Title: [Snyk] Fix for 9 vulnerabilities by AOusers · Pull Request #6 · AOusers/OpenWeatherJavaProject · GitHub
Open Graph Title: [Snyk] Fix for 9 vulnerabilities by AOusers · Pull Request #6 · AOusers/OpenWeatherJavaProject
X Title: [Snyk] Fix for 9 vulnerabilities by AOusers · Pull Request #6 · AOusers/OpenWeatherJavaProject
Description: This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable dependencies to a fixed version: pom.xml Vulnerabilities that will be fixed With an upgrade: Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity 651/1000 Why? Mature exploit, Has a fix available, CVSS 5.3 Directory Traversal SNYK-JAVA-COMMONSIO-1277109 io.github.bonigarcia:webdrivermanager: 5.3.0 -> 5.6.1 No Mature 490/1000 Why? Has a fix available, CVSS 5.3 Improper Certificate Validation SNYK-JAVA-IONETTY-1042268 org.seleniumhq.selenium:selenium-java: 4.5.3 -> 4.14.1 No No Known Exploit 539/1000 Why? Has a fix available, CVSS 6.5 HTTP Response Splitting SNYK-JAVA-IONETTY-3167773 org.seleniumhq.selenium:selenium-java: 4.5.3 -> 4.14.1 No No Known Exploit 539/1000 Why? Has a fix available, CVSS 6.5 Denial of Service (DoS) SNYK-JAVA-IONETTY-5725787 org.seleniumhq.selenium:selenium-java: 4.5.3 -> 4.14.1 No No Known Exploit 479/1000 Why? Has a fix available, CVSS 5.3 Timing Attack SNYK-JAVA-ORGBOUNCYCASTLE-1296075 io.github.bonigarcia:webdrivermanager: 5.3.0 -> 5.6.1 No No Known Exploit 561/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 4.8 Cryptographic Issues SNYK-JAVA-ORGBOUNCYCASTLE-2841508 io.github.bonigarcia:webdrivermanager: 5.3.0 -> 5.6.1 No Proof of Concept 449/1000 Why? Has a fix available, CVSS 4.7 Information Exposure SNYK-JAVA-ORGBOUNCYCASTLE-5771339 io.github.bonigarcia:webdrivermanager: 5.3.0 -> 5.6.1 No No Known Exploit 768/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 NULL Pointer Dereference SNYK-JAVA-ORGSELENIUMHQSELENIUM-6062318 org.seleniumhq.selenium:selenium-java: 4.5.3 -> 4.14.1 No Proof of Concept 539/1000 Why? Has a fix available, CVSS 6.5 Arbitrary File Write via Archive Extraction (Zip Slip) SNYK-JAVA-ORGTESTNG-3040285 org.testng:testng: 7.6.1 -> 7.7.0 No No Known Exploit (*) Note that the real score may have changed since the PR was raised. Check the changes in this PR to ensure they won't cause issues with your project. Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: 🧐 View latest project report 🛠 Adjust project settings 📚 Read more about Snyk's upgrade and patch logic Learn how to fix vulnerabilities with free interactive lessons: 🦉 Directory Traversal 🦉 Denial of Service (DoS) 🦉 Cryptographic Issues 🦉 More lessons are available in Snyk Learn
Open Graph Description: This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes i...
X Description: This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes i...
Opengraph URL: https://github.com/AOusers/OpenWeatherJavaProject/pull/6
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:5d931f53-fe10-c20f-3c8d-399ad10aa8b2 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | 9044:1DFAA9:AC8F44:DD9675:69741DC5 |
| html-safe-nonce | dd4a760a3707a2e4ee560c0fc843f40f0657c8dc8c646e57a626f11599553f3d |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5MDQ0OjFERkFBOTpBQzhGNDQ6REQ5Njc1OjY5NzQxREM1IiwidmlzaXRvcl9pZCI6Ijg5Mjg5MTAzMDA1ODA5NDUzNDkiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 1dd777d1ca95503104e957a9d6380ef8f2b85539632679d4b161852d65d6ea95 |
| hovercard-subject-tag | pull_request:1611936095 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/AOusers/OpenWeatherJavaProject/pull/6/files |
| twitter:image | https://avatars.githubusercontent.com/u/143771878?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/143771878?s=400&v=4 |
| og:image:alt | This PR was automatically created by Snyk using the credentials of a real user.Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes i... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 447dc9917c3d68d647a01abfdefe55ec7ee1785922136c1d8395dbb3ab6d57b9 |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/AOusers/OpenWeatherJavaProject git https://github.com/AOusers/OpenWeatherJavaProject.git |
| octolytics-dimension-user_id | 143771878 |
| octolytics-dimension-user_login | AOusers |
| octolytics-dimension-repository_id | 690930599 |
| octolytics-dimension-repository_nwo | AOusers/OpenWeatherJavaProject |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 591044996 |
| octolytics-dimension-repository_parent_nwo | BugorDmitriy/OpenWeatherJavaProject |
| octolytics-dimension-repository_network_root_id | 591044996 |
| octolytics-dimension-repository_network_root_nwo | BugorDmitriy/OpenWeatherJavaProject |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 8dad7bdfecbe3eaa97ac4e632d6b47e2b23e81d9 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width