Update dependency org.keycloak:keycloak-saml-core to v25 #51
Security Report
You have successfully remediated 10 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|
WS-2021-0616Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.11.0/jackson-databind-2.11.0.jar Dependency Hierarchy: -> spring-boot-starter-web-2.3.1.RELEASE.jar (Root Library) -> spring-boot-starter-json-2.3.1.RELEASE.jar -> ❌ jackson-databind-2.11.0.jar (Vulnerable Library) |
5.9 | jackson-databind-2.11.0.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 | #36 | ||
CVE-953123-750181Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/jakarta/activation/jakarta.activation-api/1.2.2/jakarta.activation-api-1.2.2.jar Dependency Hierarchy: -> keycloak-saml-core-25.0.6.jar (Root Library) -> keycloak-saml-core-public-25.0.6.jar -> xmlsec-2.2.6.jar -> jakarta.xml.bind-api-2.3.3.jar -> ❌ jakarta.activation-api-1.2.2.jar (Vulnerable Library) |
9.8 | jakarta.activation-api-1.2.2.jar | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2013-4517 | xmlsec-1.5.1.jar |
| GHSA-4xx7-2cx3-x473 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2021-3827 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2013-5823 | xmlsec-1.5.1.jar |
| CVE-2023-44483 | xmlsec-1.5.1.jar |
| GHSA-q2gp-gph3-88x9 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2017-2646 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2017-2582 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2021-40690 | xmlsec-1.5.1.jar |
| CVE-2013-2172 | xmlsec-1.5.1.jar |
Base branch total remaining vulnerabilities: 93
Base branch commit: f9e0dc6866b5df73561aeec6122e14261d82ab4d
Total libraries scanned: 97
Scan token: 03ec05b881d94bf18c23c6be4ee107ba