Find, fix and prevent vulnerabilities in your code.
high severity
- Vulnerable module: org.apache.commons:commons-lang3
- Introduced through: org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › io.swagger.core.v3:swagger-core-jakarta@2.2.30 › org.apache.commons:commons-lang3@3.17.0Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.10.
Overview
Affected versions of this package are vulnerable to Uncontrolled Recursion via the ClassUtils.getClass
function. An attacker can cause the application to terminate unexpectedly by providing excessively long input values.
Remediation
Upgrade org.apache.commons:commons-lang3
to version 3.18.0 or higher.
References
high severity
- Vulnerable module: org.apache.tomcat.embed:tomcat-embed-core
- Introduced through: org.springframework.boot:spring-boot-starter-web@3.5.4
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-tomcat@3.5.4 › org.apache.tomcat.embed:tomcat-embed-core@10.1.43Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-tomcat@3.5.4 › org.apache.tomcat.embed:tomcat-embed-websocket@10.1.43 › org.apache.tomcat.embed:tomcat-embed-core@10.1.43Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
Overview
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation.
Affected versions of this package are vulnerable to Improper Resource Shutdown or Release via the HTTP/2 Handler. An attacker can cause a denial of service by sending specially crafted requests that exploit improper handling of resource shutdown.
Remediation
Upgrade org.apache.tomcat.embed:tomcat-embed-core
to version 9.0.108, 10.1.44, 11.0.10 or higher.
References
high severity
new
- Vulnerable module: org.springframework:spring-core
- Introduced through: org.springframework.boot:spring-boot-starter-aop@3.5.4, org.springframework.boot:spring-boot-starter-validation@3.5.4 and others
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework.data:spring-data-commons@3.5.2 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework.data:spring-data-commons@3.5.2 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.6.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-expression@6.2.9 › org.springframework:spring-core@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9 › org.springframework:spring-core@6.2.9
Overview
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities.
Affected versions of this package are vulnerable to Incorrect Authorization via the AnnotationsScanner
and AnnotatedMethod
class. An attacker can gain unauthorized access to sensitive information by exploiting improper resolution of annotations on methods within type hierarchies that use parameterized supertypes with unbounded generics.
Note:
This is only exploitable if security annotations are used on methods in generic superclasses or generic interfaces and the @EnableMethodSecurity
feature is enabled.
Remediation
Upgrade org.springframework:spring-core
to version 6.2.11 or higher.
References
high severity
- Vulnerable module: org.springframework:spring-beans
- Introduced through: org.springframework.boot:spring-boot-starter-aop@3.5.4, org.springframework.boot:spring-boot-starter-web@3.5.4 and others
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework.data:spring-data-commons@3.5.2 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework:spring-context-support@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-web@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springframework:spring-webmvc@6.2.9 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.data:spring-data-jpa@3.5.2 › org.springframework:spring-orm@7.0.0-M9 › org.springframework:spring-jdbc@6.2.9 › org.springframework:spring-tx@7.0.0-M9 › org.springframework:spring-beans@6.2.9
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-validation@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-aop@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-cache@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-actuator-autoconfigure@3.5.4 › org.springframework.boot:spring-boot-actuator@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-actuator@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-data-jpa@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springframework.boot:spring-boot-starter-web@3.5.5.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-autoconfigure@3.5.4 › org.springframework.boot:spring-boot@3.5.4 › org.springframework:spring-context@6.2.9 › org.springframework:spring-aop@6.2.9 › org.springframework:spring-beans@6.2.9Remediation: Upgrade to org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.11.
Overview
org.springframework:spring-beans is a package that is the basis for Spring Framework's IoC container. The BeanFactory interface provides an advanced configuration mechanism capable of managing any type of object.
Affected versions of this package are vulnerable to Relative Path Traversal when deployed on non-compliant Servlet containers. An unauthenticated attacker could gain access to files and directories outside the intended web root.
Notes:
This is only exploitable if the application is deployed as a WAR or with an embedded Servlet container, the Servlet container does not reject suspicious sequences and the application serves static resources with Spring resource handling.
Applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as default security features are not disabled in the configuration.
This vulnerability was also fixed in the commercial versions 6.1.22 and 5.3.44.
Remediation
Upgrade org.springframework:spring-beans
to version 6.2.10 or higher.
References
medium severity
new
- Vulnerable module: ch.qos.logback:logback-core
- Introduced through: org.springframework.boot:spring-boot-starter-validation@3.5.4, org.springframework.boot:spring-boot-starter-actuator@3.5.4 and others
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
Overview
ch.qos.logback:logback-core is a logback-core module.
Affected versions of this package are vulnerable to External Initialization of Trusted Variables or Data Stores via the conditional processing of the logback.xml
configuration file when both the Janino library and Spring Framework are present on the class path. An attacker can execute arbitrary code by compromising an existing configuration file or injecting a malicious environment variable before program execution. This is only exploitable if the attacker has write access to a configuration file or can set a malicious environment variable.
Remediation
Upgrade ch.qos.logback:logback-core
to version 1.5.19 or higher.
References
medium severity
- Module: ch.qos.logback:logback-classic
- Introduced through: org.springframework.boot:spring-boot-starter-validation@3.5.4, org.springframework.boot:spring-boot-starter-actuator@3.5.4 and others
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18
Dual license: EPL-1.0, LGPL-2.1
medium severity
- Module: ch.qos.logback:logback-core
- Introduced through: org.springframework.boot:spring-boot-starter-validation@3.5.4, org.springframework.boot:spring-boot-starter-actuator@3.5.4 and others
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-actuator@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-aop@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-cache@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.springframework.boot:spring-boot-starter-jdbc@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-web@3.5.4 › org.springframework.boot:spring-boot-starter-json@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springdoc:springdoc-openapi-starter-webmvc-ui@2.8.9 › org.springdoc:springdoc-openapi-starter-webmvc-api@2.8.9 › org.springdoc:springdoc-openapi-starter-common@2.8.9 › org.springframework.boot:spring-boot-starter-validation@3.5.4 › org.springframework.boot:spring-boot-starter@3.5.4 › org.springframework.boot:spring-boot-starter-logging@3.5.4 › ch.qos.logback:logback-classic@1.5.18 › ch.qos.logback:logback-core@1.5.18
Dual license: EPL-1.0, LGPL-2.1
medium severity
- Module: com.google.code.findbugs:annotations
- Introduced through: com.google.code.findbugs:annotations@3.0.1u2
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › com.google.code.findbugs:annotations@3.0.1u2
LGPL-2.0 license
medium severity
- Module: com.h2database:h2
- Introduced through: com.h2database:h2@2.3.232
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › com.h2database:h2@2.3.232
Dual license: EPL-1.0, MPL-2.0
medium severity
- Module: org.hibernate.common:hibernate-commons-annotations
- Introduced through: org.springframework.boot:spring-boot-starter-data-jpa@3.5.4
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.hibernate.orm:hibernate-core@6.6.22.Final › org.hibernate.common:hibernate-commons-annotations@7.0.3.Final
LGPL-2.1 license
medium severity
- Module: org.hibernate.orm:hibernate-core
- Introduced through: org.springframework.boot:spring-boot-starter-data-jpa@3.5.4
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › org.springframework.boot:spring-boot-starter-data-jpa@3.5.4 › org.hibernate.orm:hibernate-core@6.6.22.Final
LGPL-2.1 license
low severity
- Vulnerable module: org.jetbrains.kotlin:kotlin-stdlib
- Introduced through: io.github.resilience4j:resilience4j-spring-boot2@2.3.0
Detailed paths
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-consumer@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-consumer@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-bulkhead@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-circuitbreaker@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-ratelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-retry@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
-
Introduced through: mirogaudi/product-catalog-service@mirogaudi/product-catalog-service#4531614ea7ea7e16b2d12c0464654caf67f3d39d › io.github.resilience4j:resilience4j-spring-boot2@2.3.0 › io.github.resilience4j:resilience4j-spring@2.3.0 › io.github.resilience4j:resilience4j-framework-common@2.3.0 › io.github.resilience4j:resilience4j-micrometer@2.3.0 › io.github.resilience4j:resilience4j-timelimiter@2.3.0 › io.github.resilience4j:resilience4j-core@2.3.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk8@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib-jdk7@1.9.0 › org.jetbrains.kotlin:kotlin-stdlib@1.9.0
Overview
org.jetbrains.kotlin:kotlin-stdlib is a Kotlin Standard Library for JVM.
Affected versions of this package are vulnerable to Information Exposure. A Kotlin application using createTempDir
or createTempFile
and placing sensitive information within either of these locations would be leaking this information in a read-only way to other users also on this system.
Note: As of version 1.4.21, the vulnerable functions have been marked as deprecated. Due to still being usable, this advisory is kept as "unfixed".
PoC by JLLeitschuh
package org.jlleitschuh.sandbox
import org.junit.jupiter.api.Test
import java.io.BufferedReader
import java.io.File
import java.io.IOException
import java.io.InputStreamReader
import java.nio.file.Files
class KotlinTempDirectoryPermissionCheck {
@Test
fun `kotlin check default directory permissions`() {
val dir = createTempDir()
runLS(dir.parentFile, dir) // Prints drwxr-xr-x
}
@Test
fun `Files check default directory permissions`() {
val dir = Files.createTempDirectory("random-directory")
runLS(dir.toFile().parentFile, dir.toFile()) // Prints drwx------
}
@Test
fun `kotlin check default file permissions`() {
val file = createTempFile()
runLS(file.parentFile, file) // Prints -rw-r--r--
}
@Test
fun `Files check default file permissions`() {
val file = Files.createTempFile("random-file", ".txt")
runLS(file.toFile().parentFile, file.toFile()) // Prints -rw-------
}
private fun runLS(file: File, lookingFor: File) {
val processBuilder = ProcessBuilder()
processBuilder.command("ls", "-l", file.absolutePath)
try {
val process = processBuilder.start()
val output = StringBuilder()
val reader = BufferedReader(
InputStreamReader(process.inputStream)
)
reader.lines().forEach { line ->
if (line.contains("total")) {
output.append(line).append('\n')
}
if (line.contains(lookingFor.name)) {
output.append(line).append('\n')
}
}
val exitVal = process.waitFor()
if (exitVal == 0) {
println("Success!")
println(output)
} else {
//abnormal...
}
} catch (e: IOException) {
e.printStackTrace()
} catch (e: InterruptedException) {
e.printStackTrace()
}
}
}
Remediation
Upgrade org.jetbrains.kotlin:kotlin-stdlib
to version 2.1.0 or higher.