Update dependency org.apache.shiro:shiro-web to v1.12.0 #55
Security Report
You have successfully remediated 7 vulnerabilities, but introduced 8 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> ksa-logistics-web-3.9.2.pom (Root Library) -> ksa-security-web-3.9.2.pom -> ksa-security-service-3.9.2.pom -> shiro-core-1.12.0.jar -> shiro-config-ogdl-1.12.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | commons-beanutils-1.9.4.jar | Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 | #20 | ||
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> ksa-finance-web-3.9.2.pom (Root Library) -> ksa-logistics-web-3.9.2.pom -> ksa-security-web-3.9.2.pom -> ksa-security-service-3.9.2.pom -> shiro-core-1.12.0.jar -> shiro-config-ogdl-1.12.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | commons-beanutils-1.9.4.jar | Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 | #52 | ||
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> shiro-web-1.12.0.jar (Root Library) -> shiro-core-1.12.0.jar -> shiro-config-ogdl-1.12.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | commons-beanutils-1.9.4.jar | Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 | None | ||
CVE-2025-48734Path to dependency file: /ksa-web-root/ksa-statistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar,/home/wss-scanner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar Dependency Hierarchy: -> ksa-security-web-3.9.2.pom (Root Library) -> ksa-security-service-3.9.2.pom -> shiro-core-1.12.0.jar -> shiro-config-ogdl-1.12.0.jar -> ❌ commons-beanutils-1.9.4.jar (Vulnerable Library) |
8.8 | commons-beanutils-1.9.4.jar | Upgrade to version: commons-beanutils:commons-beanutils:1.11.0 | #40 | ||
CVE-2023-46749Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar Dependency Hierarchy: -> ksa-logistics-web-3.9.2.pom (Root Library) -> ksa-security-web-3.9.2.pom -> ksa-security-service-3.9.2.pom -> ❌ shiro-core-1.12.0.jar (Vulnerable Library) |
6.5 | shiro-core-1.12.0.jar | Upgrade to version: org.apache.shiro:shiro-core:1.13.0 | #20 | ||
CVE-2023-46749Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar Dependency Hierarchy: -> ksa-finance-web-3.9.2.pom (Root Library) -> ksa-logistics-web-3.9.2.pom -> ksa-security-web-3.9.2.pom -> ksa-security-service-3.9.2.pom -> ❌ shiro-core-1.12.0.jar (Vulnerable Library) |
6.5 | shiro-core-1.12.0.jar | Upgrade to version: org.apache.shiro:shiro-core:1.13.0 | #52 | ||
CVE-2023-46749Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar Dependency Hierarchy: -> shiro-web-1.12.0.jar (Root Library) -> ❌ shiro-core-1.12.0.jar (Vulnerable Library) |
6.5 | shiro-core-1.12.0.jar | Upgrade to version: org.apache.shiro:shiro-core:1.13.0 | None | ||
CVE-2023-46749Path to dependency file: /ksa-web-root/ksa-logistics-web/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar,/home/wss-scanner/.m2/repository/org/apache/shiro/shiro-core/1.12.0/shiro-core-1.12.0.jar Dependency Hierarchy: -> ksa-security-web-3.9.2.pom (Root Library) -> ksa-security-service-3.9.2.pom -> ❌ shiro-core-1.12.0.jar (Vulnerable Library) |
6.5 | shiro-core-1.12.0.jar | Upgrade to version: org.apache.shiro:shiro-core:1.13.0 | #40 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-11989 | shiro-web-1.2.0.jar |
| CVE-2020-17523 | shiro-web-1.2.0.jar |
| CVE-2020-17510 | shiro-web-1.2.0.jar |
| CVE-2023-34478 | shiro-web-1.2.0.jar |
| CVE-2020-1957 | shiro-web-1.2.0.jar |
| CVE-2022-40664 | shiro-web-1.2.0.jar |
| CVE-2016-6802 | shiro-web-1.2.0.jar |
Base branch total remaining vulnerabilities: 120
Base branch commit: b4849d22848515902fbd02cf19d698089bd7f3a4
Total libraries scanned: 84
Scan token: 367b0b4578d34510868f48ba685741fe