Update spring.version to v6 (major) #216
Security Report
You have successfully remediated 69 vulnerabilities, but introduced 15 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2024-22259Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | Direct spring-web-6.0.0.jar |
spring-web-6.0.0.jar | org.springframework:spring-web:6.1.5,org.springframework:spring-web:6.0.18,org.springframework:spring-web:5.3.33 | None | ||
CVE-2024-22243Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
8.1 | Direct spring-web-6.0.0.jar |
spring-web-6.0.0.jar | org.springframework:spring-web:6.1.4,org.springframework:spring-web:5.3.32,org.springframework:spring-web:6.0.17 | None | ||
CVE-2025-41249Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar Dependency Hierarchy: -> spring-web-6.0.0.jar (Root Library) -> spring-beans-6.0.0.jar -> ❌ spring-core-6.0.0.jar (Vulnerable Library) |
7.5 | Transitive spring-core-6.0.0.jar |
spring-web-6.0.0.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11 |
None | ||
CVE-2024-38819Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | Direct spring-webmvc-6.0.0.jar |
spring-webmvc-6.0.0.jar | org.springframework:spring-webmvc:6.1.14,org.springframework:spring-webflux:6.1.14 | None | ||
CVE-2023-20860Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
7.5 | Direct spring-webmvc-6.0.0.jar |
spring-webmvc-6.0.0.jar | org.springframework:spring-webmvc:6.0.7,org.springframework:spring-webmvc:5.3.26,org.springframework:spring-webmvc:5.3.26,org.springframework:spring-webmvc:6.0.7,org.springframework:spring:5.3.26 | None | ||
CVE-2025-41234Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
6.5 | Direct spring-web-6.0.0.jar |
spring-web-6.0.0.jar | org.springframework:spring-web:6.1.21,org.springframework:spring-web:6.2.8,https://github.com/spring-projects/spring-framework.git - v6.1.21,https://github.com/spring-projects/spring-framework.git - v6.2.8 | None | ||
CVE-2023-20863Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> spring-webmvc-6.0.0.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | Transitive spring-expression-6.0.0.jar |
spring-webmvc-6.0.0.jar | Transitive 6.0.8 |
#184 | ||
CVE-2023-20861Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar Dependency Hierarchy: -> spring-webmvc-6.0.0.jar (Root Library) -> spring-context-6.0.0.jar -> ❌ spring-expression-6.0.0.jar (Vulnerable Library) |
6.5 | Transitive spring-expression-6.0.0.jar |
spring-webmvc-6.0.0.jar | Transitive 6.0.7 |
#183 | ||
CVE-2025-41242Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
5.9 | Direct spring-webmvc-6.0.0.jar |
spring-webmvc-6.0.0.jar | https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 | None | ||
CVE-2024-38809Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
5.3 | Direct spring-web-6.0.0.jar |
spring-web-6.0.0.jar | org.springframework:spring-web:6.0.23,org.springframework:spring-web:6.1.12,org.springframework:spring-web:5.3.38 | None | ||
CVE-2025-22233Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/6.0.0/spring-context-6.0.0.jar Dependency Hierarchy: -> spring-webmvc-6.0.0.jar (Root Library) -> ❌ spring-context-6.0.0.jar (Vulnerable Library) |
3.1 | Transitive spring-context-6.0.0.jar |
spring-webmvc-6.0.0.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.1.20 ,org.springframework:spring-context:6.1.20,org.springframework:spring-context:6.2.7,https://github.com/spring-projects/spring-framework.git - v6.2.7 |
None | ||
CVE-2024-38820Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar Dependency Hierarchy: -> ❌ spring-web-6.0.0.jar (Vulnerable Library) |
3.1 | Direct spring-web-6.0.0.jar |
spring-web-6.0.0.jar | org.springframework:spring-context:6.1.14 | None | ||
CVE-2018-1257Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar Dependency Hierarchy: -> spring-web-6.0.0.jar (Root Library) -> spring-beans-6.0.0.jar -> ❌ spring-core-6.0.0.jar (Vulnerable Library) |
6.5 | Transitive spring-core-6.0.0.jar |
spring-web-6.0.0.jar | Transitive 5.0.6,4.3.17 |
#148 | ||
CVE-2018-1271Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar Dependency Hierarchy: -> spring-web-6.0.0.jar (Root Library) -> spring-beans-6.0.0.jar -> ❌ spring-core-6.0.0.jar (Vulnerable Library) |
5.9 | Transitive spring-core-6.0.0.jar |
spring-web-6.0.0.jar | Transitive org.springframework:spring-webflux:5.0.5.RELEASE,org.springframework:spring-webmvc:4.3.15.RELEASE,5.0.5.RELEASE |
#109 | ||
CVE-2023-34053Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library) |
5.3 | Direct spring-webmvc-6.0.0.jar |
spring-webmvc-6.0.0.jar | org.springframework:spring-webmvc:6.0.14 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-24750 | jackson-databind-2.8.4.jar |
| CVE-2020-36185 | jackson-databind-2.8.4.jar |
| CVE-2020-10650 | jackson-databind-2.8.4.jar |
| CVE-2020-11112 | jackson-databind-2.8.4.jar |
| CVE-2024-38820 | spring-web-4.2.0.RELEASE.jar |
| CVE-2018-15756 | spring-core-4.2.0.RELEASE.jar |
| CVE-2020-14062 | jackson-databind-2.8.4.jar |
| CVE-2018-15756 | spring-web-4.2.0.RELEASE.jar |
| CVE-2018-14718 | jackson-databind-2.8.4.jar |
| CVE-2020-36518 | jackson-databind-2.8.4.jar |
| CVE-2018-1271 | spring-core-4.2.0.RELEASE.jar |
| CVE-2020-36187 | jackson-databind-2.8.4.jar |
| CVE-2024-38808 | spring-expression-4.2.0.RELEASE.jar |
| CVE-2025-41249 | spring-core-4.2.0.RELEASE.jar |
| CVE-2020-14195 | jackson-databind-2.8.4.jar |
| CVE-2018-1257 | spring-core-4.2.0.RELEASE.jar |
| CVE-2020-9548 | jackson-databind-2.8.4.jar |
| CVE-2016-1000027 | spring-web-4.2.0.RELEASE.jar |
| CVE-2020-36179 | jackson-databind-2.8.4.jar |
| CVE-2018-19361 | jackson-databind-2.8.4.jar |
| CVE-2016-5007 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2023-20861 | spring-expression-4.2.0.RELEASE.jar |
| GHSA-257q-pv89-v3xv | jquery-3.2.1.min.js |
| CVE-2020-36180 | jackson-databind-2.8.4.jar |
| CVE-2018-1271 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2020-36181 | jackson-databind-2.8.4.jar |
| CVE-2019-17531 | jackson-databind-2.8.4.jar |
| CVE-2025-22233 | spring-context-4.2.0.RELEASE.jar |
| CVE-2024-38819 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2015-5211 | spring-web-4.2.0.RELEASE.jar |
| CVE-2018-14721 | jackson-databind-2.8.4.jar |
| CVE-2018-19362 | jackson-databind-2.8.4.jar |
| WS-2016-7112 | spring-context-4.2.0.RELEASE.jar |
| CVE-2021-22096 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2019-14540 | jackson-databind-2.8.4.jar |
| CVE-2020-10673 | jackson-databind-2.8.4.jar |
| CVE-2020-36186 | jackson-databind-2.8.4.jar |
| CVE-2018-1272 | spring-core-4.2.0.RELEASE.jar |
| CVE-2020-5421 | spring-web-4.2.0.RELEASE.jar |
| CVE-2020-11113 | jackson-databind-2.8.4.jar |
| CVE-2022-25647 | gson-2.8.2.jar |
| CVE-2020-11619 | jackson-databind-2.8.4.jar |
| CVE-2023-20863 | spring-expression-4.2.0.RELEASE.jar |
| CVE-2024-22259 | spring-web-4.2.0.RELEASE.jar |
| CVE-2020-24616 | jackson-databind-2.8.4.jar |
| CVE-2020-36184 | jackson-databind-2.8.4.jar |
| CVE-2024-22243 | spring-web-4.2.0.RELEASE.jar |
| CVE-2020-36182 | jackson-databind-2.8.4.jar |
| CVE-2015-5211 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2020-25638 | hibernate-core-4.3.11.Final.jar |
| CVE-2020-14061 | jackson-databind-2.8.4.jar |
| CVE-2020-11620 | jackson-databind-2.8.4.jar |
| CVE-2019-14893 | jackson-databind-2.8.4.jar |
| CVE-2024-38809 | spring-web-4.2.0.RELEASE.jar |
| CVE-2020-36189 | jackson-databind-2.8.4.jar |
| CVE-2022-22965 | spring-beans-4.2.0.RELEASE.jar |
| CVE-2018-14720 | jackson-databind-2.8.4.jar |
| CVE-2019-14892 | jackson-databind-2.8.4.jar |
| CVE-2020-36188 | jackson-databind-2.8.4.jar |
| CVE-2021-22096 | spring-web-4.2.0.RELEASE.jar |
| CVE-2016-9878 | spring-webmvc-4.2.0.RELEASE.jar |
| CVE-2020-11111 | jackson-databind-2.8.4.jar |
| CVE-2020-14060 | jackson-databind-2.8.4.jar |
| CVE-2019-14439 | jackson-databind-2.8.4.jar |
| CVE-2018-5968 | jackson-databind-2.8.4.jar |
| CVE-2022-22970 | spring-core-4.2.0.RELEASE.jar |
| CVE-2018-14719 | jackson-databind-2.8.4.jar |
| CVE-2020-36183 | jackson-databind-2.8.4.jar |
| CVE-2019-14379 | jackson-databind-2.8.4.jar |
Base branch total remaining vulnerabilities: 186
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9
Total libraries scanned: 110
Scan token: 43fcfee3da134256bf050121fc80eda2