Skip to content

[Snyk] Fix for 9 vulnerabilities#1272

Open
sathishp-eGov wants to merge 1 commit into
masterfrom
snyk-fix-c912322da4348ed59220ddb17f0c4f83
Open

[Snyk] Fix for 9 vulnerabilities#1272
sathishp-eGov wants to merge 1 commit into
masterfrom
snyk-fix-c912322da4348ed59220ddb17f0c4f83

Conversation

@sathishp-eGov
Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 9 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • core-services/egov-accesscontrol/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551
org.flywaydb:flyway-core:
9.22.3 -> 11.8.1
Major version upgrade No Known Exploit
high severity Improper Authentication
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989808
No Known Exploit
medium severity Improper Encoding or Escaping of Output
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989812
Major version upgrade No Known Exploit
high severity Improper Authentication
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989820
Major version upgrade No Known Exploit
high severity HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-15990633
No Known Exploit
medium severity Open Redirect
SNYK-JAVA-ORGAPACHETOMCATEMBED-15990787
No Known Exploit
low severity HTTP Request Smuggling
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109603
Major version upgrade No Known Exploit
high severity Incomplete Cleanup
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618
org.springframework.boot:spring-boot-starter-validation:
3.2.3 -> 3.5.12
No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:spring-boot-starter-cache@3.4.5 to org.springframework.boot:spring-boot-starter-cache@3.5.12; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location
  • Could not upgrade org.springframework.boot:spring-boot-starter-jdbc@3.4.5 to org.springframework.boot:spring-boot-starter-jdbc@3.5.12; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location
  • Could not upgrade org.springframework.boot:spring-boot-starter-web@3.4.5 to org.springframework.boot:spring-boot-starter-web@4.0.0; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Improper Authentication
🦉 Improper Encoding or Escaping of Output
🦉 More lessons are available in Snyk Learn

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Apr 23, 2026

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 4ec99d45-619a-41b8-9349-c4e201145da3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch snyk-fix-c912322da4348ed59220ddb17f0c4f83

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants