Skip to content

Update dependency org.springframework.boot:spring-boot to v3

85e3ded
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.springframework.boot:spring-boot to v3 #14

Update dependency org.springframework.boot:spring-boot to v3
85e3ded
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jul 30, 2025 in 3m 1s

Security Report

You have successfully remediated 10 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
CVE-2018-1257

Path to dependency file: /telegrambots-spring-boot-starter/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.19/spring-core-6.1.19.jar

Dependency Hierarchy:

-> spring-boot-3.3.11.jar (Root Library)

   -> ❌ spring-core-6.1.19.jar (Vulnerable Library)

Medium 6.5 spring-core-6.1.19.jar Upgrade to version: 5.0.6,4.3.17 None

Reachable

CVE-2018-1271

Path to dependency file: /telegrambots-spring-boot-starter/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.19/spring-core-6.1.19.jar

Dependency Hierarchy:

-> spring-boot-3.3.11.jar (Root Library)

   -> ❌ spring-core-6.1.19.jar (Vulnerable Library)

Medium 5.9 spring-core-6.1.19.jar Upgrade to version: org.springframework:spring-webflux:5.0.5.RELEASE,org.springframework:spring-webmvc:4.3.15.RELEASE,5.0.5.RELEASE None

Reachable

CVE-2018-1196

Path to dependency file: /telegrambots-spring-boot-starter/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/3.3.11/spring-boot-3.3.11.jar

Dependency Hierarchy:

-> ❌ spring-boot-3.3.11.jar (Vulnerable Library)

Medium 5.9 spring-boot-3.3.11.jar Upgrade to version: 1.5.10.RELEASE None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-403178-925037 spring-boot-autoconfigure-2.7.5.jar
CVE-780011-81885 spring-expression-5.3.23.jar
CVE-2018-1257 spring-core-5.3.23.jar
CVE-953123-750181 jakarta.activation-api-1.2.2.jar
CVE-2018-1196 spring-boot-2.7.5.jar
CVE-2023-20883 spring-boot-autoconfigure-2.7.5.jar
CVE-2023-20863 spring-expression-5.3.23.jar
CVE-2018-1271 spring-core-5.3.23.jar
CVE-2023-20861 spring-expression-5.3.23.jar
CVE-2025-22235 spring-boot-2.7.5.jar

Base branch total remaining vulnerabilities: 24
Base branch commit: 5bd6572be60a4f31fafe0a650bd8413f91c71a12


Total libraries scanned: 78

Scan token: af8f4ee77f494d85bb17ae6ecce20e8f