Update dependency com.google.guava:guava to v32 #53
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2023-34055Path to dependency file: /webgoat-container/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar Dependency Hierarchy: -> webgoat-container-8.2.1-SNAPSHOT.jar (Root Library) -> spring-boot-starter-actuator-2.4.3.jar -> spring-boot-actuator-autoconfigure-2.4.3.jar -> ❌ spring-boot-actuator-2.4.3.jar (Vulnerable Library) |
5.3 | Transitive spring-boot-actuator-2.4.3.jar |
webgoat-container-8.2.1-SNAPSHOT.jar | Transitive org.springframework.boot:spring-boot-actuator:2.7.18,3.0.13,3.1.6 |
#33 | |
CVE-2023-34055Path to dependency file: /webgoat-container/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar,/home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-actuator/2.4.3/spring-boot-actuator-2.4.3.jar Dependency Hierarchy: -> spring-boot-starter-actuator-2.4.3.jar (Root Library) -> spring-boot-actuator-autoconfigure-2.4.3.jar -> ❌ spring-boot-actuator-2.4.3.jar (Vulnerable Library) |
5.3 | Transitive spring-boot-actuator-2.4.3.jar |
spring-boot-starter-actuator-2.4.3.jar | Transitive org.springframework.boot:spring-boot-actuator:2.7.18,3.0.13,3.1.6 |
#31 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-11023 | jquery-2.1.4.min.js |
| CVE-2019-11358 | jquery-2.1.4.min.js |
| CVE-2020-8908 | guava-30.1-jre.jar |
| CVE-2015-9251 | jquery-2.1.4.min.js |
| CVE-2023-2976 | guava-30.1-jre.jar |
| CVE-2020-11022 | jquery-2.1.4.min.js |
Base branch total remaining vulnerabilities: 211
Base branch commit: null
Total libraries scanned: 189
Scan token: a66d5d5540cc4fab98fc8766d3c6cfff