[Snyk] Fix for 2 vulnerabilities - #1839
Conversation
…ities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-TOOLSJACKSONCORE-18170128 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609
|
This update includes patch-level upgrades for two Spring components. The Spring Web (6.2.10 → 6.2.19)Risk: Medium This is a series of security-focused patch releases within the 6.2.x line. While patch releases are intended to be non-breaking, the fixes for some vulnerabilities can introduce behavioral changes that require verification.
Recommendation: While this is a patch upgrade, the number of security fixes warrants careful testing. Pay special attention to areas that use the Spring Expression Language (SpEL) or handle multipart requests. Spring Boot Starter JSON (4.0.0 → 4.0.7)Risk: Low This is a routine patch release for Spring Boot. The announcement for version 4.0.7 indicates it includes bug fixes, documentation improvements, and dependency upgrades, with no documented breaking changes. It also resolves two CVEs unrelated to the JSON starter itself.
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
examples/iOS-Hybrid-App-Java-Server/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-TOOLSJACKSONCORE-18170128
4.0.0->4.0.7Proof of ConceptSNYK-JAVA-ORGSPRINGFRAMEWORK-18326609
6.2.10->6.2.19No Known ExploitBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Deserialization of Untrusted Data
🦉 Allocation of Resources Without Limits or Throttling