Skip to content

[Snyk] Fix for 9 vulnerabilities#1275

Open
jagankumar-egov wants to merge 1 commit into
masterfrom
snyk-fix-c5313f40e5936eb21469d20145daa840
Open

[Snyk] Fix for 9 vulnerabilities#1275
jagankumar-egov wants to merge 1 commit into
masterfrom
snyk-fix-c5313f40e5936eb21469d20145daa840

Conversation

@jagankumar-egov
Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 9 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • core-services/egov-notification-mail/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551
No Known Exploit
high severity Improper Authentication
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989808
No Known Exploit
medium severity Improper Encoding or Escaping of Output
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989812
Major version upgrade No Known Exploit
high severity Improper Authentication
SNYK-JAVA-ORGAPACHETOMCATEMBED-15989820
Major version upgrade No Known Exploit
high severity HTTP Request Smuggling
SNYK-JAVA-ORGAPACHETOMCATEMBED-15990633
No Known Exploit
medium severity Open Redirect
SNYK-JAVA-ORGAPACHETOMCATEMBED-15990787
No Known Exploit
low severity HTTP Request Smuggling
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109603
Major version upgrade No Known Exploit
high severity Incomplete Cleanup
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618
org.springframework:spring-context-support:
4.3.4.RELEASE -> 6.2.17
Major version upgrade No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:spring-boot-starter-web@3.4.5 to org.springframework.boot:spring-boot-starter-web@4.0.0; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location
  • Could not upgrade org.springframework.kafka:spring-kafka@3.3.5 to org.springframework.kafka:spring-kafka@3.3.14; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location
  • Could not upgrade org.springframework:spring-beans@6.2.11 to org.springframework:spring-beans@6.2.17; Reason could not apply upgrade, dependency is managed externally ; Location: provenance does not contain location

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling
🦉 Improper Authentication
🦉 Improper Encoding or Escaping of Output
🦉 More lessons are available in Snyk Learn

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Apr 23, 2026

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 60ad9abc-ad98-4297-9a63-a7f147290a09

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch snyk-fix-c5313f40e5936eb21469d20145daa840

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants