Skip to content

Conversation

@muldos
Copy link
Owner

@muldos muldos commented Nov 29, 2022

No description provided.

@github-actions
Copy link

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

Medium
org.yaml:snakeyaml 1.28 org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

@muldos muldos temporarily deployed to frogbot December 6, 2022 17:18 Inactive
@github-actions
Copy link

github-actions bot commented Dec 6, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

@muldos muldos temporarily deployed to frogbot December 8, 2022 18:53 — with GitHub Actions Inactive
@github-actions
Copy link

github-actions bot commented Dec 8, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

@muldos muldos temporarily deployed to frogbot December 8, 2022 18:58 — with GitHub Actions Inactive
@muldos muldos temporarily deployed to frogbot December 8, 2022 18:59 — with GitHub Actions Inactive
@github-actions
Copy link

github-actions bot commented Dec 8, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

@github-actions
Copy link

github-actions bot commented Dec 8, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

@muldos muldos temporarily deployed to frogbot December 8, 2022 19:32 — with GitHub Actions Inactive
@github-actions
Copy link

github-actions bot commented Dec 8, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

@gitguardian
Copy link

gitguardian bot commented Dec 9, 2022

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id Secret Commit Filename
5155551 Generic High Entropy Secret 27153eb fake-creds.txt View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

@muldos muldos temporarily deployed to frogbot December 9, 2022 12:54 — with GitHub Actions Inactive
@github-actions
Copy link

github-actions bot commented Dec 9, 2022

What is Frogbot?

SEVERITY IMPACTED PACKAGE VERSION FIXED VERSIONS COMPONENT COMPONENT VERSION CVE

Critical
org.springframework:spring-web 5.3.20 [6.0.0] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2016-1000027

High
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-25857

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4.1] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42003

High
com.fasterxml.jackson.core:jackson-databind 2.12.6.1 [2.12.7.1] [2.13.4] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42004

High
org.apache.tomcat.embed:tomcat-embed-core 9.0.63 [10.0.27] [10.1.1] [8.5.53] [9.0.68] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-42252

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-41854

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38750

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38749

Medium
org.yaml:snakeyaml 1.28 [1.31] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38751

Medium
org.yaml:snakeyaml 1.28 [1.32] org.springframework.boot:spring-boot-starter-web 2.5.14 CVE-2022-38752

Medium
org.jetbrains.kotlin:kotlin-stdlib 1.5.32 [1.6.0] com.netflix.graphql.dgs:graphql-dgs-spring-boot-starter 5.4.3 CVE-2022-24329

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants