[Snyk] Upgrade org.apache.struts:struts2-spring-plugin from 2.3.20 to 2.5.22 #28
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade org.apache.struts:struts2-spring-plugin from 2.3.20 to 2.5.22.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.The recommended version fixes:
SNYK-JAVA-ORGAPACHESTRUTSXWORK-474418
SNYK-JAVA-ORGAPACHESTRUTSXWORK-451611
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30803
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30802
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30799
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30798
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30797
SNYK-JAVA-ORGAPACHESTRUTS-451610
SNYK-JAVA-ORGAPACHESTRUTS-32477
SNYK-JAVA-ORGAPACHESTRUTS-31503
SNYK-JAVA-ORGAPACHESTRUTS-31502
SNYK-JAVA-ORGAPACHESTRUTS-31501
SNYK-JAVA-ORGAPACHESTRUTS-31500
SNYK-JAVA-ORGAPACHESTRUTS-31495
SNYK-JAVA-ORGAPACHESTRUTS-30778
SNYK-JAVA-ORGAPACHESTRUTS-30776
SNYK-JAVA-ORGAPACHESTRUTS-30775
SNYK-JAVA-ORGAPACHESTRUTS-30774
SNYK-JAVA-ORGAPACHESTRUTS-30772
SNYK-JAVA-ORGAPACHESTRUTS-30771
SNYK-JAVA-ORGAPACHESTRUTS-30770
SNYK-JAVA-ORGAPACHESTRUTS-30207
SNYK-JAVA-ORGAPACHESTRUTS-30060
SNYK-JAVA-COMMONSFILEUPLOAD-30401
SNYK-JAVA-COMMONSFILEUPLOAD-30082
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30804
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30801
SNYK-JAVA-ORGAPACHESTRUTSXWORK-30800
SNYK-JAVA-ORGAPACHESTRUTS-460223
SNYK-JAVA-ORGAPACHESTRUTS-30777
SNYK-JAVA-ORGAPACHESTRUTS-30773
SNYK-JAVA-OGNL-30474
SNYK-JAVA-COMMONSFILEUPLOAD-31540
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs
[//]: # (snyk:metadata:{"dependencies":[{"name":"org.apache.struts:struts2-spring-plugin","from":"2.3.20","to":"2.5.22"}],"packageManager":"maven","type":"auto","projectUrl":"https://app.snyk.io/org/dansnyk/project/eeedcb5a-ab5a-46e8-a332-0d29660c155e?utm_source=github&utm_medium=upgrade-pr","projectPublicId":"eeedcb5a-ab5a-46e8-a332-0d29660c155e","env":"prod","prType":"upgrade","vulns":["SNYK-JAVA-ORGAPACHESTRUTSXWORK-474418","SNYK-JAVA-ORGAPACHESTRUTSXWORK-451611","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30803","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30802","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30799","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30798","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30797","SNYK-JAVA-ORGAPACHESTRUTS-451610","SNYK-JAVA-ORGAPACHESTRUTS-32477","SNYK-JAVA-ORGAPACHESTRUTS-31503","SNYK-JAVA-ORGAPACHESTRUTS-31502","SNYK-JAVA-ORGAPACHESTRUTS-31501","SNYK-JAVA-ORGAPACHESTRUTS-31500","SNYK-JAVA-ORGAPACHESTRUTS-31495","SNYK-JAVA-ORGAPACHESTRUTS-30778","SNYK-JAVA-ORGAPACHESTRUTS-30776","SNYK-JAVA-ORGAPACHESTRUTS-30775","SNYK-JAVA-ORGAPACHESTRUTS-30774","SNYK-JAVA-ORGAPACHESTRUTS-30772","SNYK-JAVA-ORGAPACHESTRUTS-30771","SNYK-JAVA-ORGAPACHESTRUTS-30770","SNYK-JAVA-ORGAPACHESTRUTS-30207","SNYK-JAVA-ORGAPACHESTRUTS-30060","SNYK-JAVA-COMMONSFILEUPLOAD-30401","SNYK-JAVA-COMMONSFILEUPLOAD-30082","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30804","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30801","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30800","SNYK-JAVA-ORGAPACHESTRUTS-460223","SNYK-JAVA-ORGAPACHESTRUTS-30777","SNYK-JAVA-ORGAPACHESTRUTS-30773","SNYK-JAVA-OGNL-30474","SNYK-JAVA-COMMONSFILEUPLOAD-31540"],"issuesToFix":[{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-474418","severity":"high","title":"Insecure Defaults","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-451611","severity":"high","title":"Command Injection","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30803","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30802","severity":"high","title":"Improper Input Validation","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30799","severity":"high","title":"Improper Input Validation","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30798","severity":"high","title":"Parameter Alteration","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30797","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-451610","severity":"high","title":"Improper Action Name Cleanup","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-32477","severity":"high","title":"Remote Code Execution","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-31503","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-31502","severity":"high","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-31501","severity":"high","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-31500","severity":"high","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-31495","severity":"high","title":"Arbitrary Command Execution","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30778","severity":"high","title":"Directory Traversal","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30776","severity":"high","title":"Access Restriction Bypass","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30775","severity":"high","title":"Access Restriction Bypass","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30774","severity":"high","title":"Cross-site Request Forgery (CSRF)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30772","severity":"high","title":"Arbitrary Command Execution","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30771","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30770","severity":"high","title":"Command Injection","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30207","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"mature"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30060","severity":"high","title":"Manipulation of Struts' internals","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-COMMONSFILEUPLOAD-30401","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-COMMONSFILEUPLOAD-30082","severity":"high","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30804","severity":"medium","title":"Regular Expression Denial of Service (ReDoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30801","severity":"medium","title":"Improper Input Validation","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTSXWORK-30800","severity":"medium","title":"Cross-site Scripting (XSS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-460223","severity":"medium","title":"Regular Expression Denial of Service (ReDoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30777","severity":"medium","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-ORGAPACHESTRUTS-30773","severity":"medium","title":"Cross-site Scripting (XSS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-OGNL-30474","severity":"medium","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JAVA-COMMONSFILEUPLOAD-31540","severity":"medium","title":"Information Disclosure","exploitMaturity":"no-known-exploit"}],"upgrade":["SNYK-JAVA-ORGAPACHESTRUTSXWORK-474418","SNYK-JAVA-ORGAPACHESTRUTSXWORK-451611","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30803","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30802","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30799","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30798","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30797","SNYK-JAVA-ORGAPACHESTRUTS-451610","SNYK-JAVA-ORGAPACHESTRUTS-32477","SNYK-JAVA-ORGAPACHESTRUTS-31503","SNYK-JAVA-ORGAPACHESTRUTS-31502","SNYK-JAVA-ORGAPACHESTRUTS-31501","SNYK-JAVA-ORGAPACHESTRUTS-31500","SNYK-JAVA-ORGAPACHESTRUTS-31495","SNYK-JAVA-ORGAPACHESTRUTS-30778","SNYK-JAVA-ORGAPACHESTRUTS-30776","SNYK-JAVA-ORGAPACHESTRUTS-30775","SNYK-JAVA-ORGAPACHESTRUTS-30774","SNYK-JAVA-ORGAPACHESTRUTS-30772","SNYK-JAVA-ORGAPACHESTRUTS-30771","SNYK-JAVA-ORGAPACHESTRUTS-30770","SNYK-JAVA-ORGAPACHESTRUTS-30207","SNYK-JAVA-ORGAPACHESTRUTS-30060","SNYK-JAVA-COMMONSFILEUPLOAD-30401","SNYK-JAVA-COMMONSFILEUPLOAD-30082","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30804","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30801","SNYK-JAVA-ORGAPACHESTRUTSXWORK-30800","SNYK-JAVA-ORGAPACHESTRUTS-460223","SNYK-JAVA-ORGAPACHESTRUTS-30777","SNYK-JAVA-ORGAPACHESTRUTS-30773","SNYK-JAVA-OGNL-30474","SNYK-JAVA-COMMONSFILEUPLOAD-31540"],"upgradeInfo":{"versionsDiff":35,"publishedDate":"2019-11-17T19:23:37.000Z"},"templateVariants":[],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false})