chore(deps): update frauddetectionservice #169
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-47764Path to dependency file: /src/frontend/package.json Path to vulnerable library: /src/frontend/node_modules/cookie/package.json Dependency Hierarchy: -> cookies-next-2.1.2.tgz (Root Library) -> ❌ cookie-0.4.2.tgz (Vulnerable Library) |
5.3 | cookie-0.4.2.tgz | Upgrade to version: cookie - 0.7.0 | None | |
CVE-2024-29025Path to dependency file: /src/frauddetectionservice/build.gradle.kts Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar Dependency Hierarchy: -> grpc-netty-1.60.0.jar (Root Library) -> netty-handler-proxy-4.1.100.Final.jar -> ❌ netty-codec-http-4.1.100.Final.jar (Vulnerable Library) |
5.3 | netty-codec-http-4.1.100.Final.jar | Upgrade to version: io.netty:netty-codec-http:4.1.108.Final | None | |
CVE-2024-37891Path to dependency file: /src/loadgenerator/requirements.txt Path to vulnerable library: /src/loadgenerator/requirements.txt Dependency Hierarchy: -> ❌ urllib3-2.0.7-py3-none-any.whl (Vulnerable Library) |
4.4 | urllib3-2.0.7-py3-none-any.whl | Upgrade to version: urllib3 - 1.26.19,2.2.2 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-7254 | protobuf-java-3.25.0.jar |
Base branch total remaining vulnerabilities: 29
Base branch commit: 651312c9c82b789d7867420ec64c43adf2e24321
Total libraries scanned: 1003
Scan token: 1443447af41846989a4bead439339507