Update dependency org.springframework.amqp:spring-rabbit to v2 #204
Security Report
You have successfully remediated 69 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
WS-2019-0379Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar Dependency Hierarchy: -> transport-5.6.4.jar (Root Library) -> reindex-client-5.6.4.jar -> elasticsearch-rest-client-5.6.4.jar -> ❌ commons-codec-1.10.jar (Vulnerable Library) |
6.5 | Transitive commons-codec-1.10.jar |
transport-5.6.4.jar | Transitive commons-codec:commons-codec:1.13 |
#39 | ||
WS-2017-3734Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.2/httpclient-4.5.2.jar Dependency Hierarchy: -> transport-5.6.4.jar (Root Library) -> reindex-client-5.6.4.jar -> elasticsearch-rest-client-5.6.4.jar -> ❌ httpclient-4.5.2.jar (Vulnerable Library) |
5.3 | Transitive httpclient-4.5.2.jar |
transport-5.6.4.jar | Transitive org.apache.httpcomponents:httpclient:4.5.3 |
#150 | ||
CVE-2020-13956Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/httpcomponents/httpclient/4.5.2/httpclient-4.5.2.jar Dependency Hierarchy: -> transport-5.6.4.jar (Root Library) -> reindex-client-5.6.4.jar -> elasticsearch-rest-client-5.6.4.jar -> ❌ httpclient-4.5.2.jar (Vulnerable Library) |
5.3 | Transitive httpclient-4.5.2.jar |
transport-5.6.4.jar | Transitive org.apache.httpcomponents:httpclient:4.5.13 |
#178 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-24750 | jackson-databind-2.8.4.jar |
| CVE-2022-22968 | spring-context-4.2.0.RELEASE.jar |
| CVE-2020-36185 | jackson-databind-2.8.4.jar |
| CVE-2002-2010 | commons-codec-1.6.jar |
| CVE-2020-10650 | jackson-databind-2.8.4.jar |
| CVE-2020-35490 | jackson-databind-2.8.4.jar |
| CVE-2020-11112 | jackson-databind-2.8.4.jar |
| CVE-2020-14062 | jackson-databind-2.8.4.jar |
| CVE-2018-14718 | jackson-databind-2.8.4.jar |
| CVE-2017-17485 | jackson-databind-2.8.4.jar |
| CVE-2019-16942 | jackson-databind-2.8.4.jar |
| CVE-2020-36518 | jackson-databind-2.8.4.jar |
| CVE-2020-36187 | jackson-databind-2.8.4.jar |
| CVE-2018-12023 | jackson-databind-2.8.4.jar |
| CVE-2020-14195 | jackson-databind-2.8.4.jar |
| CVE-2020-9548 | jackson-databind-2.8.4.jar |
| CVE-2020-36179 | jackson-databind-2.8.4.jar |
| CVE-2018-19361 | jackson-databind-2.8.4.jar |
| CVE-2020-36180 | jackson-databind-2.8.4.jar |
| CVE-2020-36181 | jackson-databind-2.8.4.jar |
| CVE-2019-17531 | jackson-databind-2.8.4.jar |
| CVE-2021-20190 | jackson-databind-2.8.4.jar |
| WS-2019-0379 | commons-codec-1.6.jar |
| CVE-2018-14721 | jackson-databind-2.8.4.jar |
| CVE-2020-35728 | jackson-databind-2.8.4.jar |
| CVE-2018-1257 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2018-19362 | jackson-databind-2.8.4.jar |
| CVE-2018-11087 | spring-rabbit-1.7.1.RELEASE.jar |
| CVE-2018-11087 | spring-amqp-1.7.1.RELEASE.jar |
| WS-2017-3734 | httpclient-4.3.6.jar |
| CVE-2019-16943 | jackson-databind-2.8.4.jar |
| CVE-2018-1270 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2019-14540 | jackson-databind-2.8.4.jar |
| CVE-2020-10673 | jackson-databind-2.8.4.jar |
| CVE-2020-36186 | jackson-databind-2.8.4.jar |
| CVE-2020-35491 | jackson-databind-2.8.4.jar |
| CVE-2018-19360 | jackson-databind-2.8.4.jar |
| CVE-2019-20330 | jackson-databind-2.8.4.jar |
| CVE-2020-11113 | jackson-databind-2.8.4.jar |
| CVE-2017-7525 | jackson-databind-2.8.4.jar |
| CVE-2018-11307 | jackson-databind-2.8.4.jar |
| CVE-2022-25647 | gson-2.8.2.jar |
| CVE-2020-11619 | jackson-databind-2.8.4.jar |
| CVE-2018-18753 | jackson-databind-2.8.4.jar |
| CVE-2020-24616 | jackson-databind-2.8.4.jar |
| CVE-2020-36184 | jackson-databind-2.8.4.jar |
| CVE-2020-36182 | jackson-databind-2.8.4.jar |
| CVE-2020-25638 | hibernate-core-4.3.11.Final.jar |
| CVE-2020-14061 | jackson-databind-2.8.4.jar |
| CVE-2022-42004 | jackson-databind-2.8.4.jar |
| CVE-2020-11620 | jackson-databind-2.8.4.jar |
| CVE-2019-14893 | jackson-databind-2.8.4.jar |
| CVE-2020-36189 | jackson-databind-2.8.4.jar |
| CVE-2019-17267 | jackson-databind-2.8.4.jar |
| CVE-2022-42003 | jackson-databind-2.8.4.jar |
| CVE-2018-14720 | jackson-databind-2.8.4.jar |
| CVE-2019-14892 | jackson-databind-2.8.4.jar |
| CVE-2020-25649 | jackson-databind-2.8.4.jar |
| CVE-2017-8045 | spring-amqp-1.7.1.RELEASE.jar |
| CVE-2020-13956 | httpclient-4.3.6.jar |
| CVE-2020-36188 | jackson-databind-2.8.4.jar |
| CVE-2020-11111 | jackson-databind-2.8.4.jar |
| CVE-2020-14060 | jackson-databind-2.8.4.jar |
| CVE-2019-14439 | jackson-databind-2.8.4.jar |
| CVE-2018-5968 | jackson-databind-2.8.4.jar |
| CVE-2018-14719 | jackson-databind-2.8.4.jar |
| CVE-2019-10202 | jackson-databind-2.8.4.jar |
| CVE-2020-36183 | jackson-databind-2.8.4.jar |
| CVE-2019-14379 | jackson-databind-2.8.4.jar |
Base branch total remaining vulnerabilities: 175
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9
Total libraries scanned: 105
Scan token: 7d6971ae320a45dc8772306f13b77e15