Skip to content

Conversation

@tt9133github
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade org.apache.sling:org.apache.sling.engine from 2.0.4-incubator to 2.16.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 56 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHESLING-5421692
479 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-COMMONSFILEUPLOAD-30081
479 Mature
medium severity Log Manipulation
SNYK-JAVA-ORGAPACHESLING-2934398
479 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGAPACHESLING-30727
479 No Known Exploit
critical severity Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-30078
479 Mature
medium severity Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-472711
479 Proof of Concept
critical severity Deserialization of Untrusted Data
SNYK-JAVA-COMMONSCOLLECTIONS-6056408
479 Mature
high severity Arbitrary File Write
SNYK-JAVA-COMMONSFILEUPLOAD-30080
479 No Known Exploit
medium severity Time of Check Time of Use (TOCTOU)
SNYK-JAVA-COMMONSFILEUPLOAD-30079
479 No Known Exploit
critical severity Arbitrary Code Execution
SNYK-JAVA-COMMONSFILEUPLOAD-30401
479 No Known Exploit
medium severity Information Exposure
SNYK-JAVA-COMMONSFILEUPLOAD-31540
479 No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-COMMONSFILEUPLOAD-3326457
479 Proof of Concept
medium severity Directory Traversal
SNYK-JAVA-COMMONSIO-1277109
479 Mature

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

…bator to 2.16.2 Snyk has created this PR to upgrade org.apache.sling:org.apache.sling.engine from 2.0.4-incubator to 2.16.2. See this package in maven: org.apache.sling:org.apache.sling.engine See this project in Snyk: https://app.snyk.io/org/t438879/project/72f1f3d3-3df2-4ca8-aa2c-fc2168e64d0b?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants