Skip to content

Update dependency org.springframework.amqp:spring-rabbit to v2

a4ffcf8
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.springframework.amqp:spring-rabbit to v2 #204

Update dependency org.springframework.amqp:spring-rabbit to v2
a4ffcf8
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Dec 11, 2025 in 8m 43s

Security Report

You have successfully remediated 69 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
WS-2019-0379

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar

Dependency Hierarchy:

-> transport-5.6.4.jar (Root Library)

   -> reindex-client-5.6.4.jar

     -> elasticsearch-rest-client-5.6.4.jar

       -> ❌ commons-codec-1.10.jar (Vulnerable Library)

Medium 6.5 Transitive commons-codec-1.10.jar transport-5.6.4.jar Transitive commons-codec:commons-codec:1.13 #39

Reachable

WS-2017-3734

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.2/httpclient-4.5.2.jar

Dependency Hierarchy:

-> transport-5.6.4.jar (Root Library)

   -> reindex-client-5.6.4.jar

     -> elasticsearch-rest-client-5.6.4.jar

       -> ❌ httpclient-4.5.2.jar (Vulnerable Library)

Medium 5.3 Transitive httpclient-4.5.2.jar transport-5.6.4.jar Transitive org.apache.httpcomponents:httpclient:4.5.3 #150

Reachable

CVE-2020-13956

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.2/httpclient-4.5.2.jar

Dependency Hierarchy:

-> transport-5.6.4.jar (Root Library)

   -> reindex-client-5.6.4.jar

     -> elasticsearch-rest-client-5.6.4.jar

       -> ❌ httpclient-4.5.2.jar (Vulnerable Library)

Medium 5.3 Transitive httpclient-4.5.2.jar transport-5.6.4.jar Transitive org.apache.httpcomponents:httpclient:4.5.13 #178

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-24750 jackson-databind-2.8.4.jar
CVE-2022-22968 spring-context-4.2.0.RELEASE.jar
CVE-2020-36185 jackson-databind-2.8.4.jar
CVE-2002-2010 commons-codec-1.6.jar
CVE-2020-10650 jackson-databind-2.8.4.jar
CVE-2020-35490 jackson-databind-2.8.4.jar
CVE-2020-11112 jackson-databind-2.8.4.jar
CVE-2020-14062 jackson-databind-2.8.4.jar
CVE-2018-14718 jackson-databind-2.8.4.jar
CVE-2017-17485 jackson-databind-2.8.4.jar
CVE-2019-16942 jackson-databind-2.8.4.jar
CVE-2020-36518 jackson-databind-2.8.4.jar
CVE-2020-36187 jackson-databind-2.8.4.jar
CVE-2018-12023 jackson-databind-2.8.4.jar
CVE-2020-14195 jackson-databind-2.8.4.jar
CVE-2020-9548 jackson-databind-2.8.4.jar
CVE-2020-36179 jackson-databind-2.8.4.jar
CVE-2018-19361 jackson-databind-2.8.4.jar
CVE-2020-36180 jackson-databind-2.8.4.jar
CVE-2020-36181 jackson-databind-2.8.4.jar
CVE-2019-17531 jackson-databind-2.8.4.jar
CVE-2021-20190 jackson-databind-2.8.4.jar
WS-2019-0379 commons-codec-1.6.jar
CVE-2018-14721 jackson-databind-2.8.4.jar
CVE-2020-35728 jackson-databind-2.8.4.jar
CVE-2018-1257 spring-messaging-4.3.7.RELEASE.jar
CVE-2018-19362 jackson-databind-2.8.4.jar
CVE-2018-11087 spring-rabbit-1.7.1.RELEASE.jar
CVE-2018-11087 spring-amqp-1.7.1.RELEASE.jar
WS-2017-3734 httpclient-4.3.6.jar
CVE-2019-16943 jackson-databind-2.8.4.jar
CVE-2018-1270 spring-messaging-4.3.7.RELEASE.jar
CVE-2019-14540 jackson-databind-2.8.4.jar
CVE-2020-10673 jackson-databind-2.8.4.jar
CVE-2020-36186 jackson-databind-2.8.4.jar
CVE-2020-35491 jackson-databind-2.8.4.jar
CVE-2018-19360 jackson-databind-2.8.4.jar
CVE-2019-20330 jackson-databind-2.8.4.jar
CVE-2020-11113 jackson-databind-2.8.4.jar
CVE-2017-7525 jackson-databind-2.8.4.jar
CVE-2018-11307 jackson-databind-2.8.4.jar
CVE-2022-25647 gson-2.8.2.jar
CVE-2020-11619 jackson-databind-2.8.4.jar
CVE-2018-18753 jackson-databind-2.8.4.jar
CVE-2020-24616 jackson-databind-2.8.4.jar
CVE-2020-36184 jackson-databind-2.8.4.jar
CVE-2020-36182 jackson-databind-2.8.4.jar
CVE-2020-25638 hibernate-core-4.3.11.Final.jar
CVE-2020-14061 jackson-databind-2.8.4.jar
CVE-2022-42004 jackson-databind-2.8.4.jar
CVE-2020-11620 jackson-databind-2.8.4.jar
CVE-2019-14893 jackson-databind-2.8.4.jar
CVE-2020-36189 jackson-databind-2.8.4.jar
CVE-2019-17267 jackson-databind-2.8.4.jar
CVE-2022-42003 jackson-databind-2.8.4.jar
CVE-2018-14720 jackson-databind-2.8.4.jar
CVE-2019-14892 jackson-databind-2.8.4.jar
CVE-2020-25649 jackson-databind-2.8.4.jar
CVE-2017-8045 spring-amqp-1.7.1.RELEASE.jar
CVE-2020-13956 httpclient-4.3.6.jar
CVE-2020-36188 jackson-databind-2.8.4.jar
CVE-2020-11111 jackson-databind-2.8.4.jar
CVE-2020-14060 jackson-databind-2.8.4.jar
CVE-2019-14439 jackson-databind-2.8.4.jar
CVE-2018-5968 jackson-databind-2.8.4.jar
CVE-2018-14719 jackson-databind-2.8.4.jar
CVE-2019-10202 jackson-databind-2.8.4.jar
CVE-2020-36183 jackson-databind-2.8.4.jar
CVE-2019-14379 jackson-databind-2.8.4.jar

Base branch total remaining vulnerabilities: 175
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9


Total libraries scanned: 105

Scan token: 7d6971ae320a45dc8772306f13b77e15