Title: [Snyk] Fix for 4 vulnerabilities by lovelingca · Pull Request #50 · lovelingca/JavaLearnVulnerability · GitHub
Open Graph Title: [Snyk] Fix for 4 vulnerabilities by lovelingca · Pull Request #50 · lovelingca/JavaLearnVulnerability
X Title: [Snyk] Fix for 4 vulnerabilities by lovelingca · Pull Request #50 · lovelingca/JavaLearnVulnerability
Description: Snyk has created this PR to fix 4 vulnerabilities in the maven dependencies of this project. Snyk changed the following file(s): Rce_Echo/TomcatEcho/pom.xml Vulnerabilities that will be fixed with an upgrade: Issue Score Upgrade Relative Path Traversal SNYK-JAVA-ORGAPACHETOMCATEMBED-13733966 671 Major version upgrade No Known Exploit Improper Output Neutralization for Logs SNYK-JAVA-ORGAPACHETOMCAT-13723548 601 org.apache.tomcat:tomcat-dbcp: 9.0.8 -> 9.0.109 No Known Exploit Improper Resource Shutdown or Release SNYK-JAVA-ORGAPACHETOMCATEMBED-13723930 586 Major version upgrade No Known Exploit External Initialization of Trusted Variables or Data Stores SNYK-JAVA-CHQOSLOGBACK-13169722 509 Major version upgrade No Known Exploit Vulnerabilities that could not be fixed Upgrade: Could not upgrade org.apache.tomcat.embed:tomcat-embed-jasper@9.0.45 to org.apache.tomcat.embed:tomcat-embed-jasper@9.0.110; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/2.4.5/spring-boot-dependencies-2.4.5.pom Could not upgrade org.springframework.boot:spring-boot-starter-tomcat@2.4.5 to org.springframework.boot:spring-boot-starter-tomcat@3.4.11; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/2.4.5/spring-boot-dependencies-2.4.5.pom Could not upgrade org.springframework.boot:spring-boot-starter-web@2.4.5 to org.springframework.boot:spring-boot-starter-web@3.4.11; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/2.4.5/spring-boot-dependencies-2.4.5.pom Important Check the changes in this PR to ensure they won't cause issues with your project. Max score is 1000. Note that the real score may have changed since the PR was raised. This PR was automatically created by Snyk using the credentials of a real user. Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic Learn how to fix vulnerabilities with free interactive lessons: 🦉 Improper Output Neutralization for Logs 🦉 Relative Path Traversal
Open Graph Description: Snyk has created this PR to fix 4 vulnerabilities in the maven dependencies of this project. Snyk changed the following file(s): Rce_Echo/TomcatEcho/pom.xml Vulnerabilities that will be fixed wit...
X Description: Snyk has created this PR to fix 4 vulnerabilities in the maven dependencies of this project. Snyk changed the following file(s): Rce_Echo/TomcatEcho/pom.xml Vulnerabilities that will be fixed wit...
Opengraph URL: https://github.com/lovelingca/JavaLearnVulnerability/pull/50
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:c0b4c194-16f2-641a-8882-55c2da29e22c |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | AA6A:9B720:302D9D0:3F13106:697D71E2 |
| html-safe-nonce | 3466378035e997e8fd19134be47dba1cf6f825eaa325feea9e1d1f9f4dcd8383 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBQTZBOjlCNzIwOjMwMkQ5RDA6M0YxMzEwNjo2OTdENzFFMiIsInZpc2l0b3JfaWQiOiI3MTIxMTA2NTE0OTg2NDk2NDgyIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | f80bf91cc28beecb362e988d8558cb9cc3d2d6d6ef6cad48ca2fe423f03ff993 |
| hovercard-subject-tag | pull_request:2958711545 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/lovelingca/JavaLearnVulnerability/pull/50/files |
| twitter:image | https://avatars.githubusercontent.com/u/115864558?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/115864558?s=400&v=4 |
| og:image:alt | Snyk has created this PR to fix 4 vulnerabilities in the maven dependencies of this project. Snyk changed the following file(s): Rce_Echo/TomcatEcho/pom.xml Vulnerabilities that will be fixed wit... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 60279d4097367e16897439d16d6bbe4180663db828c666eeed2656988ffe59f6 |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/lovelingca/JavaLearnVulnerability git https://github.com/lovelingca/JavaLearnVulnerability.git |
| octolytics-dimension-user_id | 115864558 |
| octolytics-dimension-user_login | lovelingca |
| octolytics-dimension-repository_id | 551822934 |
| octolytics-dimension-repository_nwo | lovelingca/JavaLearnVulnerability |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 257839674 |
| octolytics-dimension-repository_parent_nwo | SummerSec/JavaLearnVulnerability |
| octolytics-dimension-repository_network_root_id | 257839674 |
| octolytics-dimension-repository_network_root_nwo | SummerSec/JavaLearnVulnerability |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 7c85641c598ad130c74f7bcc27f58575cac69551 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width