fix(deps): update mend: high confidence minor and patch dependency updates - autoclosed - #52
Security Report
You have successfully remediated 127 vulnerabilities, but introduced 72 new vulnerabilities in this branch.
❌ New vulnerabilities:
Partial results (42 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2025-12543Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
9.6 | Not Defined | 0.041% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.39.Final |
None | ||
CVE-2026-22732Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-web/5.7.11/spring-security-web-5.7.11.jar Dependency Hierarchy: -> spring-boot-starter-security-2.7.18.jar (Root Library) -> ❌ spring-security-web-5.7.11.jar (Vulnerable Library) |
9.1 | Not Defined | 0.027% | Transitive spring-security-web-5.7.11.jar |
spring-boot-starter-security-2.7.18.jar | Transitive https://github.com/spring-projects/spring-security.git - 7.0.4,https://github.com/spring-projects/spring-security.git - 6.5.9 |
None | ||
CVE-2024-22257Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-core/5.7.11/spring-security-core-5.7.11.jar Dependency Hierarchy: -> spring-boot-starter-security-2.7.18.jar (Root Library) -> spring-security-config-5.7.11.jar -> ❌ spring-security-core-5.7.11.jar (Vulnerable Library) |
8.2 | Not Defined | 0.264% | Transitive spring-security-core-5.7.11.jar |
spring-boot-starter-security-2.7.18.jar | Transitive 5.7.12 |
None | ||
CVE-2024-22262Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
8.1 | Not Defined | 12.634% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 5.3.34 |
None | ||
CVE-2024-22259Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
8.1 | Not Defined | 56.395% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 5.3.33 |
None | ||
CVE-2024-22243Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
8.1 | Not Defined | 59.593% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 5.3.32 |
None | ||
WS-2026-0003Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> jackson-databind-2.13.5.jar -> ❌ jackson-core-2.13.5.jar (Vulnerable Library) |
7.5 | Not Defined | Transitive jackson-core-2.13.5.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 2.18.6 |
None | |||
WS-2022-0468Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> jackson-databind-2.13.5.jar -> ❌ jackson-core-2.13.5.jar (Vulnerable Library) |
7.5 | Not Defined | Transitive jackson-core-2.13.5.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 2.15.0-rc1 |
None | |||
CVE-2026-22754Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-config/5.7.11/spring-security-config-5.7.11.jar Dependency Hierarchy: -> spring-boot-starter-security-2.7.18.jar (Root Library) -> ❌ spring-security-config-5.7.11.jar (Vulnerable Library) |
7.5 | Not Defined | 0.047% | Transitive spring-security-config-5.7.11.jar |
spring-boot-starter-security-2.7.18.jar | Transitive 6.3.15 |
None | ||
CVE-2026-22753Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-config/5.7.11/spring-security-config-5.7.11.jar Dependency Hierarchy: -> spring-boot-starter-security-2.7.18.jar (Root Library) -> ❌ spring-security-config-5.7.11.jar (Vulnerable Library) |
7.5 | Not Defined | 0.068% | Transitive spring-security-config-5.7.11.jar |
spring-boot-starter-security-2.7.18.jar | Transitive 6.3.15 |
None | ||
CVE-2025-9784Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 1.553% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.38.Final |
None | ||
CVE-2025-52999Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> jackson-databind-2.13.5.jar -> ❌ jackson-core-2.13.5.jar (Vulnerable Library) |
