DiscordGriefBot icon indicating copy to clipboard operation
DiscordGriefBot copied to clipboard

[Snyk] Security upgrade net.dv8tion:JDA from 4.2.1_253 to 5.0.0

Open alex-vsm opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 7 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity XML External Entity (XXE) Injection
SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302
  624   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424
  616   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426
  616   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMSQUAREUPOKIO-5773320
  616   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade Proof of Concept
high severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244
  589   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade No Known Exploit
medium severity Information Exposure
SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044
  561   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade Proof of Concept
medium severity Denial of Service (DoS)
SNYK-JAVA-COMFASTERXMLJACKSONCORE-2326698
  509   net.dv8tion:JDA:
4.2.1_253 -> 5.0.0
Major version upgrade No Known Exploit

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 XML External Entity (XXE) Injection 🦉 Denial of Service (DoS)

alex-vsm avatar Jul 08 '24 08:07 alex-vsm