Skip to content

fix(deps): update mend: high confidence minor and patch dependency updates - autoclosed - #52

Closed
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
Closed

fix(deps): update mend: high confidence minor and patch dependency updates - autoclosed#52
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates

fix(deps): update mend: high confidence minor and patch dependency up…

2cfb77d
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed May 1, 2026 in 4m 6s

Security Report

You have successfully remediated 127 vulnerabilities, but introduced 72 new vulnerabilities in this branch.

❌ New vulnerabilities:

Partial results (42 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.


Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-12543

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

Critical 9.6 Not Defined 0.041% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.39.Final None

Reachable

CVE-2026-22732

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-web/5.7.11/spring-security-web-5.7.11.jar

Dependency Hierarchy:

-> spring-boot-starter-security-2.7.18.jar (Root Library)

   -> ❌ spring-security-web-5.7.11.jar (Vulnerable Library)

Critical 9.1 Not Defined 0.027% Transitive spring-security-web-5.7.11.jar spring-boot-starter-security-2.7.18.jar Transitive https://github.com/spring-projects/spring-security.git - 7.0.4,https://github.com/spring-projects/spring-security.git - 6.5.9 None

Reachable

CVE-2024-22257

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-core/5.7.11/spring-security-core-5.7.11.jar

Dependency Hierarchy:

-> spring-boot-starter-security-2.7.18.jar (Root Library)

   -> spring-security-config-5.7.11.jar

     -> ❌ spring-security-core-5.7.11.jar (Vulnerable Library)

High 8.2 Not Defined 0.264% Transitive spring-security-core-5.7.11.jar spring-boot-starter-security-2.7.18.jar Transitive 5.7.12 None

Reachable

CVE-2024-22262

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High 8.1 Not Defined 12.634% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 5.3.34 None

Reachable

CVE-2024-22259

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High 8.1 Not Defined 56.395% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 5.3.33 None

Reachable

CVE-2024-22243

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High 8.1 Not Defined 59.593% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 5.3.32 None

Reachable

WS-2026-0003

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> jackson-databind-2.13.5.jar

       -> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High 7.5 Not Defined Transitive jackson-core-2.13.5.jar spring-boot-starter-web-2.7.18.jar Transitive 2.18.6 None

Reachable

WS-2022-0468

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> jackson-databind-2.13.5.jar

       -> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High 7.5 Not Defined Transitive jackson-core-2.13.5.jar spring-boot-starter-web-2.7.18.jar Transitive 2.15.0-rc1 None

Reachable

CVE-2026-22754

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-config/5.7.11/spring-security-config-5.7.11.jar

Dependency Hierarchy:

-> spring-boot-starter-security-2.7.18.jar (Root Library)

   -> ❌ spring-security-config-5.7.11.jar (Vulnerable Library)

High 7.5 Not Defined 0.047% Transitive spring-security-config-5.7.11.jar spring-boot-starter-security-2.7.18.jar Transitive 6.3.15 None

Reachable

CVE-2026-22753

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-config/5.7.11/spring-security-config-5.7.11.jar

Dependency Hierarchy:

-> spring-boot-starter-security-2.7.18.jar (Root Library)

   -> ❌ spring-security-config-5.7.11.jar (Vulnerable Library)

High 7.5 Not Defined 0.068% Transitive spring-security-config-5.7.11.jar spring-boot-starter-security-2.7.18.jar Transitive 6.3.15 None

Reachable

CVE-2025-9784

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 1.553% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.38.Final None

Reachable

CVE-2025-52999

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> jackson-databind-2.13.5.jar

       -> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High 7.5 Not Defined 0.252% Transitive jackson-core-2.13.5.jar spring-boot-starter-web-2.7.18.jar Transitive 2.15.0 None

Reachable

CVE-2025-41249

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-2.7.18.jar

       -> ❌ spring-core-5.3.31.jar (Vulnerable Library)

High 7.5 Not Defined 0.069% Transitive spring-core-5.3.31.jar spring-boot-starter-validation-2.7.18.jar Transitive https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11 None

Reachable

CVE-2024-7885

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 10.699% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.3.17.Final None

Reachable

CVE-2024-6162

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 2.024% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.33.Final None

Reachable

CVE-2024-5971

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 3.699% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.35.Final None

Reachable

CVE-2024-4027

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 0.3% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.39.Final None

Reachable

CVE-2024-3884

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 0.382% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.39.Final None

Reachable

CVE-2024-38819

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

High 7.5 Not Defined 92.565% Transitive spring-webmvc-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 6.1.14 None

Reachable

CVE-2024-38816

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

High 7.5 Not Defined 93.877% Transitive spring-webmvc-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 6.1.13 None

Reachable

CVE-2024-1635

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 23.144% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.31.Final None

Reachable

CVE-2023-5379

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 0.161% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.31.Final None

Reachable

CVE-2023-1973

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.5 Not Defined 0.727% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.33.Final None

Reachable

CVE-2025-22228

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-crypto/5.7.11/spring-security-crypto-5.7.11.jar

Dependency Hierarchy:

-> spring-boot-starter-security-2.7.18.jar (Root Library)

   -> spring-security-config-5.7.11.jar

     -> spring-security-core-5.7.11.jar

       -> ❌ spring-security-crypto-5.7.11.jar (Vulnerable Library)

High 7.4 Not Defined 0.065% Transitive spring-security-crypto-5.7.11.jar spring-boot-starter-security-2.7.18.jar Transitive https://github.com/spring-projects/spring-security.git - 6.4.4,https://github.com/spring-projects/spring-security.git - 6.3.8,org.springframework.security:spring-security-crypto:6.4.4,org.springframework.security:spring-security-crypto:6.3.8 None

Reachable

CVE-2023-4639

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

High 7.4 Not Defined 7.36% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive 2.2.31.Final None

Reachable

CVE-2025-22235

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

High 7.3 Functional 0.39% Transitive spring-boot-2.7.18.jar spring-boot-starter-validation-2.7.18.jar Transitive https://github.com/spring-projects/spring-boot.git - v3.4.5,https://github.com/spring-projects/spring-boot.git - v3.3.11,org.springframework.boot:spring-boot-actuator-autoconfigure:3.4.5,org.springframework.boot:spring-boot-actuator-autoconfigure:3.3.11 None

Reachable

CVE-2024-12798

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-starter-logging-2.7.18.jar

       -> ❌ logback-classic-1.2.12.jar (Vulnerable Library)

High 7.3 Not Defined 0.124% Transitive logback-classic-1.2.12.jar spring-boot-starter-validation-2.7.18.jar Transitive 1.3.15 None

Reachable

CVE-2024-12798

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-starter-logging-2.7.18.jar

       -> logback-classic-1.2.12.jar

         -> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High 7.3 Not Defined 0.124% Transitive logback-core-1.2.12.jar spring-boot-starter-validation-2.7.18.jar Transitive 1.3.15 None

Reachable

CVE-2023-6481

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-starter-logging-2.7.18.jar

       -> logback-classic-1.2.12.jar

         -> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High 7.1 Not Defined 0.224% Transitive logback-core-1.2.12.jar spring-boot-starter-validation-2.7.18.jar Transitive 1.2.13 None

Reachable

CVE-2023-6378

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-starter-logging-2.7.18.jar

       -> ❌ logback-classic-1.2.12.jar (Vulnerable Library)

High 7.1 Not Defined 0.613% Transitive logback-classic-1.2.12.jar spring-boot-starter-validation-2.7.18.jar Transitive ch.qos.logback:logback-classic:1.3.12,1.4.12 None

Reachable

CVE-2023-6378

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-starter-logging-2.7.18.jar

       -> logback-classic-1.2.12.jar

         -> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High 7.1 Not Defined 0.613% Transitive logback-core-1.2.12.jar spring-boot-starter-validation-2.7.18.jar Transitive ch.qos.logback:logback-classic:1.3.12,1.4.12 None

Reachable

CVE-2026-40973

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

High 7.0 Not Defined 0.014% Transitive spring-boot-2.7.18.jar spring-boot-starter-validation-2.7.18.jar Transitive 2.7.33 None

Reachable

CVE-2026-22740

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium 6.5 Not Defined 0.046% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive org.springframework:spring-web:6.2.18,https://github.com/spring-projects/spring-framework.git - v7.0.7,org.springframework:spring-web:7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18 None

Reachable

CVE-2026-3260

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar

Dependency Hierarchy:

-> spring-boot-starter-undertow-2.7.18.jar (Root Library)

   -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library)

Medium 5.9 Not Defined 0.641% Transitive undertow-core-2.2.28.Final.jar spring-boot-starter-undertow-2.7.18.jar Transitive io.undertow:undertow-core:2.4.0.Beta1 None

Reachable

CVE-2026-22737

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium 5.9 Not Defined 0.092% Transitive spring-webmvc-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive org.springframework:spring-webflux:6.2.17,org.springframework:spring-webflux:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6 None

Reachable

CVE-2025-41242

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.3.31/spring-beans-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-2.7.18.jar

       -> spring-context-5.3.31.jar

         -> spring-aop-5.3.31.jar

           -> ❌ spring-beans-5.3.31.jar (Vulnerable Library)

Medium 5.9 Not Defined 0.087% Transitive spring-beans-5.3.31.jar spring-boot-starter-validation-2.7.18.jar Transitive https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 None