7.5 | Not Defined | 0.252% | Transitive jackson-core-2.13.5.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 2.15.0 |
None | ||
CVE-2025-41249Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-2.7.18.jar -> ❌ spring-core-5.3.31.jar (Vulnerable Library) |
7.5 | Not Defined | 0.069% | Transitive spring-core-5.3.31.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11 |
None | ||
CVE-2024-7885Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 10.699% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.3.17.Final |
None | ||
CVE-2024-6162Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 2.024% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.33.Final |
None | ||
CVE-2024-5971Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 3.699% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.35.Final |
None | ||
CVE-2024-4027Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 0.3% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.39.Final |
None | ||
CVE-2024-3884Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 0.382% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.39.Final |
None | ||
CVE-2024-38819Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library) |
7.5 | Not Defined | 92.565% | Transitive spring-webmvc-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 6.1.14 |
None | ||
CVE-2024-38816Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library) |
7.5 | Not Defined | 93.877% | Transitive spring-webmvc-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 6.1.13 |
None | ||
CVE-2024-1635Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 23.144% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.31.Final |
None | ||
CVE-2023-5379Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 0.161% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.31.Final |
None | ||
CVE-2023-1973Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.5 | Not Defined | 0.727% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.33.Final |
None | ||
CVE-2025-22228Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/security/spring-security-crypto/5.7.11/spring-security-crypto-5.7.11.jar Dependency Hierarchy: -> spring-boot-starter-security-2.7.18.jar (Root Library) -> spring-security-config-5.7.11.jar -> spring-security-core-5.7.11.jar -> ❌ spring-security-crypto-5.7.11.jar (Vulnerable Library) |
7.4 | Not Defined | 0.065% | Transitive spring-security-crypto-5.7.11.jar |
spring-boot-starter-security-2.7.18.jar | Transitive https://github.com/spring-projects/spring-security.git - 6.4.4,https://github.com/spring-projects/spring-security.git - 6.3.8,org.springframework.security:spring-security-crypto:6.4.4,org.springframework.security:spring-security-crypto:6.3.8 |
None | ||
CVE-2023-4639Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
7.4 | Not Defined | 7.36% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive 2.2.31.Final |
None | ||
CVE-2025-22235Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> ❌ spring-boot-2.7.18.jar (Vulnerable Library) |
7.3 | Functional | 0.39% | Transitive spring-boot-2.7.18.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive https://github.com/spring-projects/spring-boot.git - v3.4.5,https://github.com/spring-projects/spring-boot.git - v3.3.11,org.springframework.boot:spring-boot-actuator-autoconfigure:3.4.5,org.springframework.boot:spring-boot-actuator-autoconfigure:3.3.11 |
None | ||
CVE-2024-12798Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-starter-logging-2.7.18.jar -> ❌ logback-classic-1.2.12.jar (Vulnerable Library) |
7.3 | Not Defined | 0.124% | Transitive logback-classic-1.2.12.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive 1.3.15 |
None | ||
CVE-2024-12798Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-starter-logging-2.7.18.jar -> logback-classic-1.2.12.jar -> ❌ logback-core-1.2.12.jar (Vulnerable Library) |
7.3 | Not Defined | 0.124% | Transitive logback-core-1.2.12.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive 1.3.15 |
None | ||
CVE-2023-6481Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-starter-logging-2.7.18.jar -> logback-classic-1.2.12.jar -> ❌ logback-core-1.2.12.jar (Vulnerable Library) |
7.1 | Not Defined | 0.224% | Transitive logback-core-1.2.12.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive 1.2.13 |
None | ||
CVE-2023-6378Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-starter-logging-2.7.18.jar -> ❌ logback-classic-1.2.12.jar (Vulnerable Library) |
7.1 | Not Defined | 0.613% | Transitive logback-classic-1.2.12.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive ch.qos.logback:logback-classic:1.3.12,1.4.12 |
None | ||
CVE-2023-6378Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-starter-logging-2.7.18.jar -> logback-classic-1.2.12.jar -> ❌ logback-core-1.2.12.jar (Vulnerable Library) |
7.1 | Not Defined | 0.613% | Transitive logback-core-1.2.12.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive ch.qos.logback:logback-classic:1.3.12,1.4.12 |
None | ||
CVE-2026-40973Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> ❌ spring-boot-2.7.18.jar (Vulnerable Library) |
7.0 | Not Defined | 0.014% | Transitive spring-boot-2.7.18.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive 2.7.33 |
None | ||
CVE-2026-22740Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
6.5 | Not Defined | 0.046% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive org.springframework:spring-web:6.2.18,https://github.com/spring-projects/spring-framework.git - v7.0.7,org.springframework:spring-web:7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18 |
None | ||
CVE-2026-3260Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/io/undertow/undertow-core/2.2.28.Final/undertow-core-2.2.28.Final.jar Dependency Hierarchy: -> spring-boot-starter-undertow-2.7.18.jar (Root Library) -> ❌ undertow-core-2.2.28.Final.jar (Vulnerable Library) |
5.9 | Not Defined | 0.641% | Transitive undertow-core-2.2.28.Final.jar |
spring-boot-starter-undertow-2.7.18.jar | Transitive io.undertow:undertow-core:2.4.0.Beta1 |
None | ||
CVE-2026-22737Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library) |
5.9 | Not Defined | 0.092% | Transitive spring-webmvc-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive org.springframework:spring-webflux:6.2.17,org.springframework:spring-webflux:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6 |
None | ||
CVE-2025-41242Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.3.31/spring-beans-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-2.7.18.jar -> spring-context-5.3.31.jar -> spring-aop-5.3.31.jar -> ❌ spring-beans-5.3.31.jar (Vulnerable Library) |
5.9 | Not Defined | 0.087% | Transitive spring-beans-5.3.31.jar |
spring-boot-starter-validation-2.7.18.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 |
None | ||
CVE-2025-41242Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library) |
5.9 | Not Defined | 0.087% | Transitive spring-webmvc-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 |
None | ||
CVE-2023-2976Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/guava/guava/30.1.1-jre/guava-30.1.1-jre.jar Dependency Hierarchy: -> ❌ guava-30.1.1-jre.jar (Vulnerable Library) |
