Your dependencies cross-checked against the OSV vulnerability database.
-
Serious GHSA-c427-hjc3-wrfw Cross-site scripting in Swagger-UI
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-admin/pom.xml
A package you depend on has a known security hole (CVE-2019-17495). Fix: Update that package to its patched version.
-
Serious GHSA-6x49-w35h-wqrj Bypass serialize checks in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-bootstrap/pom.xml
A package you depend on has a known security hole (CVE-2023-29234). Fix: Update that package to its patched version.
-
Serious GHSA-933g-v89r-x8pf Apache Dubbo vulnerable to Deserialization of Untrusted Data
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-bootstrap/pom.xml
A package you depend on has a known security hole (CVE-2023-23638). Fix: Update that package to its patched version.
-
Serious GHSA-933g-v89r-x8pf Apache Dubbo vulnerable to Deserialization of Untrusted Data
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-client/shenyu-client-dubbo/shenyu-client-apache-dubbo/pom.xml
A package you depend on has a known security hole (CVE-2023-23638). Fix: Update that package to its patched version.
-
Serious GHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methods
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-e2e/shenyu-e2e-client/pom.xml
A package you depend on has a known security hole (CVE-2016-1000027). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-alibaba-dubbo-service-annotation/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-5mc7-m686-p6jg Deserialization of Untrusted Data in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-alibaba-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2021-30179). Fix: Update that package to its patched version.
-
Serious GHSA-qmfc-6www-fjqw Code injection in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-alibaba-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2021-30181). Fix: Update that package to its patched version.
-
Serious GHSA-v2rg-8cwr-75g8 Deserializer tampering in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-alibaba-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2021-25641). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-alibaba-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service-annotation/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-5qwq-g2hx-r6f7 Hessian Lite for Apache Dubbo deserialization vulnerability
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service-xml/pom.xml
A package you depend on has a known security hole (CVE-2022-39198). Fix: Update that package to its patched version.
-
Serious GHSA-933g-v89r-x8pf Apache Dubbo vulnerable to Deserialization of Untrusted Data
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service-xml/pom.xml
A package you depend on has a known security hole (CVE-2023-23638). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service-xml/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-5qwq-g2hx-r6f7 Hessian Lite for Apache Dubbo deserialization vulnerability
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2022-39198). Fix: Update that package to its patched version.
-
Serious GHSA-933g-v89r-x8pf Apache Dubbo vulnerable to Deserialization of Untrusted Data
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2023-23638). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-dubbo/shenyu-examples-apache-dubbo-service/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-5mc7-m686-p6jg Deserialization of Untrusted Data in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-alibaba-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2021-30179). Fix: Update that package to its patched version.
-
Serious GHSA-qmfc-6www-fjqw Code injection in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-alibaba-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2021-30181). Fix: Update that package to its patched version.
-
Serious GHSA-v2rg-8cwr-75g8 Deserializer tampering in Apache Dubbo
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-alibaba-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2021-25641). Fix: Update that package to its patched version.
-
Serious GHSA-5qwq-g2hx-r6f7 Hessian Lite for Apache Dubbo deserialization vulnerability
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-apache-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2022-39198). Fix: Update that package to its patched version.
-
Serious GHSA-933g-v89r-x8pf Apache Dubbo vulnerable to Deserialization of Untrusted Data
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-apache-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2023-23638). Fix: Update that package to its patched version.
-
Serious GHSA-7286-pgfv-vxvh Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sdk/shenyu-examples-sdk-dubbo/shenyu-examples-sdk-apache-dubbo-provider/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious GHSA-7q8p-9953-pxvr Remote Command Execution in SOFARPC
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-sofa/shenyu-examples-sofa-service/pom.xml
A package you depend on has a known security hole (CVE-2024-23636). Fix: Update that package to its patched version.
-
Serious GHSA-6c25-cxcc-pmc4 Dromara hutool vulnerable to SQL Injection
/workdirs/scan-d8fdaa91-feb4-4db9-91bc-a9bf993ed826/shenyu-examples/shenyu-examples-websocket/shenyu-example-spring-annotation-websocket/pom.xml
A package you depend on has a known security hole (CVE-2023-24163). Fix: Update that package to its patched version.