Skip to content

[Snyk] Fix for 7 vulnerabilities#3658

Open
AntonioG70 wants to merge 1 commit intodevelopmentfrom
snyk-fix-43a4866005664a342b7e8e964f41b25e
Open

[Snyk] Fix for 7 vulnerabilities#3658
AntonioG70 wants to merge 1 commit intodevelopmentfrom
snyk-fix-43a4866005664a342b7e8e964f41b25e

Conversation

@AntonioG70
Copy link
Copy Markdown
Collaborator

snyk-top-banner

Snyk has created this PR to fix 7 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
medium severity Missing Critical Step in Authentication
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546
org.apache.httpcomponents.client5:httpclient5:
5.6 -> 5.6.1
No Known Exploit
low severity Improper Validation of Certificate with Host Mismatch
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16191022
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
org.springframework.boot:spring-boot-starter:
3.5.12 -> 3.5.14
No Known Exploit
high severity Timing Attack
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16191381
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
No Known Exploit
medium severity Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16191649
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
org.springframework.boot:spring-boot-starter:
3.5.12 -> 3.5.14
No Known Exploit
high severity Insecure Temporary File
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16198880
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
org.springframework.boot:spring-boot-starter:
3.5.12 -> 3.5.14
No Known Exploit
low severity Improper Validation of Certificate with Host Mismatch
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16200231
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
org.springframework.boot:spring-boot-starter:
3.5.12 -> 3.5.14
No Known Exploit
medium severity Symlink Attack
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-16201011
org.springframework.boot:spring-boot-devtools:
3.5.12 -> 3.5.14
org.springframework.boot:spring-boot-starter:
3.5.12 -> 3.5.14
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
🦉 Insecure Temporary File

@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. dependencies Pull requests that update a dependency file labels Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants