[Snyk] Fix for 1 vulnerabilities - #11
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695
|
This upgrade involves multiple, significant major version jumps, including a platform migration from Spring Boot 1.5 to 2.0. These changes are substantial and will require code and configuration modifications. Spring Boot & Spring Cloud Upgrade (1.5.x → 2.0.0)Upgrading Key Breaking Changes:
Source: Spring Boot 2.0 Migration Guide Recommendation: Treat this as a dedicated migration project. Review the official Spring Boot 2.0 Migration Guide thoroughly. Add the io.jsonwebtoken:jjwt (0.9.1 → 0.12.0)This is a major upgrade with significant structural and API changes. Key Breaking Changes:
Source: JJWT CHANGELOG Recommendation: Update your build files to use the new modular artifacts (
|
Wiz Scan Summary
|
| Scanner | Findings |
|---|---|
| 3 |
|
| - | |
| - | |
| - | |
| - | |
| Total | 3 |
To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [io.netty:netty-handler:4.0.27.Final]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2016-4970 |
https://github.com/advisories/GHSA-rv63-gqm8-9w8q |
4.0.37.Final |
7.5 | 3.9 | false | false | |
CVE-2019-20445 |
https://github.com/advisories/GHSA-p2v9-g2qv-p635 |
4.1.45 |
9.1 | 3.9 | true | false | |
CVE-2023-34462 |
https://github.com/advisories/GHSA-6mjq-h674-j845 |
4.1.94.Final |
6.5 | 2.8 | true | false | |
CVE-2026-44249 |
https://github.com/advisories/GHSA-3qp7-7mw8-wx86 |
4.1.135.Final |
8.1 | 2.2 | false | false | |
CVE-2026-45416 |
https://github.com/advisories/GHSA-x4gw-5cx5-pgmh |
4.1.135.Final |
7.5 | 3.9 | false | false | |
CVE-2026-50010 |
https://github.com/advisories/GHSA-c653-97m9-rcg9 |
4.1.135.Final |
7.5 | 3.9 | false | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [io.netty:netty-codec-http:4.0.27.Final]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2019-20444 |
https://github.com/advisories/GHSA-cqqj-4p63-rrmm |
4.1.44 |
9.1 | 3.9 | true | false | |
CVE-2021-21290 |
https://github.com/advisories/GHSA-5mcr-gq6c-3hq2 |
4.1.59.Final |
5.5 | 1.8 | true | false | |
CVE-2021-43797 |
https://github.com/advisories/GHSA-wx5j-54mm-rqqq |
4.1.71.Final |
6.5 | 2.8 | false | false | |
CVE-2022-24823 |
https://github.com/advisories/GHSA-269q-hmxg-m83q |
4.1.77.Final |
5.5 | 1.8 | true | false | |
CVE-2024-29025 |
https://github.com/advisories/GHSA-5jpm-x58v-624v |
4.1.108.Final |
5.3 | 3.9 | true | false | |
CVE-2025-58056 |
https://github.com/advisories/GHSA-fghv-69vj-qj49 |
4.1.125.Final |
2.9 | 3.9 | true | false | |
CVE-2025-67735 |
https://github.com/advisories/GHSA-84h7-rjj3-6jx4 |
4.1.129.Final |
6.5 | 3.9 | true | false | |
CVE-2026-33870 |
https://github.com/advisories/GHSA-pwqr-wmgm-9rr8 |
4.1.132.Final |
7.5 | 3.9 | true | false | |
CVE-2026-41417 |
https://github.com/advisories/GHSA-v8h7-rr48-vmmv |
4.1.133.Final |
5.3 | 3.9 | true | false | |
CVE-2026-42580 |
https://github.com/advisories/GHSA-m4cv-j2px-7723 |
4.1.133.Final |
6.5 | 3.9 | true | false | |
CVE-2026-42581 |
https://github.com/advisories/GHSA-xxqh-mfjm-7mv9 |
4.1.133.Final |
9.8 | 3.9 | true | false | |
CVE-2026-42584 |
https://github.com/advisories/GHSA-57rv-r2g8-2cj3 |
4.1.133.Final |
9.1 | 3.9 | true | false | |
CVE-2026-42585 |
https://github.com/advisories/GHSA-38f8-5428-x5cv |
4.1.133.Final |
7.5 | 3.9 | true | false | |
CVE-2026-42587 |
https://github.com/advisories/GHSA-f6hv-jmp6-3vwv |
4.1.133.Final |
7.5 | 3.9 | true | false | |
CVE-2026-50020 |
https://github.com/advisories/GHSA-hvcg-qmg6-jm4c |
4.1.135.Final |
