Skip to content

fix(deps): vuln minor upgrades — 4 packages (minor: 3 · patch: 1) [samples/client] - #50

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/maven/client/7-1781594209
Draft

fix(deps): vuln minor upgrades — 4 packages (minor: 3 · patch: 1) [samples/client]#50
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/maven/client/7-1781594209

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 15 packages upgraded (MINOR changes included)

Manifests changed:

  • samples/client (maven)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
org.springframework:spring-web 6.1.5 6.2.19 minor Direct 1 HIGH, 4 MEDIUM
org.hibernate:hibernate-validator 6.0.19.Final 6.2.5.Final minor Direct 6 MEDIUM
org.hibernate:hibernate-validator 6.0.19.Final 6.2.5.Final minor Direct 6 MEDIUM
org.springframework:spring-web 6.1.6 6.2.19 minor Direct 4 MEDIUM
org.springframework:spring-web 6.1.6 6.2.19 minor Direct 4 MEDIUM
org.springframework:spring-web 6.1.6 6.2.19 minor Direct 4 MEDIUM
org.springframework:spring-web 6.1.6 6.2.19 minor Direct 4 MEDIUM
org.springframework:spring-web 6.1.6 6.2.19 minor Direct 4 MEDIUM
ch.qos.logback:logback-core 1.4.14 1.5.34 minor Direct 2 MEDIUM, 2 LOW
ch.qos.logback:logback-core 1.4.14 1.5.34 minor Direct 2 MEDIUM, 2 LOW
org.springframework:spring-context 5.3.33 5.3.39 patch Direct 2 MEDIUM, 1 LOW
org.springframework:spring-context 5.3.33 5.3.39 patch Direct 2 MEDIUM, 1 LOW
org.springframework:spring-context 5.3.33 5.3.39 patch Direct 2 MEDIUM, 1 LOW
org.springframework:spring-context 5.3.33 5.3.39 patch Direct 2 MEDIUM, 1 LOW
org.springframework:spring-context 5.3.33 5.3.39 patch Direct 2 MEDIUM, 1 LOW

Security Details

🚨 Critical & High Severity (1 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
org.springframework:spring-web GHSA-2wrp-6fg6-hmc5 HIGH Spring Framework URL Parsing with Host Validation 6.1.5 5.3.34
ℹ️ Other Vulnerabilities (59)
Package CVE Severity Summary Unsafe Version Fixed In
ch.qos.logback:logback-core GHSA-25qh-j22f-pwp8 MODERATE QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing 1.4.14 1.5.19
ch.qos.logback:logback-core GHSA-pr98-23f8-jwxv MODERATE QOS.CH logback-core Expression Language Injection vulnerability 1.4.14 1.5.13
ch.qos.logback:logback-core GHSA-25qh-j22f-pwp8 MODERATE QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing 1.4.14 1.5.19
ch.qos.logback:logback-core GHSA-pr98-23f8-jwxv MODERATE QOS.CH logback-core Expression Language Injection vulnerability 1.4.14 1.5.13
org.hibernate:hibernate-validator CVE-2023-1932 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator GHSA-x83m-pf6f-pf9g MODERATE hibernate-validator Cross-site Scripting vulnerability 6.0.19.Final 6.2.0.Final
org.hibernate:hibernate-validator CVE-2020-10693 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator GHSA-rmrm-75hp-phr2 MODERATE Improper Input Validation in Hibernate Validator 6.0.19.Final 6.1.5.Final
org.hibernate:hibernate-validator CVE-2025-35036 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator GHSA-7v6m-28jr-rg84 MODERATE Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language 6.0.19.Final 6.2.0.CR1
org.hibernate:hibernate-validator CVE-2025-35036 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator CVE-2020-10693 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator GHSA-x83m-pf6f-pf9g MODERATE hibernate-validator Cross-site Scripting vulnerability 6.0.19.Final 6.2.0.Final
org.hibernate:hibernate-validator GHSA-rmrm-75hp-phr2 MODERATE Improper Input Validation in Hibernate Validator 6.0.19.Final 6.1.5.Final
org.hibernate:hibernate-validator CVE-2023-1932 MODERATE - 6.0.19.Final -
org.hibernate:hibernate-validator GHSA-7v6m-28jr-rg84 MODERATE Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language 6.0.19.Final 6.2.0.CR1
org.springframework:spring-context GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.1.14
org.springframework:spring-context CVE-2024-38820 MODERATE - 5.3.33 -
org.springframework:spring-context GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.1.14
org.springframework:spring-context CVE-2024-38820 MODERATE - 5.3.33 -
org.springframework:spring-context CVE-2024-38820 MODERATE - 5.3.33 -
org.springframework:spring-context GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.1.14
org.springframework:spring-context CVE-2024-38820 MODERATE - 5.3.33 -
org.springframework:spring-context GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.1.14
org.springframework:spring-context CVE-2024-38820 MODERATE - 5.3.33 -
org.springframework:spring-context GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.1.14
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.6 5.3.38
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.6 6.2.8
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.6 -
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.6 6.1.14
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.6 6.1.14
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.6 -
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.6 6.2.8
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.6 5.3.38
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.6 -
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.6 6.1.14
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.6 6.2.8
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.6 5.3.38
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.6 6.1.14
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.6 5.3.38
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.6 6.2.8
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.6 -
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.6 6.1.14
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.6 -
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.6 6.2.8
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.6 5.3.38
org.springframework:spring-web CVE-2024-38820 MODERATE - 6.1.5 -
org.springframework:spring-web GHSA-2rmj-mq67-h97g MODERATE Spring Framework DoS via conditional HTTP request 6.1.5 5.3.38
org.springframework:spring-web GHSA-6r3c-xf4w-jxjm MODERATE Spring Framework vulnerable to a reflected file download (RFD) 6.1.5 6.2.8
org.springframework:spring-web GHSA-4gc7-5j7h-4qph MODERATE Spring Framework DataBinder Case Sensitive Match Exception 6.1.5 6.1.14
ch.qos.logback:logback-core GHSA-6v67-2wr5-gvf4 LOW QOS.CH logback-core Server-Side Request Forgery vulnerability 1.4.14 1.5.13
ch.qos.logback:logback-core GHSA-qqpg-mvqg-649v LOW Logback allows an attacker to instantiate classes already present on the class path 1.4.14 1.5.25
ch.qos.logback:logback-core GHSA-6v67-2wr5-gvf4 LOW QOS.CH logback-core Server-Side Request Forgery vulnerability 1.4.14 1.5.13
ch.qos.logback:logback-core GHSA-qqpg-mvqg-649v LOW Logback allows an attacker to instantiate classes already present on the class path 1.4.14 1.5.25
org.springframework:spring-context GHSA-4wp7-92pw-q264 LOW Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.2.7
org.springframework:spring-context GHSA-4wp7-92pw-q264 LOW Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.2.7
org.springframework:spring-context GHSA-4wp7-92pw-q264 LOW Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.2.7
org.springframework:spring-context GHSA-4wp7-92pw-q264 LOW Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.2.7
org.springframework:spring-context GHSA-4wp7-92pw-q264 LOW Spring Framework DataBinder Case Sensitive Match Exception 5.3.33 6.2.7
⚠️ Dependencies that have Reached EOL (2)
Dependency Unsafe Version EOL Date New Version Path
org.hibernate:hibernate-validator 6.0.19.Final - 6.2.5.Final samples/client/petstore/java/rest-assured-jackson/pom.xml
org.hibernate:hibernate-validator 6.0.19.Final - 6.2.5.Final samples/client/petstore/java/rest-assured/pom.xml

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-official

datadog-official Bot commented Jun 16, 2026

Copy link
Copy Markdown

Pipelines

Fix all issues with BitsAI

⚠️ Warnings

🚦 3 Pipeline jobs failed

OpenAPI Generator | Samples up-to-date   View in Datadog   GitHub Actions

Linux tests | Build: JDK 17 (ubuntu-latest)   View in Datadog   GitHub Actions

Windows tests | Build (17)   View in Datadog   GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c8195f9 | Docs | Datadog PR Page | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants