Skip to content

[Snyk] Fix for 10 vulnerabilities#811

Merged
lvca merged 1 commit intomainfrom
snyk-fix-bc9d1fe40d2365e34a64deca2eacacb0
Jan 27, 2023
Merged

[Snyk] Fix for 10 vulnerabilities#811
lvca merged 1 commit intomainfrom
snyk-fix-bc9d1fe40d2365e34a64deca2eacacb0

Conversation

@snyk-bot
Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • gremlin/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-IONETTY-3167776
org.apache.tinkerpop:gremlin-server:
3.6.1 -> 3.6.2
No No Known Exploit
medium severity 716/1000
Why? Mature exploit, Has a fix available, CVSS 6.6
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHECOMMONS-2944970
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No Mature
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Arbitrary Code Execution
SNYK-JAVA-ORGAPACHECOMMONS-3043138
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No Proof of Concept
high severity 569/1000
Why? Has a fix available, CVSS 7.1
Directory Traversal
SNYK-JAVA-ORGAPACHEIVY-3106014
org.apache.tinkerpop:gremlin-groovy:
3.6.1 -> 3.6.2
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-JAVA-ORGAPACHEIVY-3106929
org.apache.tinkerpop:gremlin-groovy:
3.6.1 -> 3.6.2
No No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JAVA-ORGYAML-2806360
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No No Known Exploit
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Stack-based Buffer Overflow
SNYK-JAVA-ORGYAML-3016888
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No Proof of Concept
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Stack-based Buffer Overflow
SNYK-JAVA-ORGYAML-3016889
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No No Known Exploit
medium severity 536/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.3
Stack-based Buffer Overflow
SNYK-JAVA-ORGYAML-3016891
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No Proof of Concept
low severity 399/1000
Why? Has a fix available, CVSS 3.7
Stack-based Buffer Overflow
SNYK-JAVA-ORGYAML-3113851
org.apache.tinkerpop:gremlin-core:
3.6.1 -> 3.6.2
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Arbitrary Code Execution
🦉 Arbitrary Code Execution
🦉 Directory Traversal
🦉 More lessons are available in Snyk Learn

@lvca lvca merged commit a67ba23 into main Jan 27, 2023
@lvca lvca deleted the snyk-fix-bc9d1fe40d2365e34a64deca2eacacb0 branch January 27, 2023 19:27
mergify Bot added a commit that referenced this pull request Oct 11, 2025
…/studio [skip ci]

Bumps [semver](https://github.com/npm/node-semver) from 7.7.2 to 7.7.3.
Release notes

*Sourced from [semver's releases](https://github.com/npm/node-semver/releases).*

> v7.7.3
> ------
>
> [7.7.3](npm/node-semver@v7.7.2...v7.7.3) (2025-10-06)
> --------------------------------------------------------------------------------
>
> ### Bug Fixes
>
> * [`e37e0ca`](npm/node-semver@e37e0ca) [#813](https://redirect.github.com/npm/node-semver/pull/813) faster paths for compare ([#813](https://redirect.github.com/npm/node-semver/issues/813)) ([`@​H4ad`](https://github.com/H4ad))
> * [`2471d75`](npm/node-semver@2471d75) [#811](https://redirect.github.com/npm/node-semver/pull/811) x-range build metadata support (i529015)
>
> ### Chores
>
> * [`8f05c87`](npm/node-semver@8f05c87) [#807](https://redirect.github.com/npm/node-semver/pull/807) bump `@​npmcli/template-oss` from 4.25.0 to 4.25.1 ([#807](https://redirect.github.com/npm/node-semver/issues/807)) ([`@​dependabot`](https://github.com/dependabot)[bot], [`@​owlstronaut`](https://github.com/owlstronaut))


Changelog

*Sourced from [semver's changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md).*

> [7.7.3](npm/node-semver@v7.7.2...v7.7.3) (2025-10-06)
> --------------------------------------------------------------------------------
>
> ### Bug Fixes
>
> * [`e37e0ca`](npm/node-semver@e37e0ca) [#813](https://redirect.github.com/npm/node-semver/pull/813) faster paths for compare ([#813](https://redirect.github.com/npm/node-semver/issues/813)) ([`@​H4ad`](https://github.com/H4ad))
> * [`2471d75`](npm/node-semver@2471d75) [#811](https://redirect.github.com/npm/node-semver/pull/811) x-range build metadata support (i529015)
>
> ### Chores
>
> * [`8f05c87`](npm/node-semver@8f05c87) [#807](https://redirect.github.com/npm/node-semver/pull/807) bump `@​npmcli/template-oss` from 4.25.0 to 4.25.1 ([#807](https://redirect.github.com/npm/node-semver/issues/807)) ([`@​dependabot`](https://github.com/dependabot)[bot], [`@​owlstronaut`](https://github.com/owlstronaut))


Commits

* [`a25789b`](npm/node-semver@a25789b) chore: release 7.7.3 ([#812](https://redirect.github.com/npm/node-semver/issues/812))
* [`e37e0ca`](npm/node-semver@e37e0ca) fix: faster paths for compare ([#813](https://redirect.github.com/npm/node-semver/issues/813))
* [`2471d75`](npm/node-semver@2471d75) fix: x-range build metadata support
* [`8f05c87`](npm/node-semver@8f05c87) chore: bump `@​npmcli/template-oss` from 4.25.0 to 4.25.1 ([#807](https://redirect.github.com/npm/node-semver/issues/807))
* [`d17aebf`](npm/node-semver@d17aebf) chore: bump `@​npmcli/template-oss` from 4.24.4 to 4.25.0 ([#797](https://redirect.github.com/npm/node-semver/issues/797))
* [`3b03e3b`](npm/node-semver@3b03e3b) chore: bump `@​npmcli/template-oss` from 4.24.3 to 4.24.4 ([#790](https://redirect.github.com/npm/node-semver/issues/790))
* See full diff in [compare view](npm/node-semver@v7.7.2...v7.7.3)

Maintainer changes

This version was pushed to npm by [GitHub Actions](<https://www.npmjs.com/~GitHub> Actions), a new releaser for semver since your current version.

  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=semver&package-manager=npm\_and\_yarn&previous-version=7.7.2&new-version=7.7.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants