Skip to content

Update dependency org.asciidoctor:asciidoctorj to v2.5.3

86fdd1d
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.asciidoctor:asciidoctorj to v2.5.3 #50

Update dependency org.asciidoctor:asciidoctorj to v2.5.3
86fdd1d
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed May 26, 2026 in 9m 30s

Security Report

You have successfully remediated 5 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2023-34055

Path to dependency file: /webgoat-server/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar

Dependency Hierarchy:

-> webgoat-container-8.2.1-SNAPSHOT.jar (Root Library)

   -> spring-boot-starter-actuator-2.4.3.jar

     -> spring-boot-actuator-autoconfigure-2.4.3.jar

       -> ❌ spring-boot-actuator-2.4.3.jar (Vulnerable Library)

Medium 5.3 Transitive spring-boot-actuator-2.4.3.jar webgoat-container-8.2.1-SNAPSHOT.jar Transitive org.springframework.boot:spring-boot-actuator:2.7.18,3.0.13,3.1.6 #⁠33
CVE-2023-34055

Path to dependency file: /webgoat-server/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-2.4.3.jar (Root Library)

   -> spring-boot-actuator-autoconfigure-2.4.3.jar

     -> ❌ spring-boot-actuator-2.4.3.jar (Vulnerable Library)

Medium 5.3 Transitive spring-boot-actuator-2.4.3.jar spring-boot-starter-actuator-2.4.3.jar Transitive org.springframework.boot:spring-boot-actuator:2.7.18,3.0.13,3.1.6 #⁠31

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-11023 jquery-2.1.4.min.js
WS-2019-0490 jcommander-1.72.jar
CVE-2019-11358 jquery-2.1.4.min.js
CVE-2015-9251 jquery-2.1.4.min.js
CVE-2020-11022 jquery-2.1.4.min.js

Base branch total remaining vulnerabilities: 211
Base branch commit: null


Total libraries scanned: 188

Scan token: f2a6d241994d4283b0fc951d1ad23512