FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Snyk] Security upgrade org.owasp.esapi:esapi from 2.2.3.1 to 2.7.0.0 by tyleragypt · Pull Request #31 · tyleragypt/BenchmarkJava · GitHub

[Snyk] Security upgrade org.owasp.esapi:esapi from 2.2.3.1 to 2.7.0.0 - #31

Open
tyleragypt wants to merge 1 commit into
masterfrom
snyk-fix-2f1b3fe70649876a0ce22e36ae7baa54
Open

tyleragypt wants to merge 1 commit into
masterfrom
snyk-fix-2f1b3fe70649876a0ce22e36ae7baa54

Conversation

Copy link
Copy Markdown
Owner

Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
Improper Neutralization of Special Elements
SNYK-JAVA-ORGOWASPESAPI-10562218
  620   org.owasp.esapi:esapi:
2.2.3.1 -> 2.7.0.0
No Path Found Proof of Concept
Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMMONSFILEUPLOAD-10363252
  585   org.owasp.esapi:esapi:
2.2.3.1 -> 2.7.0.0
No Path Found No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

Copy link
Copy Markdown
Owner Author


Checkmarx One – Scan Summary & Details – b5a93926-1f1e-422c-8f96-c6eb81584e26

New Issues (35)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CVE-2022-41853 Maven-org.hsqldb:hsqldb-2.3.6 detailsRecommended version: 2.7.1
Description: Those using "java.sql.Statement" or "java.sql.PreparedStatement" in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a Re...
Attack Vector: NETWORK
Attack Complexity: LOW
Exploitable Path: executeBatch@...e/BenchmarkTest02647.java - ... - executeCompiledStatement@.../Session.java

ID: v%2F3hU5r2ict0s3RJNBLGtqpUaP8emtvfq2apBto%2FzC4%3DVulnerable Package
CVE-2024-52046 Maven-org.apache.mina:mina-core-2.0.0-RC1 detailsRecommended version: 2.0.27
Description: The "ObjectSerializationDecoder" in Apache MINA uses Java's native deserialization protocol to process incoming serialized data but lacks the neces...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HrVsGJ2S8zjI8GhdkKUEKC%2F6H%2B7ccPAWEnVB5DaOfz4%3DVulnerable Package
CVE-2024-22243 Maven-org.springframework:spring-web-4.3.30.RELEASE detailsRecommended version: 5.3.31-wso2v1
Description: Applications that use "UriComponentsBuilder" to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: YZOGPl6sBCQ996pTWtGo2SIPREWTnuXbVSbcBECgqz8%3DVulnerable Package
CVE-2024-22259 Maven-org.springframework:spring-web-4.3.30.RELEASE detailsRecommended version: 5.3.31-wso2v1
Description: Applications that use "UriComponentsBuilder" in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform v...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Xxv0fkEctwxkr3tmX7eGFfy9YhQ2%2BsHxYexTFPQp3Sw%3DVulnerable Package
CVE-2024-22262 Maven-org.springframework:spring-web-4.3.30.RELEASE detailsRecommended version: 5.3.31-wso2v1
Description: Applications that use "UriComponentsBuilder" to parse an externally provided URL (e.g. through a query parameter) and perform validation checks on ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: fn468k9tw%2F7LWd%2FTpDXKJDZwEooLLGemiX%2BEFbBxkP0%3DVulnerable Package
CVE-2024-38819 Maven-org.springframework:spring-webmvc-4.3.30.RELEASE detailsRecommended version: 5.3.39-atlassian-3
Description: Applications serving static resources through the functional web frameworks "WebMvc.fn" or "WebFlux.fn" are vulnerable to path traversal attacks. A...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: dlN7owN3wX%2FsDGSUpEhRsOqnboxK%2FpR5gYaxw1EML%2BI%3DVulnerable Package
CVE-2015-9251 Npm-jquery-2.1.4 detailsRecommended version: 3.5.0
Description: jQuery before 3.0.0-beta1 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType op...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 2DLulpj3Gu%2BEWZYfeoyPSzzceQ%2F3gXwcf64u7gt%2FSo4%3DVulnerable Package
CVE-2019-11358 Npm-jquery-2.1.4 detailsRecommended version: 3.5.0
Description: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollu...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: qFzgOUEoXauD1ntIwXbfOLpCFUXUo6PJ4w4C2lQ4C8E%3DVulnerable Package
CVE-2020-11023 Npm-jquery-2.1.4 detailsRecommended version: 3.5.0
Description: In jQuery versions 1.0.3 through 3.4.1, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQu...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: y8SOy7s9jw6olR8VvwKAT%2BhaZfeBydPJ2Qjz4NDH5wc%3DVulnerable Package
CVE-2023-20861 Maven-org.springframework:spring-expression-4.3.30.RELEASE detailsRecommended version: 5.3.31-wso2v1
Description: In Spring Framework versions prior to 5.2.23.RELEASE, 5.3.x prior to 5.3.26 and 6.0.x prior to 6.0.7 it is possible for a user to provide a special...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: BzVV2YNQDeOtsjYZ69IaUlj08dOs37zpwRJAK6tnNO4%3DVulnerable Package
CVE-2023-20863 Maven-org.springframework:spring-expression-4.3.30.RELEASE detailsRecommended version: 5.3.31-wso2v1
Description: In spring framework in versions through 5.2.23.RELEASE, 5.3.0-M1 through 5.3.26, and 6.0.0-M1 through 6.0.7 it is possible for a user to provide a ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yPFwNKJGPjKxL6Zfa1aQwSOW4PyGqQNVhKuTbZLIW7I%3DVulnerable Package
CVE-2023-33201 Maven-org.bouncycastle:bcprov-jdk15on-1.70 detailsDescription: Bouncy Castle for Java versions prior to 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2FVaEBxWFHlBpjhka1lgYCfhx%2FcBLP9QzMV696C78MjQ%3DVulnerable Package
CVE-2023-33202 Maven-org.bouncycastle:bcprov-jdk15on-1.70 detailsDescription: Bouncy Castle for Java in versions prior to 1.73 contains a potential Denial-of-Service (DoS) issue within the Bouncy Castle "org.bouncycastle.open...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: enXlQVPfvQLrSkPq%2B7%2BfmonPjVNbe7O%2FsjVbIyA49bw%3DVulnerable Package
CVE-2024-29857 Maven-org.bouncycastle:bcprov-jdk15on-1.70 detailsDescription: An issue was discovered in "ECCurve.java" and "ECCurve.cs" in Bouncy Castle Java (BC Java) versions prior to 1.78, BC Java LTS versions prior to 2....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Nsw%2FJ9o0v9dJEqoNOQrMIsgTfxHwmGeaqyvWCJE%2BCY8%3DVulnerable Package

More results are available on the CxOne platform

Fixed Issues (962)
Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
CVE-2016-1000031 Maven-commons-fileupload:commons-fileupload-1.3.3
CVE-2019-17571 Maven-log4j:log4j-1.2.17
CVE-2021-4104 Maven-log4j:log4j-1.2.17
CVE-2022-23302 Maven-log4j:log4j-1.2.17
CVE-2022-23305 Maven-log4j:log4j-1.2.17
CVE-2022-23307 Maven-log4j:log4j-1.2.17
CVE-2022-23457 Maven-org.owasp.esapi:esapi-2.2.3.1
CVE-2022-24839 Maven-net.sourceforge.nekohtml:nekohtml-1.9.22
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 107
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 83
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 82
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 141
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 140
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01182.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02058.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02610.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00558.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02335.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01600.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01937.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00494.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00307.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01865.java: 59
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01289.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00741.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00093.java: 59
Command_Injection /src/main/java/org/owasp/benchmark/helpers/SeparateClassRequest.java: 31
LDAP_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02104.java: 43
LDAP_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02114.java: 43
LDAP_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00959.java: 53
LDAP_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02572.java: 43

More results are available on the CxOne platform

Policy Management Violations (1)

Policy Name: No highs or mediums
  • Rule Name: No Highs or Mediums
    Scanner: SAST

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL