Skip to content

fix: pom.xml to reduce vulnerabilities

21c449a
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade io.undertow:undertow-core from 2.0.9.Final to 2.3.20.Final #155

fix: pom.xml to reduce vulnerabilities
21c449a
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Oct 23, 2025 in 30s

An automation triggered a pipeline warning

Found 38 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2020-10683 7.5 9.8 dom4j:dom4j (Maven) Plexus
CVE-2015-7501 10 9.8 commons-collections:commons-collections (Maven) Apache-2.0
CVE-2018-3258 6.5 8.8 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2017-3523 6 8.5 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2023-22102 N/A 8.3 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2022-42252 N/A 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2023-46589 N/A 7.5 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2023-44487 N/A 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2024-38286 N/A 7.5 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2022-45689 N/A 7.5 org.json:json (Maven) JSON
CVE-2022-45690 N/A 7.5 org.json:json (Maven) JSON
CVE-2024-34750 N/A 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2015-6420 7.5 N/A commons-collections:commons-collections (Maven) Apache-2.0
CVE-2022-45688 N/A 7.5 org.json:json (Maven) JSON
CVE-2025-52434 N/A 7.5 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2024-24549 N/A 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2020-17527 5 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2023-24998 N/A 7.5 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2018-1000632 5 7.5 dom4j:dom4j (Maven) Plexus
CVE-2020-25638 5.8 7.4 org.hibernate:hibernate-core (Maven) LGPL-2.0-or-later, LGPL-2.1-only
CVE-2022-21363 6 6.6 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2019-14900 4 6.5 org.hibernate:hibernate-core (Maven) LGPL-2.0-or-later, LGPL-2.1-only
CVE-2017-3586 5.5 6.4 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2019-2692 3.5 6.3 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2023-41080 N/A 6.1 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2021-24122 4.3 5.9 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2024-21733 N/A 5.3 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2020-2934 5.1 5 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2015-2575 4.9 N/A mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2020-1935 5.8 4.8 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2020-2875 4 4.7 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2020-13943 4 4.3 org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
CVE-2021-43980 N/A 3.7 org.apache.tomcat:tomcat-util (Maven) Apache-2.0
CVE-2017-3589 2.1 3.3 mysql:mysql-connector-java (Maven) GPL-2.0-only
CVE-2020-2933 3.5 2.2 mysql:mysql-connector-java (Maven) GPL-2.0-only
debricked-233322 N/A N/A org.json:json (Maven) JSON
debricked-230251 N/A N/A org.apache.tomcat:tomcat-coyote (Maven) Apache-2.0
debricked-233321 N/A N/A org.json:json (Maven) JSON