Update dependency org.springframework.amqp:spring-rabbit to v3 #19
Security Report
You have successfully remediated 40 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|
CVE-2025-41242Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/6.1.0/spring-beans-6.1.0.jar Dependency Hierarchy: -> spring-rabbit-3.1.0.jar (Root Library) -> spring-context-6.1.0.jar -> spring-aop-6.1.0.jar -> ❌ spring-beans-6.1.0.jar (Vulnerable Library) |
5.9 | spring-beans-6.1.0.jar | Upgrade to version: org.springframework:spring-beans:6.2.10 | None | ||
CVE-2025-22233Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/6.1.0/spring-context-6.1.0.jar Dependency Hierarchy: -> spring-rabbit-3.1.0.jar (Root Library) -> ❌ spring-context-6.1.0.jar (Vulnerable Library) |
3.1 | spring-context-6.1.0.jar | Upgrade to version: https://github.com/spring-projects/spring-framework.git - v6.2.7 | None | ||
CVE-2024-38820Path to dependency file: /vprofile-project3/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/6.1.0/spring-context-6.1.0.jar Dependency Hierarchy: -> spring-rabbit-3.1.0.jar (Root Library) -> ❌ spring-context-6.1.0.jar (Vulnerable Library) |
3.1 | spring-context-6.1.0.jar | Upgrade to version: org.springframework:spring-context:6.1.14 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2018-11040 | spring-web-4.3.7.RELEASE.jar |
| CVE-2025-22233 | spring-context-4.3.7.RELEASE.jar |
| CVE-2022-22965 | spring-beans-4.3.7.RELEASE.jar |
| CVE-2023-20863 | spring-expression-4.3.7.RELEASE.jar |
| CVE-2024-38809 | spring-web-4.3.7.RELEASE.jar |
| CVE-2022-22970 | spring-core-4.3.7.RELEASE.jar |
| CVE-2018-1272 | spring-core-4.3.7.RELEASE.jar |
| CVE-2023-34050 | spring-amqp-1.7.1.RELEASE.jar |
| CVE-2024-22259 | spring-web-4.3.7.RELEASE.jar |
| CVE-2020-11022 | jquery-1.11.2.min.js |
| CVE-2021-22060 | spring-core-4.3.7.RELEASE.jar |
| CVE-2022-22970 | spring-beans-4.3.7.RELEASE.jar |
| CVE-2021-22096 | spring-core-4.3.7.RELEASE.jar |
| WS-2019-0379 | commons-codec-1.6.jar |
| CVE-2024-22243 | spring-web-4.3.7.RELEASE.jar |
| CVE-2022-22950 | spring-expression-4.3.7.RELEASE.jar |
| CVE-2018-1257 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2018-11087 | spring-rabbit-1.7.1.RELEASE.jar |
| CVE-2018-1275 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2018-11087 | spring-amqp-1.7.1.RELEASE.jar |
| WS-2017-3734 | httpclient-4.3.6.jar |
| CVE-2018-1270 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2016-1000027 | spring-web-4.3.7.RELEASE.jar |
| CVE-2024-38808 | spring-expression-4.3.7.RELEASE.jar |
| CVE-2023-20861 | spring-expression-4.3.7.RELEASE.jar |
| CVE-2024-38820 | spring-context-4.3.7.RELEASE.jar |
| CVE-2024-22262 | spring-web-4.3.7.RELEASE.jar |
| CVE-2018-15756 | spring-web-4.3.7.RELEASE.jar |
| CVE-2021-22096 | spring-web-4.3.7.RELEASE.jar |
| CVE-2018-1199 | spring-core-4.3.7.RELEASE.jar |
| CVE-2020-11023 | jquery-1.11.2.min.js |
| CVE-2020-5421 | spring-web-4.3.7.RELEASE.jar |
| CVE-2019-11358 | jquery-1.11.2.min.js |
| CVE-2015-9251 | jquery-1.11.2.min.js |
| CVE-2018-11039 | spring-web-4.3.7.RELEASE.jar |
| CVE-2017-8045 | spring-amqp-1.7.1.RELEASE.jar |
| CVE-2020-13956 | httpclient-4.3.6.jar |
| CVE-2022-22971 | spring-messaging-4.3.7.RELEASE.jar |
| CVE-2022-22968 | spring-context-4.3.7.RELEASE.jar |
| CVE-2025-41242 | spring-beans-4.3.7.RELEASE.jar |
Base branch total remaining vulnerabilities: 150
Base branch commit: c5002713c7a7db3119dd1b7c493918a56924c617
Total libraries scanned: 401
Scan token: 5a137d63d53c4e08bd521514db534c67