Skip to content

[Snyk] Security upgrade ubuntu from latest to 24.10 - #1

Open
feixiaoan wants to merge 1 commit into
masterfrom
snyk-fix-315ea5c962479f2a2251b5e794e23488
Open

[Snyk] Security upgrade ubuntu from latest to 24.10#1
feixiaoan wants to merge 1 commit into
masterfrom
snyk-fix-315ea5c962479f2a2251b5e794e23488

fix: VMs/Dockerfile to reduce vulnerabilities

ecebc24
Select commit
Loading
Failed to load commit list.
Debricked / Vulnerability analysis completed Aug 5, 2025 in 44s

An automation triggered a pipeline warning

Found 16 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.

Output from Automations

4 rules were checked:


If a new dependency is added where the license risk is at least medium

then notify all users in the group admins by email

✔️ The rule did not trigger. Manage rule



If there is a dependency where the license risk is at least high

then send a pipeline warning

✔️ The rule did not trigger. Manage rule



If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before

then notify all users in the group admins by email

📤 The rule triggered for the following vulnerabilities, causing an email notification. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2020-10683 7.5 9.8 dom4j:dom4j (Maven) Plexus
CVE-2024-52046 N/A 9.8 org.apache.mina:mina-core (Maven) Apache-2.0
CVE-2016-1000027 7.5 9.8 org.springframework:spring-web (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38819 N/A 7.5 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-30172 N/A 7.5 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2018-1000632 5 7.5 dom4j:dom4j (Maven) Plexus
CVE-2024-29857 N/A 7.5 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2024-38816 N/A 7.5 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2020-25638 5.8 7.4 org.hibernate:hibernate-core (Maven) LGPL-2.1-only, LGPL-2.1-or-later
CVE-2025-46392 N/A 6.5 commons-configuration:commons-configuration (Maven) Apache-2.0
CVE-2019-14900 4 6.5 org.hibernate:hibernate-core (Maven) LGPL-2.1-only, LGPL-2.1-or-later
CVE-2024-30171 N/A 5.9 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2023-33201 N/A 5.3 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2024-38820 N/A 5.3 org.springframework:spring-context (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38828 N/A 5.3 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38820 N/A 5.3 org.springframework:spring-web (Maven) Apache-2.0, BSD-3-Clause
CVE-2025-22233 N/A 3.1 org.springframework:spring-context (Maven) Apache-2.0, BSD-3-Clause


If a dependency contains a vulnerability which has not been marked as unaffected

then send a pipeline warning

⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule

Vulnerability CVSS2 CVSS3 Dependency Dependency Licenses
CVE-2020-10683 7.5 9.8 dom4j:dom4j (Maven) Plexus
CVE-2024-52046 N/A 9.8 org.apache.mina:mina-core (Maven) Apache-2.0
CVE-2016-1000027 7.5 9.8 org.springframework:spring-web (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38819 N/A 7.5 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-30172 N/A 7.5 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2018-1000632 5 7.5 dom4j:dom4j (Maven) Plexus
CVE-2024-29857 N/A 7.5 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2024-38816 N/A 7.5 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2020-25638 5.8 7.4 org.hibernate:hibernate-core (Maven) LGPL-2.1-only, LGPL-2.1-or-later
CVE-2025-46392 N/A 6.5 commons-configuration:commons-configuration (Maven) Apache-2.0
CVE-2019-14900 4 6.5 org.hibernate:hibernate-core (Maven) LGPL-2.1-only, LGPL-2.1-or-later
CVE-2024-30171 N/A 5.9 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2023-33201 N/A 5.3 org.bouncycastle:bcprov-jdk15on (Maven) MIT
CVE-2024-38820 N/A 5.3 org.springframework:spring-context (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38828 N/A 5.3 org.springframework:spring-webmvc (Maven) Apache-2.0, BSD-3-Clause
CVE-2024-38820 N/A 5.3 org.springframework:spring-web (Maven) Apache-2.0, BSD-3-Clause
CVE-2025-22233 N/A 3.1 org.springframework:spring-context (Maven) Apache-2.0, BSD-3-Clause