Skip to content

[Snyk] Upgrade org.springframework.boot:spring-boot-starter-json from 3.3.2 to 3.5.9 - #213

Closed
tcheeric wants to merge 1 commit into
masterfrom
snyk-upgrade-fc4d37278f5806a583fadd7f4dcbaa18
Closed

tcheeric wants to merge 1 commit into
masterfrom
snyk-upgrade-fc4d37278f5806a583fadd7f4dcbaa18

fix: upgrade org.springframework.boot:spring-boot-starter-json from 3…

c52b813
Select commit
Loading
Failed to load commit list.
Sign in for the full log view
GitHub Actions / Qodana for JVM completed Feb 15, 2026 in 0s

79 new problems found by Qodana for JVM

Qodana for JVM

79 new problems were found

Inspection name Severity Problems
Vulnerable declared dependency 🔴 Failure 5
Vulnerable declared dependency 🔶 Warning 27
Invalid properties configuration 🔶 Warning 10
Vulnerable declared dependency ◽️ Notice 37

☁️ View the detailed Qodana report

Detected 134 dependencies

Third-party software list

This page lists the third-party software dependencies used in project

Dependency Version Licenses
accessors-smart 2.5.0 Apache-2.0
accessors-smart 2.5.1 Apache-2.0
accessors-smart 2.5.2 Apache-2.0
android-json 0.0.20131108.vaadin1 Apache-2.0
angus-activation 2.0.0 BSD-3-Clause
antlr4-runtime 4.13.0 BSD-3-Clause
apiguardian-api 1.1.2 Apache-2.0
asm 9.3 BSD-3-Clause
asm 9.6 BSD-3-Clause
asm 9.7.1 BSD-3-Clause
aspectjweaver 1.9.22.1 Apache-2.0
assertj-core 3.27.3 Apache-2.0
awaitility 4.3.0 Apache-2.0
checker-qual 3.42.0 MIT
classmate 1.5.1 Apache-2.0
commons-configuration2 2.11.0 Apache-2.0
commons-lang3 3.14.0 Apache-2.0
commons-logging 1.3.2 Apache-2.0
commons-text 1.12.0 Apache-2.0
evo-inflector 1.3 Apache-2.0
hamcrest 3.0 BSD-3-Clause
hdrhistogram 2.2.2 BSD-2-Clause
hikaricp 5.1.0 Apache-2.0
istack-commons-runtime 4.1.1 BSD-3-Clause
jackson-annotations 2.17.2 Apache-2.0
jackson-annotations 2.18.1 Apache-2.0
jackson-core 2.17.2 Apache-2.0
jackson-core 2.18.1 Apache-2.0
jackson-core 2.20.0 Apache-2.0
jackson-databind 2.17.2 Apache-2.0
jackson-databind 2.18.1 Apache-2.0
jackson-databind 2.19.4 Apache-2.0
jackson-databind 2.20.0 Apache-2.0
jackson-dataformat-cbor 2.20.0 Apache-2.0
jackson-datatype-jdk8 2.18.1 Apache-2.0
jackson-datatype-jdk8 2.19.4 Apache-2.0
jackson-datatype-jsr310 2.17.2 Apache-2.0
jackson-datatype-jsr310 2.18.1 Apache-2.0
jackson-module-parameter-names 2.18.1 Apache-2.0
jackson-module-parameter-names 2.19.4 Apache-2.0
jakarta.activation-api 2.1.3 BSD-3-Clause
jakarta.annotation-api 2.1.1 Classpath-exception-2.0
EPL-2.0
GPL-2.0-only
jakarta.inject-api 2.0.1 Apache-2.0
jakarta.persistence-api 3.1.0 BSD-3-Clause
EPL-2.0
jakarta.servlet-api 6.0.0 EPL-2.0
GPL-1.0-or-later
jakarta.transaction-api 2.0.1 Classpath-exception-2.0
EPL-2.0
GPL-2.0-only
jakarta.validation-api 3.0.2 Apache-2.0
jakarta.xml.bind-api 4.0.0 BSD-3-Clause
jakarta.xml.bind-api 4.0.2 BSD-3-Clause
jandex 3.2.0 Apache-2.0
jaxb-core 4.0.2 BSD-3-Clause
