We’ve disclosed 2269 vulnerabilities
by Snyk Security
How to fix?
org.springframework:spring-beans to version 5.2.20, 5.3.18 or higher.
byte54321 is a malicious package. The package's name is based on existing repositories, namespaces, or components used by popular companies in an effort to trick employees into downloading it, also known as 'dependency confusion'. Therefore, you're only vulnerable if this package was installed from the public NPM registry rather than your private registry.
Note: This malicious package was uncovered by one of Snyk's automated algorithms, and was confirmed to contain malicious code by our Security Research Team. For more context, please visit our blogpost.
rdiffweb is an A web interface to rdiff-backup repositories.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via
Fullname parameter, by allowing an attacker to set a long string name, leading to crashes.
Affected versions of this package are vulnerable to Use of Function with Inconsistent Implementations due the
Object Factory not checking the class type when instantiating an object from a class name.
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.