[Snyk] Upgrade com.alibaba:fastjson from 1.2.24 to 1.2.83_noneautotype by preethamreddy-coder · Pull Request #1 · Cognia-TestLab/java-sec-code
Snyk has created this PR to upgrade com.alibaba:fastjson from 1.2.24 to 1.2.83_noneautotype.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
-
The recommended version is 106 versions ahead of your current version.
-
The recommended version was released 3 years ago.
Issues fixed by the recommended upgrade:
| Issue | Score | Exploit Maturity | |
|---|---|---|---|
| Deserialization of Untrusted Data SNYK-JAVA-COMALIBABA-2859222 |
780 | Proof of Concept | |
| Deserialization of Untrusted Data SNYK-JAVA-COMALIBABA-570967 |
780 | No Known Exploit | |
| Remote Code Execution (RCE) SNYK-JAVA-COMALIBABA-73578 |
780 | Mature |
Important
- Check the changes in this PR to ensure they won't cause issues with your project.
- This PR was automatically created by Snyk using the credentials of a real user.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.