Reachable

CVE-2025-41242

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium 5.9 Not Defined 0.087% Transitive spring-webmvc-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 None

Reachable

CVE-2023-2976

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/guava/guava/30.1.1-jre/guava-30.1.1-jre.jar

Dependency Hierarchy:

-> ❌ guava-30.1.1-jre.jar (Vulnerable Library)

Medium 5.5 Not Defined 0.065% Direct guava-30.1.1-jre.jar guava-30.1.1-jre.jar 32.0.1-android None

Reachable

CVE-2024-38828

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-validation-2.7.18.jar (Root Library)

   -> spring-boot-starter-2.7.18.jar

     -> spring-boot-2.7.18.jar

       -> ❌ spring-core-5.3.31.jar (Vulnerable Library)

Medium 5.3 Not Defined 0.076% Transitive spring-core-5.3.31.jar spring-boot-starter-validation-2.7.18.jar None

Reachable

CVE-2024-38828

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium 5.3 Not Defined 0.076% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 6.0.0 None

Reachable

CVE-2024-38828

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium 5.3 Not Defined 0.076% Transitive spring-webmvc-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 6.0.0 None

Reachable

CVE-2024-38809

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

   -> spring-boot-starter-json-2.7.18.jar

     -> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium 5.3 Not Defined 0.14% Transitive spring-web-5.3.31.jar spring-boot-starter-web-2.7.18.jar Transitive 5.3.38 None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2022-31692 spring-security-core-5.7.2.jar
CVE-2026-40973 spring-boot-2.7.1.jar
CVE-2024-38809 spring-web-5.3.21.jar
CVE-2021-21346 xstream-1.4.5.jar
CVE-2026-40974 spring-boot-autoconfigure-2.7.1.jar
CVE-2026-1225 logback-core-1.2.11.jar
CVE-2025-22228 spring-security-crypto-5.7.2.jar
CVE-2023-3223 undertow-servlet-2.2.18.Final.jar
CVE-2026-22746 spring-security-core-5.7.2.jar
CVE-2016-1000027 spring-web-5.3.21.jar
CVE-2021-39145 xstream-1.4.5.jar
CVE-2026-40975 spring-boot-2.7.1.jar
CVE-2022-41966 xstream-1.4.5.jar
WS-2026-0003 jackson-core-2.13.3.jar
CVE-2026-22735 spring-web-5.3.21.jar
CVE-2024-7885 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-context-5.3.21.jar
CVE-2026-22732 spring-security-web-5.7.2.jar
CVE-2021-21344 xstream-1.4.5.jar
CVE-2024-5971 undertow-core-2.2.18.Final.jar
CVE-2021-21345 xstream-1.4.5.jar
CVE-2025-41242 spring-beans-5.3.21.jar
CVE-2025-9784 undertow-core-2.2.18.Final.jar
CVE-2023-51775 jose4j-0.9.3.jar
CVE-2023-4639 undertow-core-2.2.18.Final.jar
CVE-2025-12543 undertow-core-2.2.18.Final.jar
CVE-2025-41249 spring-core-5.3.21.jar
CVE-2022-2053 undertow-core-2.2.18.Final.jar
CVE-2025-22233 spring-context-5.3.21.jar
CVE-2023-1973 undertow-core-2.2.18.Final.jar
CVE-2024-38828 spring-webmvc-5.3.21.jar
CVE-2026-22733 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2024-38816 spring-webmvc-5.3.21.jar
CVE-2021-21350 xstream-1.4.5.jar
CVE-2021-39148 xstream-1.4.5.jar
CVE-2024-12798 logback-core-1.2.11.jar
CVE-2023-34055 spring-boot-actuator-2.7.1.jar
CVE-2020-26258 xstream-1.4.5.jar
CVE-2023-20862 spring-security-core-5.7.2.jar
CVE-2024-38827 spring-security-core-5.7.2.jar
CVE-2019-10173 xstream-1.4.5.jar
CVE-2023-20863 spring-expression-5.3.21.jar
CVE-2025-41242 spring-webmvc-5.3.21.jar
CVE-2026-3260 undertow-core-2.2.18.Final.jar
CVE-2024-38828 spring-web-5.3.21.jar
