.8 commons-beanutils-1.9.4.jar Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 None

Unreachable

CVE-2025-48734

Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar

Dependency Hierarchy:

-> ksa-security-web-3.9.2.pom (Root Library)

   -> ksa-security-service-3.9.2.pom

     -> shiro-core-1.12.0.jar

       -> shiro-config-ogdl-1.12.0.jar

         -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library)

High 8.8 commons-beanutils-1.9.4.jar Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 #40

Unreachable

CVE-2023-46749

Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar

Dependency Hierarchy:

-> ksa-logistics-web-3.9.2.pom (Root Library)

   -> ksa-security-web-3.9.2.pom

     -> ksa-security-service-3.9.2.pom

       -> ❌ shiro-core-1.12.0.jar (Vulnerable Library)

Medium 6.5 shiro-core-1.12.0.jar Upgrade to version: org.apache.shiro:shiro-core:1.13.0 #20
CVE-2023-46749

Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar

Dependency Hierarchy:

-> ksa-finance-web-3.9.2.pom (Root Library)

   -> ksa-logistics-web-3.9.2.pom

     -> ksa-security-web-3.9.2.pom

       -> ksa-security-service-3.9.2.pom

         -> ❌ shiro-core-1.12.0.jar (Vulnerable Library)

Medium 6.5 shiro-core-1.12.0.jar Upgrade to version: org.apache.shiro:shiro-core:1.13.0 #52
CVE-2023-46749

Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar

Dependency Hierarchy:

-> shiro-web-1.12.0.jar (Root Library)

   -> ❌ shiro-core-1.12.0.jar (Vulnerable Library)

Medium 6.5 shiro-core-1.12.0.jar Upgrade to version: org.apache.shiro:shiro-core:1.13.0 None
CVE-2023-46749

Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar

Dependency Hierarchy:

-> ksa-security-web-3.9.2.pom (Root Library)

   -> ksa-security-service-3.9.2.pom

     -> ❌ shiro-core-1.12.0.jar (Vulnerable Library)

Medium 6.5 shiro-core-1.12.0.jar Upgrade to version: org.apache.shiro:shiro-core:1.13.0 #40

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-11989 shiro-web-1.2.0.jar
CVE-2020-17523 shiro-web-1.2.0.jar
CVE-2020-17510 shiro-web-1.2.0.jar
CVE-2023-34478 shiro-web-1.2.0.jar
CVE-2020-1957 shiro-web-1.2.0.jar
CVE-2022-40664 shiro-web-1.2.0.jar
CVE-2016-6802 shiro-web-1.2.0.jar

Base branch total remaining vulnerabilities: 120
Base branch commit: b4849d22848515902fbd02cf19d698089bd7f3a4


Total libraries scanned: 84

Scan token: 367b0b4578d34510868f48ba685741fe