Your dependencies cross-checked against the OSV vulnerability database.
-
Serious GHSA-45hx-wfhj-473x Arbitrary code execution in H2 Console
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2022-23221). Fix: Update that package to its patched version.
-
Serious GHSA-h376-j262-vhq6 RCE in H2 Console
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2021-42392). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-36p3-wjmg-h94x Remote Code Execution in Spring Framework
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter01/pom.xml
A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter03/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter03/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter03/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter05/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter05/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter05/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/core/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/core/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/core/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-36p3-wjmg-h94x Remote Code Execution in Spring Framework
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/spring/pom.xml
A package you depend on has a known security hole (CVE-2022-22965). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/spring/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/spring/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter07/spring/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter08/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter08/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter08/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.
-
Serious GHSA-2qrg-x229-3v8q Deserialization of Untrusted Data in Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter10/embedded/pom.xml
A package you depend on has a known security hole (CVE-2019-17571). Fix: Update that package to its patched version.
-
Serious GHSA-65fg-84f6-3jq3 SQL Injection in Log4j 1.2.x
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter10/embedded/pom.xml
A package you depend on has a known security hole (CVE-2022-23305). Fix: Update that package to its patched version.
-
Serious GHSA-f7vh-qwp3-x37m Deserialization of Untrusted Data in Apache Log4j
/workdirs/scan-55a6d304-028e-4e5c-a021-27a6894e683f/chapter10/embedded/pom.xml
A package you depend on has a known security hole (CVE-2022-23307). Fix: Update that package to its patched version.