Skip to content

[Snyk] Security upgrade io.mosip.esignet:esignet-core from 1.4.1 to 1.7.0#16

Open
Md-Humair-KK wants to merge 1 commit intomasterfrom
snyk-fix-a166ebca5830cc3f8f32b53a423c6715
Open

[Snyk] Security upgrade io.mosip.esignet:esignet-core from 1.4.1 to 1.7.0#16
Md-Humair-KK wants to merge 1 commit intomasterfrom
snyk-fix-a166ebca5830cc3f8f32b53a423c6715

Conversation

@Md-Humair-KK
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 30 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • binding-service-impl/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
critical severity Remote Code Execution (RCE)
SNYK-JAVA-ORGSPRINGFRAMEWORK-2436751
  919   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Mature
critical severity Missing Authorization
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8309135
  776   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
high severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-2833359
  731   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6261586
  676   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
high severity SQL Injection
SNYK-JAVA-ORGHIBERNATE-1041788
  635   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
high severity Improper Access Control
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-6457293
  624   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6597980
  591   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMNIMBUSDS-6247633
  589   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-1584063
  589   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-IONETTY-1584064
  589   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Integer Overflow or Wraparound
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-5950401
  586   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6444790
  569   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447
  559   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Timing Attack
SNYK-JAVA-ORGAPACHEKAFKA-1540737
  554   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-5422217
  539   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1082234
  524   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1082235
  524   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Information Disclosure
SNYK-JAVA-IONETTY-1082236
  524   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634
  506   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-2434828
  479   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-2823313
  479   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749
  479   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Privilege Escalation
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-1078232
  439   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Privilege Escalation
SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
  434   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Improper Output Neutralization for Logs
SNYK-JAVA-ORGSPRINGFRAMEWORK-2329097
  429   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
medium severity Improper Input Validation
SNYK-JAVA-ORGSPRINGFRAMEWORK-2330878
  429   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
low severity Timing Attack
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-1290497
  380   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230364
  329   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230365
  329   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230366
  329   io.mosip.esignet:esignet-core:
1.4.1 -> 1.7.0
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Information Disclosure
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2436751
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8309135
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-2833359
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6261586
- https://snyk.io/vuln/SNYK-JAVA-ORGHIBERNATE-1041788
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-6457293
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6597980
- https://snyk.io/vuln/SNYK-JAVA-COMNIMBUSDS-6247633
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1584063
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1584064
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-5950401
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6444790
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEKAFKA-1540737
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-5422217
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1082234
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1082235
- https://snyk.io/vuln/SNYK-JAVA-IONETTY-1082236
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2434828
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2823313
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-3369749
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-1078232
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-1296829
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2329097
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2330878
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-1290497
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230364
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230365
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230366
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants