Skip to content

[Snyk] Security upgrade de.codecentric:spring-boot-admin-starter-server from 2.1.6 to 2.3.0#541

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-bff68e02a345e449d4bd05ae70b65969
Open

[Snyk] Security upgrade de.codecentric:spring-boot-admin-starter-server from 2.1.6 to 2.3.0#541
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-bff68e02a345e449d4bd05ae70b65969

Conversation

@snyk-bot
Copy link
Copy Markdown

@snyk-bot snyk-bot commented Apr 5, 2022

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • spring-boot-admin/spring-boot-admin-server/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity Reachability
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 560/1000
Why? Has a fix available, CVSS 8.2
XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit No Path Found
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 855/1000
Why? Mature exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Mature Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 825/1000
Why? Mature exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Mature Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 705/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 780/1000
Why? Proof of Concept exploit, Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 713/1000
Why? Is reachable, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No No Known Exploit Reachable
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Deserialization of Untrusted Data
SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
de.codecentric:spring-boot-admin-starter-server:
2.1.6 -> 2.3.0
No Proof of Concept No Path Found

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

…nerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant