Skip to content

[Snyk] Fix for 8 vulnerabilities#224

Open
DanielRivers wants to merge 1 commit intomainfrom
snyk-fix-abc0363537bf26b2c27ca81251043326
Open

[Snyk] Fix for 8 vulnerabilities#224
DanielRivers wants to merge 1 commit intomainfrom
snyk-fix-abc0363537bf26b2c27ca81251043326

Conversation

@DanielRivers
Copy link
Member

snyk-top-banner

Snyk has created this PR to fix 8 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • playground/kinde-springboot-starter-example/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
low severity Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755
org.springframework.boot:spring-boot-starter-data-rest:
3.5.6 -> 4.0.0
org.springframework.boot:spring-boot-starter-security:
3.5.6 -> 3.5.12
org.springframework.boot:spring-boot-starter-web:
3.5.7 -> 3.5.12
Major version upgrade No Known Exploit
low severity Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701756
org.springframework.boot:spring-boot-starter-data-rest:
3.5.6 -> 4.0.0
org.springframework.boot:spring-boot-starter-web:
3.5.7 -> 3.5.12
No Known Exploit
high severity Directory Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-15701845
org.springframework.boot:spring-boot-starter-data-rest:
3.5.6 -> 4.0.0
org.springframework.boot:spring-boot-starter-web:
3.5.7 -> 3.5.12
No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701835
org.springframework.boot:spring-boot-starter-actuator:
3.5.5 -> 3.5.12
No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701836
org.springframework.boot:spring-boot-starter-actuator:
3.5.5 -> 3.5.12
No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701839
org.springframework.boot:spring-boot-starter-actuator:
3.5.5 -> 3.5.12
No Known Exploit
high severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701840
org.springframework.boot:spring-boot-starter-actuator:
3.5.5 -> 3.5.12
No Known Exploit
critical severity Use of Cache Containing Sensitive Information
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796
org.springframework.boot:spring-boot-starter-security:
3.5.6 -> 3.5.12
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal

@DanielRivers DanielRivers requested a review from a team as a code owner March 24, 2026 03:29
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Mar 24, 2026

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 63e42964-6921-4ddf-bf12-eb5f3757daf1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch snyk-fix-abc0363537bf26b2c27ca81251043326

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov
Copy link

codecov bot commented Mar 24, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants