Skip to content

[Snyk] Fix for 25 vulnerabilities - #239

Open
chncaption wants to merge 1 commit into
masterfrom
snyk-fix-e9e1af66965068f411ed90db34016565
Open

[Snyk] Fix for 25 vulnerabilities#239
chncaption wants to merge 1 commit into
masterfrom
snyk-fix-e9e1af66965068f411ed90db34016565

Conversation

@chncaption

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 25 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • fe/pom.xml

Vulnerabilities that will be fixed with an upgrade:

IssueScoreUpgrade
critical severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-572732
811org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeProof of Concept
high severitySQL Injection
SNYK-JAVA-LOG4J-2342645
726org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeProof of Concept
critical severityImproper Input Validation
SNYK-JAVA-ORGCODEHAUSJACKSON-3326362
704org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJETTISON-3168085
696org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeProof of Concept
high severityDenial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJETTISON-3367610
696org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeProof of Concept
medium severityArbitrary Code Execution
SNYK-JAVA-LOG4J-2316893
651org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeProof of Concept
medium severityImproper Validation of Syntactic Correctness of Input
SNYK-JAVA-ORGECLIPSEJETTY-8186141
636Major version upgradeProof of Concept
medium severityImproper Validation of Syntactic Correctness of Input
SNYK-JAVA-ORGECLIPSEJETTY-8186158
636Major version upgradeProof of Concept
high severityDenial of Service (DoS)
SNYK-JAVA-ORGECLIPSEJETTY-8186142
624Major version upgradeNo Known Exploit
high severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342646
619org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
high severityDeserialization of Untrusted Data
SNYK-JAVA-LOG4J-2342647
619org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
high severityXML External Entity (XXE) Injection
SNYK-JAVA-ORGCODEHAUSJACKSON-534878
589org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
high severityDenial of Service (DoS)
SNYK-JAVA-ORGECLIPSEJETTY-5958847
589No Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGECLIPSEJETTY-5426159
586Proof of Concept
medium severityImproper Handling of Length Parameter Inconsistency
SNYK-JAVA-ORGECLIPSEJETTY-5902998
586Proof of Concept
medium severityXML External Entity (XXE) Injection
SNYK-JAVA-COMSUNJERSEY-10441493
559org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
medium severityImproper Resource Shutdown or Release
SNYK-JAVA-ORGECLIPSEJETTY-10079022
559Major version upgradeNo Known Exploit
medium severityCryptographic Issues
SNYK-JAVA-ORGAPACHEDIRECTORYSERVER-1063040
550org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
medium severityStack-based Buffer Overflow
SNYK-JAVA-ORGCODEHAUSJETTISON-3033152
539org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-ORGCODEHAUSJETTISON-3037311
539org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
medium severityDenial of Service (DoS)
SNYK-JAVA-LOG4J-3358774
509org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
low severityInformation Exposure
SNYK-JAVA-ORGECLIPSEJETTY-5426160
441Proof of Concept
low severityInformation Exposure
SNYK-JAVA-ORGECLIPSEJETTY-5426161
441Proof of Concept
low severityInformation Exposure
SNYK-JAVA-COMMONSCODEC-561518
399org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit
low severityMan-in-the-Middle (MitM)
SNYK-JAVA-LOG4J-1300176
399org.apache.hive:hive-metastore:
2.3.7 -> 4.0.0
Major version upgradeNo Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:spring-boot-starter-jetty@2.7.3 to org.springframework.boot:spring-boot-starter-jetty@3.2.0; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/2.7.3/spring-boot-dependencies-2.7.3.pom

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 XML External Entity (XXE) Injection
🦉 Arbitrary Code Execution
🦉 SQL Injection
🦉 More lessons are available in Snyk Learn

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chncaption@snyk-bot