[Snyk] Upgrade: com.unboundid:unboundid-ldapsdk, commons-collections:commons-collections, io.undertow:undertow-core, org.apache.commons:commons-lang3, org.apache.logging.log4j:log4j-core #180
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
com.unboundid:unboundid-ldapsdk
from 3.1.1 to 3.2.1 | 2 versions ahead of your current version | 8 years ago
on 2017-02-13
commons-collections:commons-collections
from 3.1 to 3.2.2 | 3 versions ahead of your current version | 9 years ago
on 2015-11-12
io.undertow:undertow-core
from 2.2.13.Final to 2.3.15.Final | 40 versions ahead of your current version | 2 months ago
on 2024-07-16
org.apache.commons:commons-lang3
from 3.11 to 3.16.0 | 5 versions ahead of your current version | a month ago
on 2024-08-01
org.apache.logging.log4j:log4j-core
from 2.15.0 to 2.23.1 | 13 versions ahead of your current version | 6 months ago
on 2024-03-06
Issues fixed by the recommended upgrade:
SNYK-JAVA-ORGJBOSSXNIO-6403375
SNYK-JAVA-IOUNDERTOW-3012383
SNYK-JAVA-IOUNDERTOW-3339519
SNYK-JAVA-IOUNDERTOW-7300152
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
SNYK-JAVA-ORGJBOSSXNIO-2994360
SNYK-JAVA-COMMONSCOLLECTIONS-30078
SNYK-JAVA-IOUNDERTOW-6567186
SNYK-JAVA-IOUNDERTOW-7433720
SNYK-JAVA-COMMONSCOLLECTIONS-472711
SNYK-JAVA-COMMONSCOLLECTIONS-6056408
SNYK-JAVA-IOUNDERTOW-2391283
SNYK-JAVA-IOUNDERTOW-6669948
SNYK-JAVA-IOUNDERTOW-7300153
SNYK-JAVA-IOUNDERTOW-2871356
SNYK-JAVA-IOUNDERTOW-3358786
SNYK-JAVA-IOUNDERTOW-7361775
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"com.unboundid:unboundid-ldapsdk","from":"3.1.1","to":"3.2.1"},{"name":"commons-collections:commons-collections","from":"3.1","to":"3.2.2"},{"name":"io.undertow:undertow-core","from":"2.2.13.Final","to":"2.3.15.Final"},{"name":"org.apache.commons:commons-lang3","from":"3.11","to":"3.16.0"},{"name":"org.apache.logging.log4j:log4j-core","from":"2.15.0","to":"2.23.1"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGJBOSSXNIO-6403375","issue_id":"SNYK-JAVA-ORGJBOSSXNIO-6403375","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Resource Consumption"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-3012383","issue_id":"SNYK-JAVA-IOUNDERTOW-3012383","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-3339519","issue_id":"SNYK-JAVA-IOUNDERTOW-3339519","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Certificate Validation"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-7300152","issue_id":"SNYK-JAVA-IOUNDERTOW-7300152","priority_score":649,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.7","score":435},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Resource Consumption"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524","issue_id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-ORGJBOSSXNIO-2994360","issue_id":"SNYK-JAVA-ORGJBOSSXNIO-2994360","priority_score":479,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Allocation of Resources Without Limits or Throttling"},{"exploit_maturity":"mature","id":"SNYK-JAVA-COMMONSCOLLECTIONS-30078","issue_id":"SNYK-JAVA-COMMONSCOLLECTIONS-30078","priority_score":919,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Deserialization of Untrusted Data"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-6567186","issue_id":"SNYK-JAVA-IOUNDERTOW-6567186","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Improper Input Validation"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-7433720","issue_id":"SNYK-JAVA-IOUNDERTOW-7433720","priority_score":649,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.7","score":435},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Recursion"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JAVA-COMMONSCOLLECTIONS-472711","issue_id":"SNYK-JAVA-COMMONSCOLLECTIONS-472711","priority_score":601,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.6","score":280},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Deserialization of Untrusted Data"},{"exploit_maturity":"mature","id":"SNYK-JAVA-COMMONSCOLLECTIONS-6056408","issue_id":"SNYK-JAVA-COMMONSCOLLECTIONS-6056408","priority_score":919,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Deserialization of Untrusted Data"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-2391283","issue_id":"SNYK-JAVA-IOUNDERTOW-2391283","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-6669948","issue_id":"SNYK-JAVA-IOUNDERTOW-6669948","priority_score":589,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Allocation of Resources Without Limits or Throttling"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-7300153","issue_id":"SNYK-JAVA-IOUNDERTOW-7300153","priority_score":649,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.7","score":435},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-2871356","issue_id":"SNYK-JAVA-IOUNDERTOW-2871356","priority_score":479,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-3358786","issue_id":"SNYK-JAVA-IOUNDERTOW-3358786","priority_score":479,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JAVA-IOUNDERTOW-7361775","issue_id":"SNYK-JAVA-IOUNDERTOW-7361775","priority_score":479,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"5.3","score":265},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Directory Traversal"},{"exploit_maturity":"mature","id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014","issue_id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014","priority_score":879,"priority_score_factors":[{"type":"exploit","label":"High","score":214},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"9","score":450},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Remote Code Execution (RCE)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339","issue_id":"SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339","priority_score":651,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.6","score":330},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Arbitrary Code Execution"}],"prId":"c2884ea2-0e0a-426c-bf1f-f5f3d4a4fccd","prPublicId":"c2884ea2-0e0a-426c-bf1f-f5f3d4a4fccd","packageManager":"maven","priorityScoreList":[589,589,589,649,696,479,919,589,649,601,919,589,589,649,479,479,479,879,651],"projectPublicId":"12ba0d0f-f584-40a6-ad23-bb2ca0d124ae","projectUrl":"https://app.snyk.io/org/victoria.slater/project/12ba0d0f-f584-40a6-ad23-bb2ca0d124ae?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JAVA-ORGJBOSSXNIO-6403375","SNYK-JAVA-IOUNDERTOW-3012383","SNYK-JAVA-IOUNDERTOW-3339519","SNYK-JAVA-IOUNDERTOW-7300152","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524","SNYK-JAVA-ORGJBOSSXNIO-2994360","SNYK-JAVA-COMMONSCOLLECTIONS-30078","SNYK-JAVA-IOUNDERTOW-6567186","SNYK-JAVA-IOUNDERTOW-7433720","SNYK-JAVA-COMMONSCOLLECTIONS-472711","SNYK-JAVA-COMMONSCOLLECTIONS-6056408","SNYK-JAVA-IOUNDERTOW-2391283","SNYK-JAVA-IOUNDERTOW-6669948","SNYK-JAVA-IOUNDERTOW-7300153","SNYK-JAVA-IOUNDERTOW-2871356","SNYK-JAVA-IOUNDERTOW-3358786","SNYK-JAVA-IOUNDERTOW-7361775","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339"],"upgradeInfo":{"versionsDiff":2,"publishedDate":"2017-02-13T18:52:08.000Z"},"vulns":["SNYK-JAVA-ORGJBOSSXNIO-6403375","SNYK-JAVA-IOUNDERTOW-3012383","SNYK-JAVA-IOUNDERTOW-3339519","SNYK-JAVA-IOUNDERTOW-7300152","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524","SNYK-JAVA-ORGJBOSSXNIO-2994360","SNYK-JAVA-COMMONSCOLLECTIONS-30078","SNYK-JAVA-IOUNDERTOW-6567186","SNYK-JAVA-IOUNDERTOW-7433720","SNYK-JAVA-COMMONSCOLLECTIONS-472711","SNYK-JAVA-COMMONSCOLLECTIONS-6056408","SNYK-JAVA-IOUNDERTOW-2391283","SNYK-JAVA-IOUNDERTOW-6669948","SNYK-JAVA-IOUNDERTOW-7300153","SNYK-JAVA-IOUNDERTOW-2871356","SNYK-JAVA-IOUNDERTOW-3358786","SNYK-JAVA-IOUNDERTOW-7361775","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014","SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339"]}'