CVE-2024-22262 spring-web-5.3.21.jar
CVE-2021-21349 xstream-1.4.5.jar
CVE-2026-22735 spring-webmvc-5.3.21.jar
CVE-2024-38819 spring-webmvc-5.3.21.jar
CVE-2017-7957 xstream-1.4.5.jar
CVE-2023-6378 logback-core-1.2.11.jar
CVE-2024-22259 spring-web-5.3.21.jar
CVE-2021-39151 xstream-1.4.5.jar
CVE-2021-21347 xstream-1.4.5.jar
CVE-2021-39141 xstream-1.4.5.jar
CVE-2026-22737 spring-webmvc-5.3.21.jar
CVE-2023-20860 spring-webmvc-5.3.21.jar
CVE-2026-22733 spring-boot-starter-actuator-2.7.1.jar
CVE-2024-22257 spring-security-core-5.7.2.jar
CVE-2025-52999 jackson-core-2.13.3.jar
CVE-2024-12798 logback-classic-1.2.11.jar
CVE-2021-21342 xstream-1.4.5.jar
WS-2022-0468 jackson-core-2.13.3.jar
CVE-2021-39146 xstream-1.4.5.jar
CVE-2026-22754 spring-security-config-5.7.2.jar
CVE-2022-1259 undertow-core-2.2.18.Final.jar
CVE-2026-40977 spring-boot-2.7.1.jar
CVE-2024-47072 xstream-1.4.5.jar
CVE-2024-4027 undertow-core-2.2.18.Final.jar
CVE-2023-2976 guava-30.1-jre.jar
CVE-2024-38828 spring-core-5.3.21.jar
CVE-2022-31692 spring-security-web-5.7.2.jar
CVE-2024-38827 spring-security-web-5.7.2.jar
CVE-2021-39153 xstream-1.4.5.jar
CVE-2022-42004 jackson-databind-2.13.3.jar
CVE-2013-7285 xstream-1.4.5.jar
CVE-2016-3674 xstream-1.4.5.jar
CVE-2024-12801 logback-core-1.2.11.jar
CVE-2023-20873 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2024-1635 undertow-core-2.2.18.Final.jar
CVE-2021-39152 xstream-1.4.5.jar
CVE-2024-3653 undertow-servlet-2.2.18.Final.jar
CVE-2024-3653 undertow-core-2.2.18.Final.jar
CVE-2024-38808 spring-expression-5.3.21.jar
CVE-2021-39154 xstream-1.4.5.jar
CVE-2021-39139 xstream-1.4.5.jar
CVE-2023-34034 spring-security-config-5.7.2.jar
CVE-2024-38821 spring-security-web-5.7.2.jar
CVE-2024-1459 undertow-core-2.2.18.Final.jar
CVE-2026-22740 spring-web-5.3.21.jar
CVE-2022-40151 xstream-1.4.5.jar
CVE-2021-39149 xstream-1.4.5.jar
CVE-2024-38827 spring-security-crypto-5.7.2.jar
CVE-2026-0603 hibernate-core-5.6.9.Final.jar
CVE-2026-22753 spring-security-config-5.7.2.jar
CVE-2022-4492 undertow-core-2.2.18.Final.jar
CVE-2024-3884 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-core-5.3.21.jar
CVE-2025-22235 spring-boot-2.7.1.jar
CVE-2023-20862 spring-security-web-5.7.2.jar
CVE-2024-29371 jose4j-0.9.3.jar
CVE-2021-21343 xstream-1.4.5.jar
CVE-2023-5379 undertow-core-2.2.18.Final.jar
CVE-2021-39150 xstream-1.4.5.jar
CVE-2020-8908 guava-30.1-jre.jar
CVE-2025-22235 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2026-22741 spring-webmvc-5.3.21.jar
CVE-2020-26259 xstream-1.4.5.jar
CVE-2025-11226 logback-core-1.2.11.jar
CVE-2023-1108 undertow-core-2.2.18.Final.jar
CVE-2022-42003 jackson-databind-2.13.3.jar
CVE-2021-43859 xstream-1.4.5.jar
CVE-2023-20883 spring-boot-autoconfigure-2.7.1.jar
CVE-2024-22243 spring-web-5.3.21.jar
CVE-2021-29505 xstream-1.4.5.jar
CVE-2021-21351 xstream-1.4.5.jar
CVE-2023-6378 logback-classic-1.2.11.jar
CVE-2021-21341 xstream-1.4.5.jar
CVE-2024-38827 spring-security-config-5.7.2.jar
CVE-2023-20861 spring-expression-5.3.21.jar
CVE-2021-39140 xstream-1.4.5.jar
CVE-2024-6162 undertow-core-2.2.18.Final.jar
CVE-2021-39147 xstream-1.4.5.jar
CVE-2020-26217 xstream-1.4.5.jar
CVE-2024-38820 spring-webmvc-5.3.21.jar
CVE-2021-21348 xstream-1.4.5.jar
CVE-2024-38820 spring-web-5.3.21.jar

Base branch total remaining vulnerabilities: 169
Base branch commit: ac51cc66d00ff1d8f52a045066eb5928bb0b7d81


Total libraries scanned: 153

Scan token: f416a5ed2e32419291dc8305d9e0c3ad