jaxb-runtime 4.0.2 BSD-3-Clause
jboss-logging 3.5.0.final Apache-2.0
json-path 2.9.0 Apache-2.0
json-smart 2.5.0 Apache-2.0
json-smart 2.5.1 Apache-2.0
json-smart 2.5.2 Apache-2.0
jsonassert 1.5.3 Apache-2.0
jul-to-slf4j 2.0.16 MIT
jul-to-slf4j 2.0.17 MIT
junit-jupiter-params 5.12.2 EPL-2.0
junit-jupiter 5.12.2 EPL-2.0
latencyutils 2.0.3 CC0-1.0
log4j-api 2.24.1 Apache-2.0
log4j-api 2.24.3 Apache-2.0
log4j-to-slf4j 2.24.1 Apache-2.0
log4j-to-slf4j 2.24.3 Apache-2.0
logback-classic 1.5.12 EPL-1.0
LGPL-2.0-or-later
logback-core 1.5.12 EPL-1.0
LGPL-2.0-or-later
lombok 1.18.36 BSD-3-CLAUSE-NO-TRADEMARK
MIT
micrometer-commons 1.14.1 Apache-2.0
micrometer-core 1.14.1 Apache-2.0
micrometer-jakarta9 1.14.1 Apache-2.0
micrometer-observation 1.14.1 Apache-2.0
postgresql 42.7.3 BSD-2-Clause
postgresql 42.7.4 BSD-2-Clause
slf4j-api 2.0.13 MIT
slf4j-api 2.0.15 MIT
slf4j-api 2.0.16 MIT
slf4j-api 2.0.17 MIT
snakeyaml 2.3 Apache-2.0
snakeyaml 2.4 Apache-2.0
spring-aop 6.2.0 Apache-2.0
spring-aspects 6.2.0 Apache-2.0
spring-beans 6.2.0 Apache-2.0
spring-beans 6.2.15 Apache-2.0
spring-boot-actuator-autoconfigure 3.4.0 Apache-2.0
spring-boot-actuator 3.4.0 Apache-2.0
spring-boot-autoconfigure 3.4.0 Apache-2.0
spring-boot-autoconfigure 3.5.0 Apache-2.0
spring-boot-autoconfigure 3.5.9 Apache-2.0
spring-boot-starter-actuator 3.4.0 Apache-2.0
spring-boot-starter-data-jpa 3.4.0 Apache-2.0
spring-boot-starter-data-rest 3.4.0 Apache-2.0
spring-boot-starter-jdbc 3.4.0 Apache-2.0
spring-boot-starter-json 3.4.0 Apache-2.0
spring-boot-starter-json 3.5.9 Apache-2.0
spring-boot-starter-logging 3.4.0 Apache-2.0
spring-boot-starter-logging 3.5.0 Apache-2.0
spring-boot-starter-logging 3.5.9 Apache-2.0
spring-boot-starter-test 3.5.0 Apache-2.0
spring-boot-starter-tomcat 3.4.0 Apache-2.0
spring-boot-starter-validation 3.4.0 Apache-2.0
spring-boot-starter-web 3.4.0 Apache-2.0
spring-boot-starter 3.4.0 Apache-2.0
spring-boot-starter 3.5.0 Apache-2.0
spring-boot-starter 3.5.9 Apache-2.0
spring-boot-test-autoconfigure 3.5.0 Apache-2.0
spring-boot-test 3.5.0 Apache-2.0
spring-boot 3.4.0 Apache-2.0
spring-boot 3.5.0 Apache-2.0
spring-boot 3.5.9 Apache-2.0
spring-context 6.2.0 Apache-2.0
spring-core 6.2.0 Apache-2.0
spring-core 6.2.15 Apache-2.0
spring-core 6.2.7 Apache-2.0
spring-data-commons 3.4.0 Apache-2.0
spring-data-jpa 3.4.0 Apache-2.0
spring-data-rest-core 4.4.0 Apache-2.0
spring-data-rest-webmvc 4.4.0 Apache-2.0
spring-expression 6.2.0 Apache-2.0
spring-hateoas 2.4.0 Apache-2.0
spring-jdbc 6.2.0 Apache-2.0
spring-orm 6.2.0 Apache-2.0
spring-plugin-core 3.0.0 Apache-2.0
spring-tx 6.2.0 Apache-2.0
spring-web 6.2.0 Apache-2.0
spring-web 6.2.15 Apache-2.0
spring-webmvc 6.2.0 Apache-2.0
tomcat-embed-core 10.1.33 Apache-2.0
CDDL-1.0
PROPRIETARY-LICENSE
tomcat-embed-el 10.1.33 Apache-2.0
tomcat-embed-websocket 10.1.33 Apache-2.0
txw2 4.0.2 BSD-3-Clause
xmlunit-core 2.10.1 Apache-2.0
Contact Qodana team

Contact us at qodana-support@jetbrains.com

Details

This result was published with Qodana GitHub Action

Annotations

Check warning on line 10 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.username'

Check warning on line 7 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.payee'

Check warning on line 2 in cashu-gateway-phoenixd/src/main/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.expiration'

Check warning on line 11 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.password'

Check warning on line 12 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.base_url'

Check warning on line 2 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.expiration'

Check warning on line 8 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'A1b2C3d4.wid'

Check warning on line 7 in cashu-gateway-phoenixd/src/main/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'A1b2C3d4.wid'

Check warning on line 14 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.webhook_secret'

Check warning on line 13 in cashu-gateway-phoenixd/src/test/resources/app.properties

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Invalid properties configuration

Cannot resolve configuration property 'phoenixd.timeout'

Check failure on line 58 in cashu-gateway-rest/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.apache.tomcat.embed:tomcat-embed-core:10.1.33

* [CVE-2025-31651](https://www.mend.io/vulnerability-database/CVE-2025-31651?utm_source=Jetbrains) 9.8 Insufficient Information
* [CVE-2024-50379](https://www.mend.io/vulnerability-database/CVE-2024-50379?utm_source=Jetbrains) 9.8 Insufficient Information
* [CVE-2024-56337](https://www.mend.io/vulnerability-database/CVE-2024-56337?utm_source=Jetbrains) 9.8 Insufficient Information
* [CVE-2025-24813](https://www.mend.io/vulnerability-database/CVE-2025-24813?utm_source=Jetbrains) 9.8 Insufficient Information
* [CVE-2025-55754](https://www.mend.io/vulnerability-database/CVE-2025-55754?utm_source=Jetbrains) 9.6 Insufficient Information
* [CVE-2025-31650](https://www.mend.io/vulnerability-database/CVE-2025-31650?utm_source=Jetbrains) 7.5 Insufficient Information
* [CVE-2025-48976](https://www.mend.io/vulnerability-database/CVE-2025-48976?utm_source=Jetbrains) 7.5 Insufficient Information
* [CVE-2025-48988](https://www.mend.io/vulnerability-database/CVE-2025-48988?utm_source=Jetbrains) 7.5 Insufficient Information
* [CVE-2025-48989](https://www.mend.io/vulnerability-database/CVE-2025-48989?utm_source=Jetbrains) 7.5 Insufficient Information
* [CVE-2025-55752](https://www.mend.io/vulnerability-database/CVE-2025-55752?utm_source=Jetbrains) 7.5 Insufficient Information

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 73 in cashu-gateway-rest/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:ch.qos.logback:logback-classic:1.5.12

* [CVE-2024-12798](https://www.mend.io/vulnerability-database/CVE-2024-12798?utm_source=JetBrains) 6.6 JaninoEventEvaluator vulnerability

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check warning on line 116 in cashu-gateway-phoenixd/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Dependency maven:commons-beanutils:commons-beanutils:1.9.4 is vulnerable , safe version 1.11.0

* [CVE-2025-48734](https://www.mend.io/vulnerability-database/CVE-2025-48734?utm_source=Jetbrains) 8.8 Insufficient Information

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 84 in cashu-gateway-phoenixd/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.eclipse.jetty:jetty-server:11.0.20

* [CVE-2024-8184](https://www.mend.io/vulnerability-database/CVE-2024-8184?utm_source=JetBrains) 5.9 Allocation of Resources Without Limits or Throttling
* [CVE-2024-6763](https://www.mend.io/vulnerability-database/CVE-2024-6763?utm_source=Jetbrains) 3.7 Improper Validation of Syntactic Correctness of Input

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check warning on line 43 in cashu-gateway-client/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.springframework.boot:spring-boot:3.4.0

* [CVE-2025-22235](https://www.mend.io/vulnerability-database/CVE-2025-22235?utm_source=Jetbrains) 7.3 Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 109 in cashu-gateway-phoenixd/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Dependency maven:org.apache.commons:commons-lang3:3.17.0 is vulnerable , safe version 3.18.0

* [CVE-2025-48924](https://www.mend.io/vulnerability-database/CVE-2025-48924?utm_source=Jetbrains) 5.3 Insufficient Information

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 84 in cashu-gateway-phoenixd/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:commons-io:commons-io:2.11.0

* [CVE-2024-47554](https://www.mend.io/vulnerability-database/CVE-2024-47554?utm_source=Jetbrains) 4.3 Uncontrolled Resource Consumption ('Resource Exhaustion')

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 50 in cashu-gateway-webhook/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:ch.qos.logback:logback-core:1.5.12

* [CVE-2025-11226](https://www.mend.io/vulnerability-database/CVE-2025-11226?utm_source=JetBrains) 6.9 Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino
* [CVE-2024-12798](https://www.mend.io/vulnerability-database/CVE-2024-12798?utm_source=JetBrains) 6.6 JaninoEventEvaluator vulnerability
* [CVE-2026-1225](https://www.mend.io/vulnerability-database/CVE-2026-1225?utm_source=Jetbrains) 5.0 Malicious logback.xml configuration file allows instantiation of arbitrary classes
* [GHSA-qqpg-mvqg-649v](https://www.mend.io/vulnerability-database/GHSA-qqpg-mvqg-649v?utm_source=Jetbrains) 5.0 Insufficient Information
* [CVE-2024-12801](https://www.mend.io/vulnerability-database/CVE-2024-12801?utm_source=JetBrains) 4.4 SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check warning on line 43 in cashu-gateway-client/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.springframework:spring-core:6.2.0

* [CVE-2025-41249](https://www.mend.io/vulnerability-database/CVE-2025-41249?utm_source=Jetbrains) 7.5 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 50 in cashu-gateway-webhook/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.springframework:spring-context:6.2.0

* [CVE-2025-22233](https://www.mend.io/vulnerability-database/CVE-2025-22233?utm_source=Jetbrains) 3.1 Spring Framework DataBinder Case Sensitive Match Exception

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 57 in cashu-gateway-common/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.apache.commons:commons-lang3:3.14.0

* [CVE-2025-48924](https://www.mend.io/vulnerability-database/CVE-2025-48924?utm_source=Jetbrains) 5.3 Insufficient Information

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check warning on line 67 in cashu-gateway-webhook/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.springframework:spring-core:6.2.7

* [CVE-2025-41249](https://www.mend.io/vulnerability-database/CVE-2025-41249?utm_source=Jetbrains) 7.5 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 48 in cashu-gateway-client/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:ch.qos.logback:logback-core:1.5.12

* [CVE-2025-11226](https://www.mend.io/vulnerability-database/CVE-2025-11226?utm_source=JetBrains) 6.9 Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino
* [CVE-2024-12798](https://www.mend.io/vulnerability-database/CVE-2024-12798?utm_source=JetBrains) 6.6 JaninoEventEvaluator vulnerability
* [CVE-2026-1225](https://www.mend.io/vulnerability-database/CVE-2026-1225?utm_source=Jetbrains) 5.0 Malicious logback.xml configuration file allows instantiation of arbitrary classes
* [GHSA-qqpg-mvqg-649v](https://www.mend.io/vulnerability-database/GHSA-qqpg-mvqg-649v?utm_source=Jetbrains) 5.0 Insufficient Information
* [CVE-2024-12801](https://www.mend.io/vulnerability-database/CVE-2024-12801?utm_source=JetBrains) 4.4 SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check notice on line 50 in cashu-gateway-webhook/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Provides transitive vulnerable dependency maven:org.springframework:spring-web:6.2.0

* [CVE-2025-41234](https://www.mend.io/vulnerability-database/CVE-2025-41234?utm_source=Jetbrains) 6.5 RFD Attack via "Content-Disposition" Header Sourced from Request

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)

Check warning on line 103 in cashu-gateway-model/pom.xml

See this annotation in the file changed.

@github-actions github-actions / Qodana for JVM

Vulnerable declared dependency

Dependency maven:org.assertj:assertj-core:3.23.1 is vulnerable , safe version 3.27.7

* [CVE-2026-24400](https://www.mend.io/vulnerability-database/CVE-2026-24400?utm_source=Jetbrains) 7.3 AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion

Results powered by [Mend.io](https://www.mend.io/jetbrains-lp/?utm_source=JetBrains)