Skip to content

Conversation

@Raj2020Github
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • todolist-goof/todolist-web-struts/pom.xml
    • todolist-goof/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity Reachability
medium severity 535/1000
Why? Mature exploit, Has a fix available, CVSS 5.3
Directory Traversal
SNYK-JAVA-COMMONSIO-1277109
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
Yes Mature No Path Found
critical severity 800/1000
Why? Mature exploit, Has a fix available, CVSS 10
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2314720
org.apache.logging.log4j:log4j-core:
2.7 -> 2.12.4
No Mature No Path Found
critical severity 750/1000
Why? Mature exploit, Has a fix available, CVSS 9
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014
org.apache.logging.log4j:log4j-core:
2.7 -> 2.12.4
No Mature No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
org.apache.logging.log4j:log4j-core:
2.7 -> 2.12.4
No Proof of Concept No Path Found
medium severity 555/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.6
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339
org.apache.logging.log4j:log4j-core:
2.7 -> 2.12.4
No Proof of Concept No Path Found
critical severity 760/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Deserialization of Untrusted Data
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-31409
org.apache.logging.log4j:log4j-core:
2.7 -> 2.12.4
No Mature No Path Found
critical severity 790/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHESTRUTS-1049003
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
high severity 630/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHESTRUTS-2635340
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Proof of Concept No Path Found
critical severity 800/1000
Why? Mature exploit, Has a fix available, CVSS 10
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHESTRUTS-30207
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
high severity 705/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Command Injection
SNYK-JAVA-ORGAPACHESTRUTS-30770
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
critical severity 790/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Arbitrary Command Execution
SNYK-JAVA-ORGAPACHESTRUTS-30772
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
high severity 705/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Arbitrary Command Execution
SNYK-JAVA-ORGAPACHESTRUTS-31495
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
critical severity 760/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHESTRUTS-31503
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
high severity 705/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Remote Code Execution
SNYK-JAVA-ORGAPACHESTRUTS-32477
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
critical severity 760/1000
Why? Mature exploit, Has a fix available, CVSS 9.8
Remote Code Execution (RCE)
SNYK-JAVA-ORGAPACHESTRUTS-608097
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Mature No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGAPACHESTRUTS-608098
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
org.apache.struts:struts2-spring-plugin:
2.3.20 -> 2.5.30
No Proof of Concept No Path Found
high severity 705/1000
Why? Mature exploit, Has a fix available, CVSS 8.1
Command Injection
SNYK-JAVA-ORGAPACHESTRUTSXWORK-451611
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
No Mature No Path Found
high severity 600/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Server-side Template Injection (SSTI)
SNYK-JAVA-ORGFREEMARKER-1076795
org.apache.struts:struts2-core:
2.3.20 -> 6.1.2
No Proof of Concept No Path Found

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal
🦉 Remote Code Execution (RCE)
🦉 Denial of Service (DoS)
🦉 More lessons are available in Snyk Learn

@Raj2020Github Raj2020Github merged commit 40acfe7 into main Nov 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants