Skip to content

Update dependency org.keycloak:keycloak-saml-core to v25

23e090e
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.keycloak:keycloak-saml-core to v25 #51

Update dependency org.keycloak:keycloak-saml-core to v25
23e090e
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jul 1, 2025 in 2m 53s

Security Report

You have successfully remediated 10 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
WS-2021-0616

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.11.0/jackson-databind-2.11.0.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.3.1.RELEASE.jar (Root Library)

   -> spring-boot-starter-json-2.3.1.RELEASE.jar

     -> ❌ jackson-databind-2.11.0.jar (Vulnerable Library)

Medium 5.9 jackson-databind-2.11.0.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 #36

Reachable

CVE-953123-750181

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/jakarta/activation/jakarta.activation-api/1.2.2/jakarta.activation-api-1.2.2.jar

Dependency Hierarchy:

-> keycloak-saml-core-25.0.6.jar (Root Library)

   -> keycloak-saml-core-public-25.0.6.jar

     -> xmlsec-2.2.6.jar

       -> jakarta.xml.bind-api-2.3.3.jar

         -> ❌ jakarta.activation-api-1.2.2.jar (Vulnerable Library)

Critical 9.8 jakarta.activation-api-1.2.2.jar None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2013-4517 xmlsec-1.5.1.jar
GHSA-4xx7-2cx3-x473 keycloak-saml-core-1.8.1.Final.jar
CVE-2021-3827 keycloak-saml-core-1.8.1.Final.jar
CVE-2013-5823 xmlsec-1.5.1.jar
CVE-2023-44483 xmlsec-1.5.1.jar
GHSA-q2gp-gph3-88x9 keycloak-saml-core-1.8.1.Final.jar
CVE-2017-2646 keycloak-saml-core-1.8.1.Final.jar
CVE-2017-2582 keycloak-saml-core-1.8.1.Final.jar
CVE-2021-40690 xmlsec-1.5.1.jar
CVE-2013-2172 xmlsec-1.5.1.jar

Base branch total remaining vulnerabilities: 93
Base branch commit: f9e0dc6866b5df73561aeec6122e14261d82ab4d


Total libraries scanned: 97

Scan token: 03ec05b881d94bf18c23c6be4ee107ba