5.5 | Not Defined | 0.065% | Direct guava-30.1.1-jre.jar |
guava-30.1.1-jre.jar | 32.0.1-android | None | ||
CVE-2024-38828Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-validation-2.7.18.jar (Root Library) -> spring-boot-starter-2.7.18.jar -> spring-boot-2.7.18.jar -> ❌ spring-core-5.3.31.jar (Vulnerable Library) |
5.3 | Not Defined | 0.076% | Transitive spring-core-5.3.31.jar |
spring-boot-starter-validation-2.7.18.jar | None | |||
CVE-2024-38828Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
5.3 | Not Defined | 0.076% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 6.0.0 |
None | ||
CVE-2024-38828Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library) |
5.3 | Not Defined | 0.076% | Transitive spring-webmvc-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 6.0.0 |
None | ||
CVE-2024-38809Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar Dependency Hierarchy: -> spring-boot-starter-web-2.7.18.jar (Root Library) -> spring-boot-starter-json-2.7.18.jar -> ❌ spring-web-5.3.31.jar (Vulnerable Library) |
5.3 | Not Defined | 0.14% | Transitive spring-web-5.3.31.jar |
spring-boot-starter-web-2.7.18.jar | Transitive 5.3.38 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2022-31692 | spring-security-core-5.7.2.jar |
| CVE-2026-40973 | spring-boot-2.7.1.jar |
| CVE-2024-38809 | spring-web-5.3.21.jar |
| CVE-2021-21346 | xstream-1.4.5.jar |
| CVE-2026-40974 | spring-boot-autoconfigure-2.7.1.jar |
| CVE-2026-1225 | logback-core-1.2.11.jar |
| CVE-2025-22228 | spring-security-crypto-5.7.2.jar |
| CVE-2023-3223 | undertow-servlet-2.2.18.Final.jar |
| CVE-2026-22746 | spring-security-core-5.7.2.jar |
| CVE-2016-1000027 | spring-web-5.3.21.jar |
| CVE-2021-39145 | xstream-1.4.5.jar |
| CVE-2026-40975 | spring-boot-2.7.1.jar |
| CVE-2022-41966 | xstream-1.4.5.jar |
| WS-2026-0003 | jackson-core-2.13.3.jar |
| CVE-2026-22735 | spring-web-5.3.21.jar |
| CVE-2024-7885 | undertow-core-2.2.18.Final.jar |
| CVE-2024-38820 | spring-context-5.3.21.jar |
| CVE-2026-22732 | spring-security-web-5.7.2.jar |
| CVE-2021-21344 | xstream-1.4.5.jar |
| CVE-2024-5971 | undertow-core-2.2.18.Final.jar |
| CVE-2021-21345 | xstream-1.4.5.jar |
| CVE-2025-41242 | spring-beans-5.3.21.jar |
| CVE-2025-9784 | undertow-core-2.2.18.Final.jar |
| CVE-2023-51775 | jose4j-0.9.3.jar |
| CVE-2023-4639 | undertow-core-2.2.18.Final.jar |
| CVE-2025-12543 | undertow-core-2.2.18.Final.jar |
| CVE-2025-41249 | spring-core-5.3.21.jar |
| CVE-2022-2053 | undertow-core-2.2.18.Final.jar |
| CVE-2025-22233 | spring-context-5.3.21.jar |
| CVE-2023-1973 | undertow-core-2.2.18.Final.jar |
| CVE-2024-38828 | spring-webmvc-5.3.21.jar |
| CVE-2026-22733 | spring-boot-actuator-autoconfigure-2.7.1.jar |
| CVE-2024-38816 | spring-webmvc-5.3.21.jar |
| CVE-2021-21350 | xstream-1.4.5.jar |
| CVE-2021-39148 | xstream-1.4.5.jar |
| CVE-2024-12798 | logback-core-1.2.11.jar |
| CVE-2023-34055 | spring-boot-actuator-2.7.1.jar |
| CVE-2020-26258 | xstream-1.4.5.jar |
| CVE-2023-20862 | spring-security-core-5.7.2.jar |
| CVE-2024-38827 | spring-security-core-5.7.2.jar |
| CVE-2019-10173 | xstream-1.4.5.jar |
| CVE-2023-20863 | spring-expression-5.3.21.jar |
| CVE-2025-41242 | spring-webmvc-5.3.21.jar |
| CVE-2026-3260 | undertow-core-2.2.18.Final.jar |
| CVE-2024-38828 | spring-web-5.3.21.jar |
| CVE-2024-22262 | spring-web-5.3.21.jar |
| CVE-2021-21349 | xstream-1.4.5.jar |
| CVE-2026-22735 | spring-webmvc-5.3.21.jar |
| CVE-2024-38819 | spring-webmvc-5.3.21.jar |
| CVE-2017-7957 | xstream-1.4.5.jar |
| CVE-2023-6378 | logback-core-1.2.11.jar |
| CVE-2024-22259 | spring-web-5.3.21.jar |
| CVE-2021-39151 | xstream-1.4.5.jar |
| CVE-2021-21347 | xstream-1.4.5.jar |
| CVE-2021-39141 | xstream-1.4.5.jar |
| CVE-2026-22737 | spring-webmvc-5.3.21.jar |
| CVE-2023-20860 | spring-webmvc-5.3.21.jar |
| CVE-2026-22733 | spring-boot-starter-actuator-2.7.1.jar |
| CVE-2024-22257 | spring-security-core-5.7.2.jar |
| CVE-2025-52999 | jackson-core-2.13.3.jar |
| CVE-2024-12798 | logback-classic-1.2.11.jar |
| CVE-2021-21342 | xstream-1.4.5.jar |
| WS-2022-0468 | jackson-core-2.13.3.jar |
| CVE-2021-39146 | xstream-1.4.5.jar |
| CVE-2026-22754 | spring-security-config-5.7.2.jar |
| CVE-2022-1259 | undertow-core-2.2.18.Final.jar |
| CVE-2026-40977 | spring-boot-2.7.1.jar |
| CVE-2024-47072 | xstream-1.4.5.jar |
| CVE-2024-4027 | undertow-core-2.2.18.Final.jar |
| CVE-2023-2976 | guava-30.1-jre.jar |
| CVE-2024-38828 | spring-core-5.3.21.jar |
| CVE-2022-31692 | spring-security-web-5.7.2.jar |
| CVE-2024-38827 | spring-security-web-5.7.2.jar |
| CVE-2021-39153 | xstream-1.4.5.jar |
| CVE-2022-42004 | jackson-databind-2.13.3.jar |
| CVE-2013-7285 | xstream-1.4.5.jar |
| CVE-2016-3674 | xstream-1.4.5.jar |
| CVE-2024-12801 | logback-core-1.2.11.jar |
| CVE-2023-20873 | spring-boot-actuator-autoconfigure-2.7.1.jar |
| CVE-2024-1635 | undertow-core-2.2.18.Final.jar |
| CVE-2021-39152 | xstream-1.4.5.jar |
| CVE-2024-3653 | undertow-servlet-2.2.18.Final.jar |
| CVE-2024-3653 | undertow-core-2.2.18.Final.jar |
| CVE-2024-38808 | spring-expression-5.3.21.jar |
| CVE-2021-39154 | xstream-1.4.5.jar |
| CVE-2021-39139 | xstream-1.4.5.jar |
| CVE-2023-34034 | spring-security-config-5.7.2.jar |
| CVE-2024-38821 | spring-security-web-5.7.2.jar |
| CVE-2024-1459 | undertow-core-2.2.18.Final.jar |
| CVE-2026-22740 | spring-web-5.3.21.jar |
| CVE-2022-40151 | xstream-1.4.5.jar |
| CVE-2021-39149 | xstream-1.4.5.jar |
| CVE-2024-38827 | spring-security-crypto-5.7.2.jar |
| CVE-2026-0603 | hibernate-core-5.6.9.Final.jar |
| CVE-2026-22753 | spring-security-config-5.7.2.jar |
| CVE-2022-4492 | undertow-core-2.2.18.Final.jar |
| CVE-2024-3884 | undertow-core-2.2.18.Final.jar |
| CVE-2024-38820 | spring-core-5.3.21.jar |
| CVE-2025-22235 | spring-boot-2.7.1.jar |
| CVE-2023-20862 | spring-security-web-5.7.2.jar |
| CVE-2024-29371 | jose4j-0.9.3.jar |
| CVE-2021-21343 | xstream-1.4.5.jar |
| CVE-2023-5379 | undertow-core-2.2.18.Final.jar |
| CVE-2021-39150 | xstream-1.4.5.jar |
| CVE-2020-8908 | guava-30.1-jre.jar |
| CVE-2025-22235 | spring-boot-actuator-autoconfigure-2.7.1.jar |
| CVE-2026-22741 | spring-webmvc-5.3.21.jar |
| CVE-2020-26259 | xstream-1.4.5.jar |
| CVE-2025-11226 | logback-core-1.2.11.jar |
| CVE-2023-1108 | undertow-core-2.2.18.Final.jar |
| CVE-2022-42003 | jackson-databind-2.13.3.jar |
| CVE-2021-43859 | xstream-1.4.5.jar |
| CVE-2023-20883 | spring-boot-autoconfigure-2.7.1.jar |
| CVE-2024-22243 | spring-web-5.3.21.jar |
| CVE-2021-29505 | xstream-1.4.5.jar |
| CVE-2021-21351 | xstream-1.4.5.jar |
| CVE-2023-6378 | logback-classic-1.2.11.jar |
| CVE-2021-21341 | xstream-1.4.5.jar |
| CVE-2024-38827 | spring-security-config-5.7.2.jar |
| CVE-2023-20861 | spring-expression-5.3.21.jar |
| CVE-2021-39140 | xstream-1.4.5.jar |
| CVE-2024-6162 | undertow-core-2.2.18.Final.jar |
| CVE-2021-39147 | xstream-1.4.5.jar |
| CVE-2020-26217 | xstream-1.4.5.jar |
| CVE-2024-38820 | spring-webmvc-5.3.21.jar |
| CVE-2021-21348 | xstream-1.4.5.jar |
| CVE-2024-38820 | spring-web-5.3.21.jar |
Base branch total remaining vulnerabilities: 169
Base branch commit: ac51cc66d00ff1d8f52a045066eb5928bb0b7d81
Total libraries scanned: 153
Scan token: f416a5ed2e32419291dc8305d9e0c3ad