[Snyk] Fix for 2 vulnerabilities - #1835
Conversation
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-15365915 - https://snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-15371178
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-18170128 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-18170128 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609
|
This update includes two patch-level upgrades. The upgrade for org.springframework:spring-web@6.2.17 → 6.2.19 (Medium Risk) This is a security-focused release that addresses numerous CVEs in the web layer (Spring MVC and WebFlux). [13] Key changes include:
Recommendation: After upgrading, verify application functionality related to file serving, URL redirects, complex SpEL expressions, and JMS message conversion to ensure these security enhancements do not cause regressions. org.springframework.boot:spring-boot-starter-json@4.0.0 → 4.0.7 (Low Risk) This is a routine patch release for Spring Boot. It bundles bug fixes, documentation improvements, and dependency upgrades, including patches for two CVEs (CVE-2026-40992, CVE-2026-41001). [8] No breaking API changes are documented for this range.
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
examples/iOS-Hybrid-App-Java-Server/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-TOOLSJACKSONCORE-18170128
4.0.0->4.0.7Proof of ConceptSNYK-JAVA-ORGSPRINGFRAMEWORK-18326609
6.2.17->6.2.19No Known ExploitBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Deserialization of Untrusted Data
🦉 Allocation of Resources Without Limits or Throttling