5.3 | 3.9 | false | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [com.thoughtworks.xstream:xstream:1.4.10]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2013-7285 |
https://github.com/advisories/GHSA-f554-x222-wgf7 |
1.4.11 |
9.8 | 3.9 | true | false | |
CVE-2019-10173 |
https://github.com/advisories/GHSA-hf23-9pf7-388p |
1.4.11 |
9.8 | 3.9 | false | false | |
CVE-2020-26217 |
https://github.com/advisories/GHSA-mw36-7c6c-q4q2 |
1.4.14-java7 |
8.8 | 2.8 | true | false | |
CVE-2020-26258 |
https://github.com/advisories/GHSA-4cch-wxpw-8p28 |
1.4.15 |
7.7 | 3.1 | true | false | |
CVE-2020-26259 |
https://github.com/advisories/GHSA-jfvx-7wrx-43fh |
1.4.15 |
6.8 | 2.2 | true | false | |
CVE-2021-21341 |
https://github.com/advisories/GHSA-2p3x-qw9c-25hh |
1.4.16 |
7.5 | 3.9 | true | false | |
CVE-2021-21342 |
https://github.com/advisories/GHSA-hvv8-336g-rx3m |
1.4.16 |
9.1 | 3.9 | true | false | |
CVE-2021-21343 |
https://github.com/advisories/GHSA-74cv-f58x-f9wf |
1.4.16 |
7.5 | 3.9 | true | false | |
CVE-2021-21344 |
https://github.com/advisories/GHSA-59jw-jqf4-3wq3 |
1.4.16 |
9.8 | 3.9 | true | false | |
CVE-2021-21345 |
https://github.com/advisories/GHSA-hwpc-8xqv-jvj4 |
1.4.16 |
9.9 | 3.1 | true | false | |
CVE-2021-21346 |
https://github.com/advisories/GHSA-4hrm-m67v-5cxr |
1.4.16 |
9.8 | 3.9 | true | false | |
CVE-2021-21347 |
https://github.com/advisories/GHSA-qpfq-ph7r-qv6f |
1.4.16 |
9.8 | 3.9 | true | false | |
CVE-2021-21348 |
https://github.com/advisories/GHSA-56p8-3fh9-4cvq |
1.4.16 |
7.5 | 3.9 | false | false | |
CVE-2021-21349 |
https://github.com/advisories/GHSA-f6hm-88x3-mfjv |
1.4.16 |
8.6 | 3.9 | true | false | |
CVE-2021-21350 |
https://github.com/advisories/GHSA-43gc-mjxg-gvrq |
1.4.16 |
9.8 | 3.9 | true | false | |
CVE-2021-21351 |
https://github.com/advisories/GHSA-hrcp-8f3q-4w2c |
1.4.16 |
9.1 | 2.3 | true | false | |
CVE-2021-29505 |
https://github.com/advisories/GHSA-7chv-rrw6-w6fc |
1.4.17 |
8.8 | 2.8 | true | false | |
CVE-2021-39139 |
https://github.com/advisories/GHSA-64xx-cq4q-mf44 |
1.4.18 |
8.8 | 2.8 | false | false | |
CVE-2021-39140 |
https://github.com/advisories/GHSA-6wf9-jmg9-vxcc |
1.4.18 |
6.3 | 1.8 | true | false | |
CVE-2021-39141 |
https://github.com/advisories/GHSA-g5w6-mrj7-75h2 |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39144 |
https://github.com/advisories/GHSA-j9h8-phrw-h4fh |
1.4.18 |
8.5 | 1.8 | true | true | |
CVE-2021-39145 |
https://github.com/advisories/GHSA-8jrj-525p-826v |
1.4.18 |
8.5 | 1.8 | false | false | |
CVE-2021-39146 |
https://github.com/advisories/GHSA-p8pq-r894-fm8f |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39147 |
https://github.com/advisories/GHSA-h7v4-7xg3-hxcc |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39148 |
https://github.com/advisories/GHSA-qrx8-8545-4wg2 |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39149 |
https://github.com/advisories/GHSA-3ccq-5vw3-2p6x |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39150 |
https://github.com/advisories/GHSA-cxfm-5m4g-x7xp |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39151 |
https://github.com/advisories/GHSA-hph2-m3g5-xxv4 |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39152 |
https://github.com/advisories/GHSA-xw4p-crpj-vjx2 |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39153 |
https://github.com/advisories/GHSA-2q8x-2p7f-574v |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-39154 |
https://github.com/advisories/GHSA-6w62-hx7r-mw68 |
1.4.18 |
8.5 | 1.8 | true | false | |
CVE-2021-43859 |
https://github.com/advisories/GHSA-rmr5-cpv2-vgjf |
1.4.19 |
7.5 | 3.9 | true | false | |
CVE-2022-40151 |
https://github.com/advisories/GHSA-f8cc-g7j8-xxpm |
1.4.20 |
7.5 | 3.9 | true | false | |
CVE-2022-41966 |
https://github.com/advisories/GHSA-j563-grx4-pjpv |
1.4.20 |
7.5 | 3.9 | true | false | |
CVE-2024-47072 |
https://github.com/advisories/GHSA-hfq9-hggm-c56q |
1.4.21 |
7.5 | 3.9 | false | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [org.bouncycastle:bcprov-jdk15on:1.56]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2018-1000180 |
https://github.com/advisories/GHSA-xqj7-j8j5-f2xr |
1.60 |
7.5 | 3.9 | false | false | |
CVE-2020-15522 |
https://github.com/advisories/GHSA-6xx3-rg99-gc3p |
1.66 |
5.9 | 2.2 | false | false | |
CVE-2020-26939 |
https://github.com/advisories/GHSA-72m5-fvvv-55m6 |
1.61 |
5.3 | 3.9 | false | false | |
CVE-2023-33201 |
https://github.com/advisories/GHSA-hr8g-6v94-x4m9 |
- | 5.3 | 3.9 | false | false | |
CVE-2023-33202 |
https://github.com/advisories/GHSA-wjxj-5m7g-mg7q |
- | 5.5 | 1.8 | true | false | |
CVE-2024-29857 |
https://github.com/advisories/GHSA-8xfc-gm6g-vgpv |
1.78 |
7.5 | 3.9 | false | false | |
CVE-2024-30171 |
https://github.com/advisories/GHSA-v435-xc8x-wvr9 |
1.78 |
5.9 | 2.2 | false | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [org.codehaus.jettison:jettison:1.3.7]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2022-40149 |
https://github.com/advisories/GHSA-56h3-78gp-v83r |
1.5.1 |
7.5 | 3.9 | false | false | |
CVE-2022-40150 |
https://github.com/advisories/GHSA-x27m-9w8j-5vcw |
1.5.2 |
7.5 | 3.9 | false | false | |
CVE-2022-45685 |
https://github.com/advisories/GHSA-7rf3-mqpx-h7xg |
1.5.2 |
7.5 | 3.9 | true | false | |
CVE-2022-45693 |
https://github.com/advisories/GHSA-grr4-wv38-f68w |
1.5.2 |
7.5 | 3.9 | true | false | |
CVE-2023-1436 |
https://github.com/advisories/GHSA-q6g2-g7f3-rr83 |
1.5.4 |
7.5 | 3.9 | true | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
| <groupId>org.springframework.cloud</groupId> | ||
| <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId> | ||
| <version>1.4.0.RELEASE</version> | ||
| <version>2.0.0.RELEASE</version> |
There was a problem hiding this comment.
More Details
Vulnerabilities [io.netty:netty-codec:4.0.27.Final]
| Name | Severity | Source | Fixed version | CVSS score | CVSS exploitability score | Has public exploit | Has CISA KEV exploit |
|---|---|---|---|---|---|---|---|
CVE-2021-37136 |
https://github.com/advisories/GHSA-grg4-wf29-r9vv |
4.1.68.Final |
7.5 | 3.9 | false | false | |
CVE-2021-37137 |
https://github.com/advisories/GHSA-9vjp-v76f-g363 |
4.1.68.Final |
7.5 | 3.9 | false | false | |
CVE-2025-58057 |
https://github.com/advisories/GHSA-3p8m-j85q-pgmj |
4.1.125.Final |
6.9 | 3.9 | true | false | |
CVE-2026-42583 |
https://github.com/advisories/GHSA-mj4r-2hfc-f8p6 |
4.1.133.Final |
7.5 | 3.9 | true | false |
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695
0.9.1->0.12.0org.springframework.cloud:spring-cloud-starter-netflix-eureka-client:
1.4.0.RELEASE->2.0.0.RELEASEMajor version upgradeProof of ConceptBreaking Change Risk
Vulnerabilities that could not be fixed
org.springframework.boot:[email protected]toorg.springframework.boot:[email protected]; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.1.RELEASE/spring-boot-dependencies-1.5.1.RELEASE.pomorg.springframework.boot:[email protected]toorg.springframework.boot:[email protected]; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/1.5.1.RELEASE/spring-boot-dependencies-1.5.1.RELEASE.pomImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Improperly Controlled Modification of Dynamically-Determined Object Attributes