Title: [Snyk] Fix for 2 vulnerabilities by snyk-bot · Pull Request #200 · secureCodeBox/engine · GitHub
Open Graph Title: [Snyk] Fix for 2 vulnerabilities by snyk-bot · Pull Request #200 · secureCodeBox/engine
X Title: [Snyk] Fix for 2 vulnerabilities by snyk-bot · Pull Request #200 · secureCodeBox/engine
Description: Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable dependencies to a fixed version: pom.xml Vulnerabilities that will be fixed With an upgrade: Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity 509/1000 Why? Has a fix available, CVSS 5.9 Deserialization of Untrusted Data SNYK-JAVA-COMGOOGLEGUAVA-32236 io.springfox:springfox-swagger-ui: 2.9.2 -> 2.10.0 io.springfox:springfox-swagger2: 2.9.2 -> 2.10.0 No No Known Exploit 589/1000 Why? Has a fix available, CVSS 7.5 XML Entity Expansion SNYK-JAVA-ORGGLASSFISHJERSEYMEDIA-595972 No No Known Exploit (*) Note that the real score may have changed since the PR was raised. Vulnerabilities that could not be fixed Upgrade: Could not upgrade org.glassfish.jersey.core:jersey-server@2.30.1 to org.glassfish.jersey.core:jersey-server@2.31; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-starter-jersey/2.3.3.RELEASE/spring-boot-starter-jersey-2.3.3.RELEASE.pom Check the changes in this PR to ensure they won't cause issues with your project. Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: 🧐 View latest project report 🛠 Adjust project settings 📚 Read more about Snyk's upgrade and patch logic
Open Graph Description: Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable de...
X Description: Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable de...
Opengraph URL: https://github.com/secureCodeBox/engine/pull/200
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:56f44a1c-c041-3f37-7489-1618e8b6ecde |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | BD94:11A76C:FE1B65:143F87C:69902548 |
| html-safe-nonce | 49d896e70904174c46d5359e467a105da8866038b4650044e30351c0681f0bd9 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCRDk0OjExQTc2QzpGRTFCNjU6MTQzRjg3Qzo2OTkwMjU0OCIsInZpc2l0b3JfaWQiOiI1ODM1MDY0MDMyMzQ0Njc5NzUyIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 8b29c028a35f2359580ddda4aa19416af6912bac0cc849cb0e931f868c8c2f21 |
| hovercard-subject-tag | pull_request:484392739 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/secureCodeBox/engine/pull/200/files |
| twitter:image | https://avatars.githubusercontent.com/u/19733683?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/19733683?s=400&v=4 |
| og:image:alt | Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable de... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/secureCodeBox/engine git https://github.com/secureCodeBox/engine.git |
| octolytics-dimension-user_id | 34573705 |
| octolytics-dimension-user_login | secureCodeBox |
| octolytics-dimension-repository_id | 123422137 |
| octolytics-dimension-repository_nwo | secureCodeBox/engine |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 123422137 |
| octolytics-dimension-repository_network_root_nwo | secureCodeBox/engine |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 3b33c5aedc9808f45bc5fcf0b1e4404cf749dac7 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width